VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 38 of 187
  • CVE-2026-69278HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2026-61925HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-25652HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction.

  • CVE-2026-7867HigAug 6, 2026
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter,…

  • CVE-2026-43947HigJul 21, 2026
    risk 0.51cvss epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Code Execution vulnerability when `secureEnabled` is set to `true`. The `POST /api/runscript` endpoint checks authorization against the stored script's…

  • CVE-2026-43945HigJul 21, 2026
    risk 0.51cvss epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state…

  • CVE-2026-58424HigJul 3, 2026
    risk 0.51cvss 8.9epss 0.00

    Permanent Fork PR Workflow Approval Gate Bypass

  • CVE-2026-21031HigJun 5, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.

  • CVE-2025-32348HigJun 1, 2026
    risk 0.51cvss 7.8epss 0.00

    In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-28951HigMay 11, 2026
    risk 0.51cvss 7.8epss 0.00

    An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to gain root privileges.

  • CVE-2026-39454HigApr 20, 2026
    risk 0.51cvss 7.8epss 0.00

    SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may manipulate and/or place arbitrary files within the installation folder of the product. As a result,…

  • CVE-2026-34040HigMar 31, 2026
    risk 0.51cvss 8.8epss 0.10

    Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.

  • CVE-2026-26141HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

  • CVE-2026-29127HigMar 5, 2026
    risk 0.51cvss 7.8epss 0.00

    The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured with permissions 0777, granting read, write, and execute access to all local users on the system, which may cause local privilege…

  • CVE-2026-29126HigMar 5, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) SFX2100 Satellite Receiver allows a local unprivileged attacker to potentially execute arbitrary commands with root privileges (local privilege escalation and…

  • CVE-2025-4960HigFeb 19, 2026
    risk 0.51cvss 7.8epss 0.00

    The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege escalation vulnerability due to multiple flaws in its implementation. It fails to properly authenticate clients over the XPC protocol and does not correctly…

  • CVE-2026-21274HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could leverage this vulnerability to bypass security measures and execute…

  • CVE-2025-47382HigDec 18, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while loading an invalid firmware in boot loader.

  • CVE-2025-14305HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    ListCheck.exe developed by Acer has a Local Privilege Escalation vulnerability. Authenticated local attackers can replace ListCheck.exe with a malicious executable of the same name, which will be executed by the system and result in privilege escalation.

  • CVE-2025-43387HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. A malicious app may be able to gain root privileges.