VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,241)

page 175 of 213
  • CVE-2026-85622MedSep 4, 2026
    risk 0.27cvss 5.3epss 0.00

    AppFlowy-Cloud through 0.9.64 fails to validate workspace membership when establishing WebSocket connections in the establish_ws_connection_v2 handler, allowing authenticated users to bind sessions to workspaces they do not belong to. Attackers can send sync Manifest messages…

  • CVE-2026-85587MedSep 4, 2026
    risk 0.27cvss —epss 0.00

    phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to…

  • CVE-2026-81165MedSep 2, 2026
    risk 0.27cvss 5.3epss 0.00

    Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.

  • CVE-2026-73478MedSep 2, 2026
    risk 0.27cvss 5.3epss 0.00

    Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.

  • CVE-2026-73477MedSep 2, 2026
    risk 0.27cvss 5.3epss 0.00

    Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1.

  • CVE-2026-82395MedAug 31, 2026
    risk 0.27cvss —epss 0.00

    Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied collection value instead of the media item's actual source collection, and…

  • CVE-2026-82394MedAug 31, 2026
    risk 0.27cvss —epss 0.01

    Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php do not enforce VIEW permission for the target resource…

  • CVE-2026-54766MedAug 28, 2026
    risk 0.27cvss —epss 0.00

    Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operation in pkg/models/project_duplicate.go allows an authenticated user who can read a source project to place its duplicate beneath an arbitrary target parent…

  • CVE-2026-77507MedAug 26, 2026
    risk 0.27cvss 5.3epss 0.00

    Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, Weblate's object-scoped RSS feeds do not apply the permission checks used elsewhere, allowing unauthorized users to read change-history metadata from…

  • CVE-2026-73290MedAug 12, 2026
    risk 0.27cvss 5.3epss 0.00

    RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request in rustfs/src/storage/access.rs that lacks a direct bucket-policy grant falls back to an s3:ListBucket check and returns before the policy_allowed path…

  • CVE-2026-73221MedAug 11, 2026
    risk 0.27cvss —epss 0.00

    CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with the Worker role can use predictable task-based request IDs with the lambda request retrieve and destroy endpoints to view automatic annotation requests…

  • CVE-2026-18703MedAug 11, 2026
    risk 0.27cvss 4.2epss 0.00

    An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to restrict authentication to other mechanisms.…

  • CVE-2026-66059MedAug 7, 2026
    risk 0.27cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. This issue is fixed in versions 16.23.0 and 15.112.0.

  • CVE-2026-71433MedAug 6, 2026
    risk 0.27cvss 5.3epss 0.00

    LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted hierarchical namespaces as a dot joined string…

  • CVE-2026-66064MedJul 28, 2026
    risk 0.27cvss 5.3epss 0.00

    goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs…

  • CVE-2026-13068MedJul 22, 2026
    risk 0.27cvss 4.2epss 0.00

    An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for other users. The behavior stems from an authorization check that does not…

  • CVE-2026-54517MedJun 23, 2026
    risk 0.27cvss 5.3epss 0.00

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied only to creator properties;…

  • CVE-2026-54022MedJun 23, 2026
    risk 0.27cvss 5.3epss 0.00

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the ydoc:document:join Socket.IO handler checks note ownership only when the document_id starts with note: (colon). However, the YdocManager storage layer…

  • CVE-2026-49983MedJun 23, 2026
    risk 0.27cvss 5.2epss 0.00

    Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permission. You can deny it with --deny-env, or restrict it to a specific allowlist with --allow-env=FOO,BAR. The expectation is that a program running without env…

  • CVE-2026-54398MedJun 12, 2026
    risk 0.27cvss —epss 0.00

    An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions to assign a MISP object, or attributes contained within an object, to a sharing group that the user was not authorized to use or view. When editing objects,…