VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,241)

page 181 of 213
  • CVE-2023-0091LowJan 13, 2023
    risk 0.25cvss 3.8epss 0.00

    A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.

  • CVE-2022-23452MedSep 1, 2022
    risk 0.25cvss 4.9epss 0.01

    An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.

  • CVE-2022-1553MedMay 16, 2022
    risk 0.25cvss 4.9epss 0.01

    Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising…

  • CVE-2020-15120MedJul 27, 2020
    risk 0.25cvss 4.9epss 0.01

    In "I hate money" before version 4.1.5, an authenticated member of one project can modify and delete members of another project, without knowledge of this other project's private code. This can be further exploited to access all bills of another project without knowledge of this…

  • CVE-2020-6752LowJun 17, 2020
    risk 0.25cvss 3.8epss 0.01

    In OMERO before 5.6.1, group owners can access members' data in other groups.

  • CVE-2018-15774LowDec 13, 2018
    risk 0.25cvss 3.8epss 0.01

    Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privilege escalation vulnerability. An authenticated malicious iDRAC user with operator privileges could potentially exploit a…

  • CVE-2017-6816MedMar 12, 2017
    risk 0.25cvss 4.9epss 0.03

    In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.

  • CVE-2026-92403LowSep 19, 2026
    risk 0.24cvss 3.7epss 0.00

    The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and…

  • CVE-2026-92611MedSep 17, 2026
    risk 0.24cvss —epss 0.00

    In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entries to be skipped and allow unauthorized…

  • CVE-2026-81439LowSep 17, 2026
    risk 0.24cvss 3.7epss 0.00

    Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

  • CVE-2026-78887LowAug 25, 2026
    risk 0.24cvss 3.7epss 0.00

    A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of the component Journey Photo Proxy. Executing a manipulation can lead to incorrect authorization. The attack can be launched remotely. This attack is…

  • CVE-2026-13238MedJul 10, 2026
    risk 0.24cvss 4.8epss 0.00

    Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2.

  • CVE-2026-13237MedJul 10, 2026
    risk 0.24cvss 4.8epss 0.00

    Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.

  • CVE-2026-35635MedApr 9, 2026
    risk 0.24cvss 4.8epss 0.00

    OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that allows attackers to collapse multi-account configurations onto shared webhook paths. Attackers can exploit inherited or duplicate webhook paths to bypass…

  • CVE-2026-27447MedApr 3, 2026
    risk 0.24cvss 4.8epss 0.00

    OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The…

  • CVE-2026-33869MedMar 27, 2026
    risk 0.24cvss 4.8epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on the 4.4.x branch prior to 4.4.15, an attacker that knows of a quote before it has reached a server can prevent it from being correctly processed on…

  • CVE-2026-4363LowMar 25, 2026
    risk 0.24cvss 3.7epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user to gain unauthorized access to resources due to improper caching of…

  • CVE-2026-32065MedMar 21, 2026
    risk 0.24cvss 4.8epss 0.01

    OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where rendered command text is used as approval identity while trimming argv token whitespace, but runtime execution uses raw argv. An attacker can craft a trailing-space…

  • CVE-2025-59376LowSep 15, 2025
    risk 0.24cvss 3.7epss 0.00

    feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g., it allows a "kubectl version; kubectl delete pod" command because the first word (i.e., "version") is not a write or delete…

  • CVE-2025-47937LowMay 20, 2025
    risk 0.24cvss 3.7epss 0.00

    TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, when performing a database query involving multiple tables through the database abstraction…