VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 59 of 187
  • CVE-2026-32918HigMar 29, 2026
    risk 0.48cvss 8.4epss 0.00

    OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent or sibling session state. Attackers can supply arbitrary sessionKey values to read or modify session data outside their sandbox…

  • CVE-2026-28513HigMar 10, 2026
    risk 0.48cvss 8.5epss 0.00

    Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, the OIDC token endpoint rejects an authorization code only when both the client ID is wrong and the code is expired. This allows cross-client code exchange and…

  • CVE-2025-55077HigAug 7, 2025
    risk 0.48cvss 7.4epss 0.00

    Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating system commands within the remote Microsoft Windows environment with the privileges of the authenticated user. Tyler Technologies deployed hardened remote…

  • CVE-2022-31671HigNov 14, 2024
    risk 0.48cvss 7.4epss 0.01

    Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying different job IDs, malicious authenticated users could read…

  • CVE-2022-31668HigNov 14, 2024
    risk 0.48cvss 7.4epss 0.00

    Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat…

  • CVE-2024-10173HigOct 20, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in didi DDMQ 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Console Module. The manipulation with the input /;login leads to improper authentication. The attack can be launched remotely.…

  • CVE-2024-39690HigAug 20, 2024
    risk 0.48cvss 8.4epss 0.01

    Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been taken over by a tenant (i.e., namespaces without the ownerReference field), thereby gaining control of that…

  • CVE-2023-50363HigApr 26, 2024
    risk 0.48cvss 7.4epss 0.00

    An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network. We have already fixed the vulnerability in the…

  • CVE-2023-6400HigMar 27, 2024
    risk 0.48cvss 7.4epss 0.00

    Incorrect Authorization vulnerability in OpenText™ ZENworks Configuration Management (ZCM) allows Unauthorized Use of Device Resources.This issue affects ZENworks Configuration Management (ZCM) versions: 2020 update 3, 23.3, and 23.4.

  • CVE-2023-5356HigJan 12, 2024
    risk 0.48cvss 7.3epss 0.01

    Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as…

  • CVE-2023-6837HigDec 15, 2023
    risk 0.48cvss 8.5epss 0.00

    Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met: * An IDP configured for federated authentication and JIT…

  • CVE-2023-45185HigDec 14, 2023
    risk 0.48cvss 7.4epss 0.01

    IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper authority checks the attacker could perform operations on the PC under the user's authority. IBM X-Force ID: 268273.

  • CVE-2020-36714HigOct 20, 2023
    risk 0.48cvss 7.4epss 0.00

    The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125. This makes it possible for authenticated attackers to access and interact with available AJAX…

  • CVE-2023-28352HigMay 31, 2023
    risk 0.48cvss 7.4epss 0.01

    An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system, an attacker-controlled artificial Student Console can connect to and attack a Teacher Console even after Enhanced Security Mode has been enabled.

  • CVE-2022-39956HigSep 20, 2022
    risk 0.48cvss 7.3epss 0.01

    The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will…

  • CVE-2022-39955HigSep 20, 2022
    risk 0.48cvss 7.3epss 0.01

    The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable back-end can potentially be exploited by declaring multiple…

  • CVE-2021-3563HigAug 26, 2022
    risk 0.48cvss 7.4epss 0.01

    A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and…

  • CVE-2022-30203HigJul 12, 2022
    risk 0.48cvss 7.4epss 0.01

    Windows Boot Manager Security Feature Bypass Vulnerability

  • CVE-2022-26668HigJun 20, 2022
    risk 0.48cvss 7.3epss 0.01

    ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform partial system operations or cause partial disrupt of service.

  • CVE-2021-36778HigMay 2, 2022
    risk 0.48cvss 7.3epss 0.01

    A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects: SUSE Rancher Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.