VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 34 of 209
  • CVE-2026-87499HigSep 9, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-87471HigSep 9, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78626HigSep 8, 2026
    risk 0.53cvss 8.1epss 0.00

    The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application…

  • CVE-2026-76202HigSep 8, 2026
    risk 0.53cvss 8.2epss 0.00

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.

  • CVE-2026-82053HigSep 8, 2026
    risk 0.53cvss 8.1epss 0.00

    A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an unintended LDAP identity…

  • CVE-2026-82302HigSep 3, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

  • CVE-2026-78583HigSep 3, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic…

  • CVE-2026-84334HigSep 2, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

  • CVE-2026-76019HigAug 20, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17429HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host…

  • CVE-2026-19629HigAug 14, 2026
    risk 0.53cvss 8.1epss 0.00

    A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables…

  • CVE-2026-55987HigAug 13, 2026
    risk 0.53cvss 8.1epss 0.00

    OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)

  • CVE-2026-19550HigAug 11, 2026
    risk 0.53cvss 8.2epss 0.00

    A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an…

  • CVE-2026-18712HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.00

    An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different collection. This is due to insufficient…

  • CVE-2026-18690HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.00

    An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical system collections being dropped and…

  • CVE-2026-73090CriAug 11, 2026
    risk 0.53cvss 9.3epss 0.00

    PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying that byActor.url is authorized for the host in videoObject.id, allowing a…

  • CVE-2026-17594HigAug 7, 2026
    risk 0.53cvss —epss 0.01

    Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scoped to a specific repository format could…

  • CVE-2026-70474HigAug 4, 2026
    risk 0.53cvss 8.1epss 0.00

    Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The authorize, callback, and refresh handlers query…

  • CVE-2026-50528HigJul 14, 2026
    risk 0.53cvss 8.2epss 0.01

    Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-48349HigJul 14, 2026
    risk 0.53cvss 8.1epss 0.00

    Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is…