VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 30 of 187
  • CVE-2023-5009HigSep 19, 2023
    risk 0.54cvss 8.2epss 0.08

    An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies. This was a bypass of…

  • CVE-2023-32629HigJul 26, 2023
    risk 0.54cvss 7.8epss 0.10

    Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr on Ubuntu kernels

  • CVE-2020-14321HigAug 16, 2022
    risk 0.54cvss 8.8epss 0.16

    In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.

  • CVE-2022-1631HigMay 9, 2022
    risk 0.54cvss 8.8epss 0.09

    Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows…

  • CVE-2021-21389HigMar 26, 2021
    risk 0.54cvss 8.1epss 0.14

    BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability…

  • CVE-2013-2574HigJan 29, 2020
    risk 0.54cvss 7.5epss 0.30

    An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /log/ directories, which could let a malicious user obtain sensitive information.

  • CVE-2019-0732HigApr 9, 2019
    risk 0.54cvss 7.8epss 0.04

    A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Security Feature Bypass Vulnerability'.

  • CVE-2018-9488HigNov 6, 2018
    risk 0.54cvss 7.8epss 0.00

    In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead to a local escalation of privilege, with System privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0…

  • CVE-2017-4915HigMay 22, 2017
    risk 0.54cvss 7.8epss 0.05

    VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privileges to root in a Linux host machine.

  • CVE-2026-19629HigAug 14, 2026
    risk 0.53cvss 8.1epss 0.00

    A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables…

  • CVE-2026-55987HigAug 13, 2026
    risk 0.53cvss 8.1epss 0.00

    OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)

  • CVE-2026-19550HigAug 11, 2026
    risk 0.53cvss 8.2epss 0.00

    A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an…

  • CVE-2026-18712HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.00

    An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different collection. This is due to insufficient…

  • CVE-2026-18690HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.00

    An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical system collections being dropped and…

  • CVE-2026-73090CriAug 11, 2026
    risk 0.53cvss 9.3epss 0.00

    PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying that byActor.url is authorized for the host in videoObject.id, allowing a…

  • CVE-2026-17594HigAug 7, 2026
    risk 0.53cvss epss 0.01

    Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scoped to a specific repository format could…

  • CVE-2026-50528HigJul 14, 2026
    risk 0.53cvss 8.2epss 0.01

    Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-47984HigJul 14, 2026
    risk 0.53cvss 8.2epss 0.01

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does…

  • CVE-2026-47339HigJun 19, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue affects Apache APISIX: from 2.14.1 through 3.16.0. Users are…

  • CVE-2026-53738HigJun 10, 2026
    risk 0.53cvss 8.1epss 0.00

    Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite plugin settings via the f parameter, bypassing per-function capability checks.