VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 40 of 209
  • CVE-2026-88008CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns…

  • CVE-2026-88007CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a transport dedicated to each…

  • CVE-2026-85597CriSep 4, 2026
    risk 0.52cvss 9.1epss 0.00

    Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected…

  • CVE-2026-73475CriSep 2, 2026
    risk 0.52cvss 9.1epss 0.00

    Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.

  • CVE-2026-18918CriAug 28, 2026
    risk 0.52cvss —epss 0.00

    In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server. In those cases, application that based their authz filters upon Lyo-provided `AbstractAdapterCredentialsFilter`, are vulnerable. An…

  • CVE-2026-16644CriAug 25, 2026
    risk 0.52cvss 9.1epss 0.00

    Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.

  • CVE-2026-68525CriAug 25, 2026
    risk 0.52cvss 9.1epss 0.01

    Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1…

  • CVE-2026-65182CriAug 25, 2026
    risk 0.52cvss 9.1epss 0.01

    Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1…

  • CVE-2026-59689HigJul 27, 2026
    risk 0.52cvss 8.0epss 0.00

    An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting…

  • CVE-2026-53512CriJul 15, 2026
    risk 0.52cvss 9.1epss 0.00

    Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession of the bound refreshToken row and matching client_id, without…

  • CVE-2026-20706CriJul 3, 2026
    risk 0.52cvss 9.1epss 0.01

    Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.

  • CVE-2026-32967CriJun 17, 2026
    risk 0.52cvss 9.1epss 0.00

    Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

  • CVE-2026-35482HigJun 2, 2026
    risk 0.52cvss 8.0epss 0.00

    alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox escape vulnerability in the alf.io extension script engine allows an authenticated administrator to execute arbitrary operating system…

  • CVE-2026-22872CriJun 1, 2026
    risk 0.52cvss 9.1epss 0.01

    Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantResource RawItems processing logic forcibly sets the namespace, this is ineffective for cluster-scoped resources. Prior to version…

  • CVE-2026-42032CriMay 13, 2026
    risk 0.52cvss 9.1epss 0.00

    CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to bypass authorization in order to gain access to private resources and PostgreSQL system…

  • CVE-2026-44221CriMay 12, 2026
    risk 0.52cvss 9.0epss 0.00

    ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database on the same server. Two distinct defects contributed: (1)…

  • CVE-2026-42889CriMay 12, 2026
    risk 0.52cvss 9.1epss 0.00

    Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSocket endpoints. When authentication is configured, WebSocket connections without a token query parameter were incorrectly treated…

  • CVE-2026-42571CriMay 9, 2026
    risk 0.52cvss —epss 0.00

    Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.24.0 to before 7.24.2, there is a a privilege escalation vulnerability affecting Pelican's Web User Interface (WebUI). This attack…

  • CVE-2026-43566CriMay 5, 2026
    risk 0.52cvss 9.1epss 0.00

    OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade logic skips webhook wake events carrying untrusted content. Attackers can exploit this by sending untrusted webhook wake events to preserve owner-like…

  • CVE-2026-5712HigApr 29, 2026
    risk 0.52cvss 8.0epss 0.00

    This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.