VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 175 of 187
  • CVE-2026-62224MedJul 17, 2026
    risk 0.00cvss 5.4epss 0.00

    OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiting the mutable display name binding in…

  • CVE-2026-62223HigJul 17, 2026
    risk 0.00cvss 8.8epss 0.00

    OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execute actions beyond their intended authorization. Attackers can exploit misconfigured input paths to execute or persist unauthorized…

  • CVE-2026-62221MedJul 17, 2026
    risk 0.00cvss 5.4epss 0.00

    OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's…

  • CVE-2026-62219HigJul 17, 2026
    risk 0.00cvss 7.1epss 0.00

    OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actions that should require stronger…

  • CVE-2026-62217HigJul 17, 2026
    risk 0.00cvss 8.8epss 0.00

    OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization,…

  • CVE-2026-62209HigJul 17, 2026
    risk 0.00cvss 8.1epss 0.00

    OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path…

  • CVE-2026-62202HigJul 17, 2026
    risk 0.00cvss 8.8epss 0.00

    OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can execute or persist actions beyond their intended authorization by leveraging…

  • CVE-2026-62290HigJul 16, 2026
    risk 0.00cvss 7.3epss 0.00

    cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. From 1.18.0 until 1.19.6 and 1.20.3, Challenge resources under acme.cert-manager.io can be created…

  • CVE-2026-63085HigJul 16, 2026
    risk 0.00cvss 8.8epss 0.00

    Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticated non-admin users to escalate privileges by exploiting unenforced field restrictions on nested relational save operations. Attackers can modify sensitive User…

  • CVE-2026-56743MedJul 15, 2026
    risk 0.00cvss 5.4epss 0.00

    Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured…

  • CVE-2026-61643MedJul 15, 2026
    risk 0.00cvss 5.9epss 0.00

    FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can save a workflow node that points to another user's private HTTP toolset by using a crafted saved tool id such as http-<victim_toolset_app_id>/<tool_name>. The…

  • CVE-2026-59258HigJul 15, 2026
    risk 0.00cvss 8.3epss 0.00

    immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions. Attackers with editor access can demote the album owner to editor and promote…

  • CVE-2026-62683LowJul 15, 2026
    risk 0.00cvss 3.1epss 0.00

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser can leave a public directory share behind when the shared directory is deleted through a path with a trailing…

  • CVE-2026-55242HigJul 15, 2026
    risk 0.00cvss 8.8epss 0.00

    ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthorized disclosure of data…

  • CVE-2026-61644HigJul 15, 2026
    risk 0.00cvss 7.7epss 0.00

    FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api/core/chat/record/getCollectionQuote endpoint authenticates the caller's chat and collection context, but the initialId center-node lookup is not bound to that authorized context.…

  • CVE-2026-54563HigJul 15, 2026
    risk 0.00cvss 7.1epss 0.00

    Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a configured folder can send paths such as /dav/%2e%2e/outside.txt because stripPrefix in pkg/webdav/webdav.go joins the decoded request suffix to the account…

  • CVE-2026-60087MedJul 15, 2026
    risk 0.00cvss 6.1epss 0.00

    PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arbitrary arguments. Attackers can exploit this by obtaining approval for a benign operation and then executing dangerous file write…

  • CVE-2026-15752HigJul 14, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the component Backend User Endpoint. Performing a manipulation results in missing authorization. The attack…

  • CVE-2026-48327CriJul 14, 2026
    risk 0.00cvss 9.0epss 0.00

    ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

  • CVE-2026-48349HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.00

    Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is…