VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,235)

page 204 of 212
  • CVE-2026-54563HigJul 15, 2026
    risk 0.00cvss 7.1epss 0.00

    Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a configured folder can send paths such as /dav/%2e%2e/outside.txt because stripPrefix in pkg/webdav/webdav.go joins the decoded request suffix to the account…

  • CVE-2026-60087MedJul 15, 2026
    risk 0.00cvss 6.1epss 0.00

    PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arbitrary arguments. Attackers can exploit this by obtaining approval for a benign operation and then executing dangerous file write…

  • CVE-2026-15752HigJul 14, 2026
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the component Backend User Endpoint. Performing a manipulation results in missing authorization. The attack…

  • CVE-2026-15641HigJul 14, 2026
    risk 0.00cvss 7.1epss 0.00

    Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver…

  • CVE-2026-62198MedJul 13, 2026
    risk 0.00cvss 4.3epss 0.00

    OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to perform actions requiring stronger policy checks. Attackers can exploit misconfigured input paths to bypass intended authorization…

  • CVE-2026-62193MedJul 13, 2026
    risk 0.00cvss 4.9epss 0.00

    OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) check. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path could execute or…

  • CVE-2026-62192HigJul 13, 2026
    risk 0.00cvss 8.1epss 0.00

    OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip cross-provider…

  • CVE-2026-62191HigJul 13, 2026
    risk 0.00cvss 7.1epss 0.00

    OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip requester…

  • CVE-2026-62190HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.01

    OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can leverage configured input paths to bypass durable exec approval…

  • CVE-2026-62188HigJul 13, 2026
    risk 0.00cvss 8.1epss 0.00

    OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could ignore per-account disablement settings. When the affected feature is enabled and reachable, a lower-trust caller or configured…

  • CVE-2026-62187HigJul 13, 2026
    risk 0.00cvss 8.1epss 0.00

    OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configured input path could perform actions that should have required a stronger authorization or policy check, resulting in unauthorized…

  • CVE-2026-62186HigJul 13, 2026
    risk 0.00cvss 7.6epss 0.00

    OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to bypass admin…

  • CVE-2026-58408MedJul 13, 2026
    risk 0.00cvss 6.5epss 0.00

    ChurchCRM is an open-source church management system. Prior to version 7.4.0, a low-privileged user can bypass the /admin/export UI and exfiltrate the entire member directory. The POST /CSVCreateFile.php endpoint generates and streams a CSV containing the full Personally…

  • CVE-2026-15541HigJul 13, 2026
    risk 0.00cvss 7.3epss 0.01

    A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component Master Websocket Handler. Executing a manipulation of the argument Agent can lead to missing authorization. It is…

  • CVE-2026-15507MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation results in missing authorization. Remote exploitation of the attack is possible. The…

  • CVE-2026-61874LowJul 12, 2026
    risk 0.00cvss 3.1epss 0.00

    filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind. Attackers can delete a shared directory using a trailing-slash path, then recreate the same…

  • CVE-2026-56252MedJul 12, 2026
    risk 0.00cvss 5.4epss 0.00

    Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint that allows app-scoped API keys to invoke org-scoped webhook operations. Attackers with app-scoped credentials can trigger signed outbound webhook deliveries for arbitrary…

  • CVE-2026-1359HigJul 11, 2026
    risk 0.00cvss 8.8epss 0.00

    The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. This makes it possible for authenticated…

  • CVE-2026-59154MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct Meteor collection allow rules for Checklists and ChecklistItems because updates are authorized only against the current source doc.cardId and do not inspect…

  • CVE-2026-39903HigJul 10, 2026
    risk 0.00cvss 7.1epss 0.00

    Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a single-character operator error causes the permission check to always pass regardless of user…