VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 43 of 209
  • CVE-2026-58424HigJul 3, 2026
    risk 0.51cvss 8.9epss 0.00

    Permanent Fork PR Workflow Approval Gate Bypass

  • CVE-2026-21031HigJun 5, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.

  • CVE-2025-32348HigJun 1, 2026
    risk 0.51cvss 7.8epss 0.00

    In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-28951HigMay 11, 2026
    risk 0.51cvss 7.8epss 0.00

    An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to gain root privileges.

  • CVE-2026-39454HigApr 20, 2026
    risk 0.51cvss 7.8epss 0.00

    SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may manipulate and/or place arbitrary files within the installation folder of the product. As a result,…

  • CVE-2026-34040HigMar 31, 2026
    risk 0.51cvss 8.8epss 0.09

    Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.

  • CVE-2026-26141HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

  • CVE-2026-29127HigMar 5, 2026
    risk 0.51cvss 7.8epss 0.00

    The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured with permissions 0777, granting read, write, and execute access to all local users on the system, which may cause local privilege…

  • CVE-2026-29126HigMar 5, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) SFX2100 Satellite Receiver allows a local unprivileged attacker to potentially execute arbitrary commands with root privileges (local privilege escalation and…

  • CVE-2025-4960HigFeb 19, 2026
    risk 0.51cvss 7.8epss 0.00

    The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege escalation vulnerability due to multiple flaws in its implementation. It fails to properly authenticate clients over the XPC protocol and does not correctly…

  • CVE-2026-21274HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could leverage this vulnerability to bypass security measures and execute…

  • CVE-2025-47382HigDec 18, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while loading an invalid firmware in boot loader.

  • CVE-2025-14305HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    ListCheck.exe developed by Acer has a Local Privilege Escalation vulnerability. Authenticated local attackers can replace ListCheck.exe with a malicious executable of the same name, which will be executed by the system and result in privilege escalation.

  • CVE-2025-43387HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. A malicious app may be able to gain root privileges.

  • CVE-2025-48523HigSep 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2025-32333HigSep 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-26436HigSep 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…

  • CVE-2025-22428HigSep 2, 2025
    risk 0.51cvss 7.8epss 0.00

    In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user from the primary user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution…

  • CVE-2024-7457HigJun 11, 2025
    risk 0.51cvss 7.8epss 0.00

    The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of macOS’s authorization model. Instead of validating the client's authorization reference, the helper invokes AuthorizationCopyRights() using its own privileged context (root),…

  • CVE-2025-25251HigMay 28, 2025
    risk 0.51cvss 7.8epss 0.00

    An Incorrect Authorization vulnerability [CWE-863] in FortiClient Mac 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 may allow a local attacker to escalate privileges via crafted XPC messages.