VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,241)

page 184 of 213
  • CVE-2026-90820MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizationRequestHandlerDecorator.onListTasks of the file server-common/src/main/java/org/a2aproject/sdk/server/requesthandlers/AuthorizationRequestHandlerDecorator.ja…

  • CVE-2026-90934MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses. Attackers can recover hidden attendee emails by exploiting incorrect ACL scope validation…

  • CVE-2026-89267MedSep 12, 2026
    risk 0.21cvss 4.3epss 0.00

    starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to…

  • CVE-2026-90450MedSep 11, 2026
    risk 0.21cvss 4.3epss 0.00

    The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any…

  • CVE-2026-87017MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.1, the built-in knowledge search tool passed the caller's readable knowledge identifiers through a metadata filter, but the search methods in eleven shipped vector…

  • CVE-2026-61907MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was…

  • CVE-2026-86753MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create checkout requests for non-requestable asset models by…

  • CVE-2026-53638MedSep 8, 2026
    risk 0.21cvss 4.3epss 0.00

    Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an authorization bypass vulnerability exists in the shop account API. The `PATCH /api/v2/shop/account/orders/{tokenValue}/payments/{paymentId}`…

  • CVE-2026-84808MedSep 2, 2026
    risk 0.21cvss 4.3epss 0.00

    Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with view_other_timesheet permission can list timesheets using activities restricted to teams they…

  • CVE-2026-72633MedSep 1, 2026
    risk 0.21cvss 4.3epss 0.00

    Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges,…

  • CVE-2026-84206MedSep 1, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset identifiers to the bulk restore endpoint to…

  • CVE-2026-50199MedAug 31, 2026
    risk 0.21cvss 4.3epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/currency/update_exchange.php loads the first Fixer/API Layer credential globally instead of loading the credential for the authenticated user. As a result, a normal…

  • CVE-2026-80209MedAug 27, 2026
    risk 0.21cvss 4.3epss 0.00

    The updateWorkspace handler in mods/identity/src/workspaces/createUpdateWorkspace.ts in Fonoster through 0.22.7 invokes the gRPC callback with PERMISSION_DENIED when createIsWorkspaceMember reports that the caller is not a member of the target workspace, but it does not return.…

  • CVE-2026-41262MedAug 26, 2026
    risk 0.21cvss 4.3epss 0.00

    Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify team ownership of the requested policy, allowing an authenticated user with…

  • CVE-2026-77923MedAug 24, 2026
    risk 0.21cvss 4.3epss 0.00

    Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action handler in htdocs/core/actions_massactions.inc.php. Authenticated users with project…

  • CVE-2026-4245MedAug 22, 2026
    risk 0.21cvss 4.3epss 0.00

    The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` permission callback only verifying the `duplicate_posts` capability without checking whether the…

  • CVE-2026-62313MedAug 21, 2026
    risk 0.21cvss 4.3epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricted.containers.privilege=isolated` can be trivially bypassed, allowing a user to create a non-isolated (shared host idmap) container in a project that is…

  • CVE-2026-49431LowAug 19, 2026
    risk 0.21cvss 3.3epss 0.00

    The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is able to set metadata on a dataset indicating that the dataset has received properties from a zfs-recv(8) stream. Any local user can set the internal ZFS…

  • CVE-2026-45122MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissions for the destination calendar when moving events. A user with moderation permission for the source calendar can move an event to a calendar where the user…

  • CVE-2026-70657MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the containing folder. This vulnerability was only…