VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 60 of 187
  • CVE-2019-17014HigJan 8, 2020
    risk 0.48cvss 7.4epss 0.01

    If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-origin information leak. This vulnerability affects Firefox < 71.

  • CVE-2019-6855HigJan 6, 2020
    risk 0.48cvss 7.3epss 0.01

    Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the…

  • CVE-2026-9816HigAug 17, 2026
    risk 0.47cvss 8.3epss 0.00

    Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board admin to arbitrary users via POST…

  • CVE-2026-71383HigAug 11, 2026
    risk 0.47cvss 7.3epss 0.00

    is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized read and write access, causing a limited disruption to availability.…

  • CVE-2026-18635HigAug 11, 2026
    risk 0.47cvss 7.2epss 0.00

    Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to…

  • CVE-2026-19010HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packages/main/src/index.ts of the component Message API Endpoint. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit…

  • CVE-2026-18255HigJul 29, 2026
    risk 0.47cvss 7.2epss 0.00

    A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.

  • CVE-2026-53853HigJun 16, 2026
    risk 0.47cvss 8.3epss 0.00

    OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments for allowlisted executables on Linux and macOS systems. Attackers can bypass configured argPattern restrictions by directly…

  • CVE-2026-11577HigJun 8, 2026
    risk 0.47cvss 7.2epss 0.00

    A flaw was found in Keycloak. A limited administrator can exploit an improper access control vulnerability in the POST /admin/realms/{realm}/partialImport endpoint. This allows them to bypass Fine-Grained Admin Permissions (FGAP) and escalate their privileges to a full realm…

  • CVE-2026-9350HigMay 24, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This affects the function check_all_command_guards of the file tools/approval.py of the component Batch Runner. Such manipulation leads to missing authorization. The attack can be launched remotely. The…

  • CVE-2025-10908HigMay 11, 2026
    risk 0.47cvss 7.3epss 0.00

    Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass Key methods. This bypasses the intended security control that should prevent access to accounts that have been locked. This…

  • CVE-2026-0562HigMar 29, 2026
    risk 0.47cvss 8.3epss 0.00

    A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other users. The `respond_request()` function in `backend/routers/friends.py` does not implement proper authorization checks,…

  • CVE-2026-1497HigMar 11, 2026
    risk 0.47cvss 7.2epss 0.00

    Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario:  an admin that intends to give a user an access to a remote database constituent "namespace.name" will inadvertently…

  • CVE-2026-27803HigMar 4, 2026
    risk 0.47cvss 8.3epss 0.00

    Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several management operations as long as they have access to the…

  • CVE-2026-27802HigMar 4, 2026
    risk 0.47cvss 8.3epss 0.00

    Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permission update to unauthorized collections by Manager. This issue has been patched in…

  • CVE-2026-23572HigFeb 5, 2026
    risk 0.47cvss 7.2epss 0.00

    Improper access control in the TeamViewer Full and Host clients (Windows, macOS, Linux) prior version 15.74.5 allows an authenticated user to bypass additional access controls with “Allow after confirmation” configuration in a remote…

  • CVE-2025-13806HigDec 1, 2025
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthModule.java of the component Transaction…

  • CVE-2025-13063HigNov 12, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead to missing authorization. The attack may be performed from remote. The exploit has been published and may be used. Multiple endpoints are affected.

  • CVE-2025-12925HigNov 10, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/deleteDic of the file src/main/java/com/rymcu/forest/lucene/api/UserDicController.java. The manipulation results in missing…

  • CVE-2025-55177MedKEVAug 29, 2025
    risk 0.47cvss 5.4epss 0.04

    Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a…