VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 18 of 209
  • CVE-2026-76836HigAug 24, 2026
    risk 0.57cvss 8.8epss 0.00

    AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated with GROUP_GENERAL, and PUT /api/station/{station_id}/profile/edit in…

  • CVE-2026-77234HigAug 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later.

  • CVE-2026-62941CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration…

  • CVE-2026-55089CriAug 19, 2026
    risk 0.57cvss 9.9epss 0.00

    Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in the authorization_code OAuth path by using requiredClaims with the admin claim. This check requires only that the claim exists,…

  • CVE-2026-19198HigAug 19, 2026
    risk 0.57cvss —epss 0.00

    Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkActions dispatcher.This issue affects Akaunting: 3.1.21.

  • CVE-2026-70408HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.00

    An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.

  • CVE-2026-48508HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_principal.Permission.__init__() with zero Need objects when ADMIN_ONLY_AUTHORITY_CREATION and LEMUR_STRICT_ROLE_ENFORCEMENT are…

  • CVE-2026-61574HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and the response includes connection settings…

  • CVE-2026-71387HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an…

  • CVE-2026-62872HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-72886CriAug 10, 2026
    risk 0.57cvss 9.9epss 0.00

    Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the owner/admin host-schedule gate only in…

  • CVE-2026-69118HigAug 10, 2026
    risk 0.57cvss 8.8epss 0.01

    Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create malicious incident templates with Blade directives or Twig filters that execute system…

  • CVE-2026-67341CriAug 1, 2026
    risk 0.57cvss 9.8epss 0.00

    ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls…

  • CVE-2026-59851HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.

  • CVE-2026-47303HigJul 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-15125HigJul 8, 2026
    risk 0.57cvss 8.8epss 0.00

    Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-27780CriJul 3, 2026
    risk 0.57cvss 9.8epss 0.01

    Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.

  • CVE-2026-48781CriJun 17, 2026
    risk 0.57cvss 9.9epss 0.00

    Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without…

  • CVE-2026-32966CriJun 17, 2026
    risk 0.57cvss 9.8epss 0.00

    DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

  • CVE-2016-20075HigJun 15, 2026
    risk 0.57cvss 8.8epss 0.00

    WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles to upload malicious files by exploiting the custom fields functionality. Attackers can upload PHP…