VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 66 of 209
  • CVE-2021-3563HigAug 26, 2022
    risk 0.48cvss 7.4epss 0.02

    A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and…

  • CVE-2022-30203HigJul 12, 2022
    risk 0.48cvss 7.4epss 0.01

    Windows Boot Manager Security Feature Bypass Vulnerability

  • CVE-2022-26668HigJun 20, 2022
    risk 0.48cvss 7.3epss 0.01

    ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform partial system operations or cause partial disrupt of service.

  • CVE-2021-36778HigMay 2, 2022
    risk 0.48cvss 7.3epss 0.01

    A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects: SUSE Rancher Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.

  • CVE-2019-17014HigJan 8, 2020
    risk 0.48cvss 7.4epss 0.01

    If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-origin information leak. This vulnerability affects Firefox < 71.

  • CVE-2019-6855HigJan 6, 2020
    risk 0.48cvss 7.3epss 0.01

    Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the…

  • CVE-2026-63443HigSep 15, 2026
    risk 0.47cvss 8.3epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request URL when the port is the…

  • CVE-2026-91778HigSep 15, 2026
    risk 0.47cvss —epss 0.00

    In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would allow the script to execute without the…

  • CVE-2026-87090HigSep 10, 2026
    risk 0.47cvss 8.3epss 0.00

    Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker with a token granting node-write permission…

  • CVE-2026-88939HigSep 10, 2026
    risk 0.47cvss 8.3epss 0.00

    knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.

  • CVE-2026-86665HigSep 8, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly…

  • CVE-2026-84173HigSep 7, 2026
    risk 0.47cvss —epss 0.00

    In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard. An authenticated workload with access restricted by such a rule can submit a…

  • CVE-2026-85512HigSep 4, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation of the argument ID results in missing authorization. The attack can be executed remotely. The…

  • CVE-2026-85538HigSep 4, 2026
    risk 0.47cvss —epss 0.00

    An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org permissions. The affected attribute deletion paths relied on organization membership checks performed by…

  • CVE-2026-63137HigSep 1, 2026
    risk 0.47cvss 8.3epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a…

  • CVE-2026-75921HigSep 1, 2026
    risk 0.47cvss 7.2epss 0.01

    The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.9 via the upload_template_kit function. This is…

  • CVE-2026-75542HigAug 24, 2026
    risk 0.47cvss —epss 0.00

    Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories permission to read another organization's private packages. When an API key is exchanged for a token through the OAuth client_credentials grant,…

  • CVE-2026-50173HigAug 19, 2026
    risk 0.47cvss —epss 0.01

    Flow-Like is a platform for building end-to-end use cases. Prior to version 1.0.4, `GET /api/v1/apps/{app_id}/invoke/presign` grants Azure Blob Storage SAS credentials with write and delete access to app content to any app member that has `ExecuteEvents`, even when that member…

  • CVE-2026-9816HigAug 17, 2026
    risk 0.47cvss 8.3epss 0.00

    Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board admin to arbitrary users via POST…

  • CVE-2026-71383HigAug 11, 2026
    risk 0.47cvss 7.3epss 0.00

    is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized read and write access, causing a limited disruption to availability.…