VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 31 of 187
  • CVE-2026-24724HigJun 10, 2026
    risk 0.53cvss 8.1epss 0.00

    An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass intended access restrictions. We have already fixed the vulnerability in the following version: File…

  • CVE-2026-8046HigMay 26, 2026
    risk 0.53cvss 8.1epss 0.00

    The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those with higher privileges.

  • CVE-2026-44553HigMay 15, 2026
    risk 0.53cvss 8.1epss 0.00

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, administrative role changes and user deletions do not iterate SESSION_POOL to disconnect affected sessions. As a result, a user whose admin role has been revoked…

  • CVE-2026-44633HigMay 14, 2026
    risk 0.53cvss 8.1epss 0.00

    Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a REST user with lhchat/use to update a chat in a department they cannot read. The endpoint accepts arbitrary chat object…

  • CVE-2026-44260HigMay 12, 2026
    risk 0.53cvss 8.1epss 0.00

    efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is intended to prevent file modifications. When protected=true, elfinder_checkRisk enforces that the client sends readonly=true (matching the session value), but no…

  • CVE-2026-26289HigMay 12, 2026
    risk 0.53cvss 8.2epss 0.00

    PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions only.

  • CVE-2026-42349HigMay 11, 2026
    risk 0.53cvss 8.1epss 0.00

    Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when…

  • CVE-2025-40897HigApr 15, 2026
    risk 0.53cvss 8.1epss 0.00

    An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restriction not being properly enforced for users with view-only privileges. An authenticated user with view-only privileges for the Threat Intelligence functionality…

  • CVE-2026-23925HigMar 6, 2026
    risk 0.53cvss 8.1epss 0.00

    An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit…

  • CVE-2025-41078HigJan 12, 2026
    risk 0.53cvss 8.1epss 0.00

    Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges to list and access other user data, use user creation, modification, and deletion features, and escalate privileges by impersonating other users of the…

  • CVE-2025-59683HigDec 25, 2025
    risk 0.53cvss 8.2epss 0.00

    Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to…

  • CVE-2018-25146HigDec 24, 2025
    risk 0.53cvss 8.1epss 0.00

    Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system processes. Attackers can send arbitrary signals to kill background processes and system services through a hidden feature, potentially…

  • CVE-2023-7322HigOct 30, 2025
    risk 0.53cvss 8.1epss 0.01

    Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevertheless able to invoke API endpoints, resulting in unintended access to data and actions exposed via the API. This incorrect…

  • CVE-2025-54263HigOct 14, 2025
    risk 0.53cvss 8.1epss 0.01

    Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. A low-privileged attacker could leverage this vulnerability to bypass security measures and maintain unauthorized…

  • CVE-2025-3719HigOct 7, 2025
    risk 0.53cvss 8.1epss 0.00

    An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can issue administrative CLI commands, altering the device…

  • CVE-2025-30744HigJul 15, 2025
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Multiplatform Sync Errors). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2025-30743HigJul 15, 2025
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). The supported version that is affected is 12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2025-48466HigJun 24, 2025
    risk 0.53cvss 8.1epss 0.01

    Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs, potentially allowing remote control of relay channel which may lead to operational or safety risks.

  • CVE-2025-36546HigMay 7, 2025
    risk 0.53cvss 8.1epss 0.00

    On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance Mode; access via SSH key-based authentication is still allowed. For an attacker to exploit this vulnerability they must obtain the…

  • CVE-2025-43922HigApr 21, 2025
    risk 0.53cvss 8.1epss 0.00

    The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SYSTEM.