VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 39 of 187
  • CVE-2025-48523HigSep 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2025-32333HigSep 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-26436HigSep 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…

  • CVE-2025-22428HigSep 2, 2025
    risk 0.51cvss 7.8epss 0.00

    In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user from the primary user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution…

  • CVE-2024-7457HigJun 11, 2025
    risk 0.51cvss 7.8epss 0.00

    The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of macOS’s authorization model. Instead of validating the client's authorization reference, the helper invokes AuthorizationCopyRights() using its own privileged context (root),…

  • CVE-2025-25251HigMay 28, 2025
    risk 0.51cvss 7.8epss 0.00

    An Incorrect Authorization vulnerability [CWE-863] in FortiClient Mac 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 may allow a local attacker to escalate privileges via crafted XPC messages.

  • CVE-2025-23244HigMay 1, 2025
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability which could allow an unprivileged attacker to escalate permissions. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data…

  • CVE-2024-44305HigMar 21, 2025
    risk 0.51cvss 7.8epss 0.00

    This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able to gain root privileges.

  • CVE-2025-30074HigMar 16, 2025
    risk 0.51cvss 7.8epss 0.00

    Alludo Parallels Desktop before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms allows privilege escalation to root via the VM creation routine.

  • CVE-2024-45328HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.00

    An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged administrator to execute elevated CLI commands via the GUI console menu.

  • CVE-2025-0360HigMar 4, 2025
    risk 0.51cvss 7.8epss 0.00

    During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.

  • CVE-2024-40771HigJan 15, 2025
    risk 0.51cvss 7.8epss 0.00

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to execute arbitrary…

  • CVE-2024-12831HigDec 20, 2024
    risk 0.51cvss 7.8epss 0.00

    Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Arista NG Firewall. An attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2018-9374HigNov 28, 2024
    risk 0.51cvss 7.8epss 0.00

    In installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-7915HigNov 25, 2024
    risk 0.51cvss 7.8epss 0.00

    The application Sensei Mac Cleaner contains a local privilege escalation vulnerability, allowing an attacker to perform multiple operations as the root user. These operations include arbitrary file deletion and writing, loading and unloading daemons, manipulating file…

  • CVE-2023-21270HigNov 19, 2024
    risk 0.51cvss 7.8epss 0.00

    In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to incorrect permission flags cleared during an update. This could lead to local escalation of privilege with User execution…

  • CVE-2024-29821HigOct 18, 2024
    risk 0.51cvss 7.8epss 0.00

    Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.

  • CVE-2024-29213HigOct 18, 2024
    risk 0.51cvss 7.8epss 0.00

    Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.

  • CVE-2024-47560HigOct 1, 2024
    risk 0.51cvss 7.8epss 0.00

    RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is exploited, unintended processes may be executed in the sandbox environment. Even if malware is executed in the sandbox environment, it does not compromise the…

  • CVE-2024-44162HigSep 17, 2024
    risk 0.51cvss 7.8epss 0.00

    This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 16. A malicious application may gain access to a user's Keychain items.