VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,238)

page 208 of 212
  • CVE-2026-25767HigFeb 12, 2026
    risk 0.00cvss 8.1epss 0.00

    LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymaker” tag, could create shovels bypassing access controls. an authenticated user with the "Policymaker" management tag could exploit it to read messages from…

  • CVE-2026-25924HigFeb 11, 2026
    risk 0.00cvss 8.4epss 0.01

    Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remote Code Execution (RCE). Although the application correctly hides the plugin…

  • CVE-2026-2208MedFeb 8, 2026
    risk 0.00cvss 4.3epss 0.00

    A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the component Rules Handler. The manipulation leads to missing authorization. The attack can be initiated remotely. Upgrading to version…

  • CVE-2026-1897MedFeb 5, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/methods/positionHistory.js of the component Position-History Tracking. The manipulation results in missing authorization. The attack may be performed from…

  • CVE-2026-23837CriJan 19, 2026
    risk 0.00cvss 9.8epss 0.01

    MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and poetntially earlier versions allows unauthenticated users to bypass the mandatory authentication check in the roleBasedAuthMiddleware. By simply not providing…

  • CVE-2026-22784MedJan 12, 2026
    risk 0.00cvss 4.3epss 0.00

    Lychee is a free, open-source photo-management tool. Prior to 7.1.0, an authorization vulnerability exists in Lychee's album password unlock functionality that allows users to gain possibly unauthorized access to other users' password-protected albums. When a user unlocks a…

  • CVE-2025-5199HigJul 12, 2025
    risk 0.00cvss 7.3epss 0.00

    In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed with administrative privileges by a Launch Daemon during system startup.

  • CVE-2025-48475HigMay 29, 2025
    risk 0.00cvss 8.1epss 0.00

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the System does not provide a check on which "clients" of the System an authorized user can view and edit, and which ones they cannot. As a result, an authorized user who does not have access…

  • CVE-2025-48474HigMay 29, 2025
    risk 0.00cvss 8.1epss 0.00

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application incorrectly checks user access rights for conversations. Users with show_only_assigned_conversations enabled can assign themselves to an arbitrary conversation from the…

  • CVE-2025-48473MedMay 29, 2025
    risk 0.00cvss 4.3epss 0.00

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, when creating a conversation from a message in another conversation, there is no check to ensure that the user has the ability to view this message. Thus, the user can view arbitrary messages…

  • CVE-2025-48472HigMay 29, 2025
    risk 0.00cvss 8.1epss 0.00

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, there is no check to ensure that the user is disabling notifications for the mailbox to which they already have access. Moreover, the code explicitly implements functionality that if the user…

  • CVE-2025-48373CriMay 22, 2025
    risk 0.00cvss 9.1epss 0.00

    Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to redirect users to different panels based on their role. Prior to version 1.0.1, this implementation poses a serious security risk because it assumes that the…

  • CVE-2025-47930MedMay 16, 2025
    risk 0.00cvss 5.3epss 0.00

    Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access control mechanism can be circumvented by creating a private or web-public channel, and then changing the channel privacy to public. A…

  • CVE-2025-32796MedApr 18, 2025
    risk 0.00cvss 6.5epss 0.00

    Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enable or disable apps through the API, even though the web UI button for this action is disabled and normal users are not permitted to…

  • CVE-2024-7039Mar 20, 2025
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-10109HigMar 20, 2025
    risk 0.00cvss 8.3epss 0.01

    A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "/api/system/custom-models". This access enables them to modify the model's API key and base path, leading to potential API key…

  • CVE-2025-26532LowFeb 24, 2025
    risk 0.00cvss 3.1epss 0.00

    Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.

  • CVE-2025-26531LowFeb 24, 2025
    risk 0.00cvss 3.1epss 0.00

    Insufficient capability checks made it possible to disable badges a user does not have permission to access.

  • CVE-2025-26526MedFeb 24, 2025
    risk 0.00cvss 6.5epss 0.00

    Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.

  • CVE-2025-0781HigJan 28, 2025
    risk 0.00cvss 8.6epss 0.00

    An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.