VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,241)

page 183 of 213
  • CVE-2020-8919LowDec 10, 2020
    risk 0.23cvss 3.5epss 0.00

    An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's personal account data as well as…

  • CVE-2020-29374LowNov 28, 2020
    risk 0.23cvss 3.6epss 0.00

    An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can grant unintended…

  • CVE-2026-90508LowSep 13, 2026
    risk 0.22cvss 3.4epss 0.00

    A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in missing…

  • CVE-2026-71325MedAug 6, 2026
    risk 0.22cvss 4.4epss 0.00

    Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant…

  • CVE-2024-54010LowJan 8, 2025
    risk 0.22cvss 3.4epss 0.00

    A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires…

  • CVE-2023-27903MedMar 10, 2023
    risk 0.22cvss 4.4epss 0.00

    Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a file parameter through the CLI, potentially allowing attackers with access to the Jenkins…

  • CVE-2020-35501LowMar 30, 2022
    risk 0.22cvss 3.4epss 0.00

    A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem

  • CVE-2021-32716MedJun 24, 2021
    risk 0.22cvss 4.4epss 0.01

    Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidden fields when an association has been loaded with a to many reference. Users are recommend to update to version 6.4.1.1. You can get the update to 6.4.1.1…

  • CVE-2020-1729MedMay 28, 2021
    risk 0.22cvss 4.4epss 0.00

    A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a…

  • CVE-2026-10518MedSep 29, 2026
    risk 0.21cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with guest-level permissions to read private security policy content they…

  • CVE-2026-102297MedSep 28, 2026
    risk 0.21cvss 4.3epss 0.00

    ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame records from monitors they are denied access to, disclosing event and frame…

  • CVE-2026-100628MedSep 26, 2026
    risk 0.21cvss 4.3epss 0.00

    capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API keys. In the POST /apikey endpoint, requests that supply app_id but omit org_id, limited_to_orgs, and expires_at resolve the target app and scope the key to it,…

  • CVE-2026-100590MedSep 26, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to persist Gateway voice configuration. Attackers with command access can change the voice used by Talk responses for the configured…

  • CVE-2026-100553MedSep 26, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, so unpin requests can bypass the shared same-provider cross-context target check. When tools.message.crossContext.allowWithinProvider is…

  • CVE-2026-77425MedSep 22, 2026
    risk 0.21cvss 4.3epss 0.00

    Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-controlled strategy IDs to unprotectedUpdateStrategiesSortOrder and…

  • CVE-2026-88978MedSep 21, 2026
    risk 0.21cvss 4.3epss 0.00

    Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, the WorkerStatus gRPC polling path in pkg/repository/durable_events.go passes caller-supplied durable task, node, and branch identifiers to ListSatisfiedEntries…

  • CVE-2026-93954MedSep 19, 2026
    risk 0.21cvss 4.3epss 0.00

    A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings API Endpoint. Such…

  • CVE-2026-92774MedSep 16, 2026
    risk 0.21cvss 4.3epss 0.00

    Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, tree, tags, searchTags, and links resolvers to retrieve restricted page metadata including…

  • CVE-2026-92764MedSep 16, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenCVE versions 2.4.0 before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve every organization their creator belongs to,…

  • CVE-2026-91983MedSep 15, 2026
    risk 0.21cvss 4.3epss 0.00

    Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter to access restricted data like comments, reactions, and…