VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 172 of 187
  • CVE-2026-65975MedJul 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to but not including 1.107.1 and 2.0.0b1 up to but not including 2.5.0, the UI adapters (AG-UI via Agent.to_ag_ui()/AGUIAdapter, and Vercel AI via…

  • CVE-2026-6336MedJul 29, 2026
    risk 0.00cvss 5.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthorized user to view project import source information due to a missing…

  • CVE-2025-14562LowJul 29, 2026
    risk 0.00cvss 3.1epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to commit changes to a project after…

  • CVE-2026-18236CriJul 29, 2026
    risk 0.00cvss epss 0.00

    A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool confirmation response. This is possible…

  • CVE-2025-10656CriJul 29, 2026
    risk 0.00cvss 9.8epss 0.00

    The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes it possible for unauthenticated attackers to create admin…

  • CVE-2026-48396HigJul 28, 2026
    risk 0.00cvss 8.6epss 0.00

    Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a…

  • CVE-2026-48390HigJul 28, 2026
    risk 0.00cvss 8.2epss 0.00

    Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-7868MedJul 28, 2026
    risk 0.00cvss 6.5epss 0.00

    IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrator privileges.

  • CVE-2026-14167HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.

  • CVE-2026-43672HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious application may be able to bypass Privacy preferences.

  • CVE-2026-42016HigJul 27, 2026
    risk 0.00cvss 8.1epss 0.00

    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

  • CVE-2026-17568HigJul 27, 2026
    risk 0.00cvss 8.8epss 0.00

    Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. This issue affects…

  • CVE-2026-17530MedJul 27, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/astr_agent_tool_exec.py of the component Subagent. The manipulation results in incorrect authorization.…

  • CVE-2026-17529MedJul 27, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument req.func_tool leads to incorrect authorization. The attack may be initiated remotely. The exploit is…

  • CVE-2026-8789HigJul 24, 2026
    risk 0.00cvss 8.1epss 0.00

    The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it…

  • CVE-2026-15704CriJul 24, 2026
    risk 0.00cvss 9.8epss 0.00

    In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's…

  • CVE-2026-15630CriJul 23, 2026
    risk 0.00cvss 9.9epss 0.00

    A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

  • CVE-2026-59678HigJul 23, 2026
    risk 0.00cvss epss 0.00

    An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.

  • CVE-2026-65596HigJul 22, 2026
    risk 0.00cvss 8.1epss 0.00

    n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) in the GraphQL node, unlike the HTTP Request node. An authenticated user able to create or edit…

  • CVE-2026-65594MedJul 22, 2026
    risk 0.00cvss 6.5epss 0.00

    n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. On instances with at least one active MCP…