VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,241)

page 192 of 213
  • CVE-2019-9364LowSep 27, 2019
    risk 0.21cvss 3.3epss 0.00

    In AudioService, there is a possible trigger of background user audio due to a permissions bypass. This could lead to local information disclosure by playing the background user's audio with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2019-1667LowFeb 21, 2019
    risk 0.21cvss 3.3epss 0.00

    A vulnerability in the Graphite interface of Cisco HyperFlex software could allow an authenticated, local attacker to write arbitrary data to the Graphite interface. The vulnerability is due to insufficient authorization controls. An attacker could exploit this vulnerability by…

  • CVE-2018-7957LowJul 31, 2018
    risk 0.21cvss 3.3epss 0.00

    Huawei smartphones with software Victoria-AL00 8.0.0.336a(C00) have an information leakage vulnerability. Because an interface does not verify authorization correctly, attackers can exploit an application with the authorization of phone state to obtain user location additionally.

  • CVE-2018-1999004MedJul 23, 2018
    risk 0.21cvss 4.3epss 0.01

    A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java that allows attackers with Overall/Read permission to initiate agent launches, and abort in-progress agent launches.

  • CVE-2018-1999003MedJul 23, 2018
    risk 0.21cvss 4.3epss 0.01

    A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allows attackers with Overall/Read permission to cancel queued builds.

  • CVE-2017-2611MedMay 8, 2018
    risk 0.21cvss 4.3epss 0.02

    Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jenkins to trigger these…

  • CVE-2018-1000109MedMar 13, 2018
    risk 0.21cvss 4.3epss 0.01

    An improper authorization vulnerability exists in Jenkins Google Play Android Publisher Plugin version 1.6 and earlier in GooglePlayBuildStepDescriptor.java that allow an attacker to obtain credential IDs.

  • CVE-2018-1000105MedMar 13, 2018
    risk 0.21cvss 4.3epss 0.01

    An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to retrieve some configuration information about Gerrit in Jenkins.

  • CVE-2026-92945MedSep 17, 2026
    risk 0.20cvss 4.2epss 0.00

    vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with allowlisted modules by performing…

  • CVE-2026-92130LowSep 16, 2026
    risk 0.20cvss 3.1epss 0.00

    Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.

  • CVE-2023-45023MedSep 14, 2026
    risk 0.20cvss 4.2epss 0.00

    The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.

  • CVE-2026-87652LowSep 9, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87614LowSep 9, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-87485LowSep 9, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87452LowSep 9, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect authorization in GPU in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-86487LowSep 7, 2026
    risk 0.20cvss 3.1epss 0.00

    In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content

  • CVE-2026-78587LowSep 2, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership during multi-part data upload operations, allowing any authenticated agent to…

  • CVE-2026-84355LowSep 2, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-84331LowSep 2, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-78606MedSep 1, 2026
    risk 0.20cvss 4.2epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated principals originating from different authentication realms share…