VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 69 of 209
  • CVE-2021-39155HigAug 24, 2021
    risk 0.47cvss 8.3epss 0.01

    Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. According to [RFC 4343](https://datatracker.ietf.org/doc/html/rfc4343), Istio authorization policy…

  • CVE-2021-33335HigAug 3, 2021
    risk 0.47cvss 7.2epss 0.01

    Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows remote authenticated users with permission to update/edit users to take over a company administrator user account by editing the…

  • CVE-2021-23015HigMay 10, 2021
    risk 0.47cvss 7.2epss 0.01

    On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an authenticated user assigned the 'Administrator' role may be able to bypass Appliance Mode restrictions utilizing undisclosed iControl…

  • CVE-2021-0319HigJan 11, 2021
    risk 0.47cvss 7.3epss 0.00

    In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without appropriate permissions due to a permissions bypass. This could lead to local escalation of privilege that grants access to nearby MAC…

  • CVE-2020-13322HigSep 30, 2020
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthorized user can create and delete deploy tokens.

  • CVE-2020-5343HigMay 4, 2020
    risk 0.47cvss 7.3epss 0.00

    Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permissions vulnerability. A local authenticated malicious user with low privileges could exploit this vulnerability to gain unauthorized access…

  • CVE-2018-7079HigDec 7, 2018
    risk 0.47cvss 7.2epss 0.01

    Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute those operations regardless of privilege level. This could…

  • CVE-2018-6980HigNov 13, 2018
    risk 0.47cvss 7.2epss 0.01

    VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registration method. Successful exploitation of this issue may allow Admin users with view only permission to perform certain administrative…

  • CVE-2026-93594HigSep 18, 2026
    risk 0.46cvss 8.1epss 0.00

    ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through LSM index files or the TimeSeries engine never invoke that…

  • CVE-2026-93593HigSep 18, 2026
    risk 0.46cvss 8.1epss 0.00

    ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets. An authenticated low-privilege user can read or insert TimeSeries…

  • CVE-2026-92793HigSep 16, 2026
    risk 0.46cvss 8.1epss 0.00

    GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter. Attackers can append a query string containing the admin prefix followed by /logout to reach…

  • CVE-2026-92782HigSep 16, 2026
    risk 0.46cvss 8.1epss 0.00

    Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, and update records in foreign collections…

  • CVE-2026-92776HigSep 16, 2026
    risk 0.46cvss 8.1epss 0.00

    Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing…

  • CVE-2026-54076HigSep 15, 2026
    risk 0.46cvss 8.1epss 0.00

    ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to LocalDocumentType.createProperty, while the remaining public schema mutators in engine/src/main/java/com/arcadedb/schema/LocalDocumentType.java and…

  • CVE-2026-57134HigSep 15, 2026
    risk 0.46cvss 8.2epss 0.00

    PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth policies accept any non-empty…

  • CVE-2026-70283HigSep 8, 2026
    risk 0.46cvss 7.0epss 0.00

    Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.

  • CVE-2026-86544HigSep 7, 2026
    risk 0.46cvss 8.1epss 0.00

    knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate…

  • CVE-2026-77125HigSep 2, 2026
    risk 0.46cvss —epss 0.00

    A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorization check. A user granted only the nexus:blobstores:create permission could invoke these endpoints to convert…

  • CVE-2026-14199HigSep 2, 2026
    risk 0.46cvss 7.1epss 0.00

    Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could…

  • CVE-2026-73724HigSep 1, 2026
    risk 0.46cvss 7.1epss 0.00

    Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.