VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 71 of 187
  • CVE-2025-8886MedOct 10, 2025
    risk 0.44cvss 6.7epss 0.00

    Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization, Incorrect Authorization vulnerability in Usta Information Systems Inc. Aybs Interaktif allows Privilege Abuse, Authentication Bypass. This…

  • CVE-2025-36578MedJun 10, 2025
    risk 0.44cvss 6.8epss 0.00

    Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

  • CVE-2025-3272MedMay 7, 2025
    risk 0.44cvss epss 0.00

    Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager.  The vulnerability could allow authenticated users to change their password without providing their old password. This issue affects Operations Bridge Manager: 24.2, 24.4.

  • CVE-2024-39328MedFeb 18, 2025
    risk 0.44cvss 6.8epss 0.00

    Insecure Permissions in Atos Eviden IDRA and IDCA before 2.7.0. A highly trusted role (Config Admin) could exceed their configuration privileges in a multi-partition environment and access some confidential data. Data integrity and availability is not at risk.

  • CVE-2024-54916MedFeb 11, 2025
    risk 0.44cvss 6.8epss 0.00

    An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate privileges by manipulating the return value of the checkPasscode method.

  • CVE-2025-24401MedJan 22, 2025
    risk 0.44cvss 6.8epss 0.00

    Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality…

  • CVE-2024-48911HigOct 14, 2024
    risk 0.44cvss 7.8epss 0.00

    OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0.9.4, where the config file is stored in an unprivileged user directory but the daemon is executed by root, it’s possible for the unprivileged user to change…

  • CVE-2024-9136MedSep 27, 2024
    risk 0.44cvss 6.7epss 0.00

    Access permission verification vulnerability in the App Multiplier module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-6979MedSep 10, 2024
    risk 0.44cvss 6.8epss 0.00

    Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts having more privileges than designed. The risk of exploitation is very low as it requires complex steps to execute,…

  • CVE-2024-5714MedJun 27, 2024
    risk 0.44cvss 6.8epss 0.01

    In lunary-ai/lunary version 1.2.4, an improper access control vulnerability allows members with team management permissions to manipulate project identifiers in requests, enabling them to invite users to projects in other organizations, change members to projects in other…

  • CVE-2024-3331MedJun 27, 2024
    risk 0.44cvss 6.8epss 0.00

    Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server allows The impact of this vulnerability depends on the privileges of the user…

  • CVE-2024-0160MedJun 12, 2024
    risk 0.44cvss 6.8epss 0.00

    Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.

  • CVE-2024-36365MedMay 29, 2024
    risk 0.44cvss 6.8epss 0.00

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent

  • CVE-2023-6355MedDec 18, 2023
    risk 0.44cvss 6.8epss 0.00

    Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local debug. This issue affects: Gallagher Controller 7000 9.00 prior to vCR9.00.231204b (distributed in 9.00.1507 (MR1)), 8.90 prior to…

  • CVE-2023-24047MedDec 4, 2023
    risk 0.44cvss 6.8epss 0.00

    An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via use of weak hashing algorithm.

  • CVE-2023-1832MedOct 4, 2023
    risk 0.44cvss 6.8epss 0.01

    An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.

  • CVE-2023-34724MedAug 28, 2023
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered in TECHView LA5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated privileges via the UART interface.

  • CVE-2023-4107MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.01

    Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin's details such as email, first name and last name.

  • CVE-2022-29871MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper access control in the Intel(R) CSME software installer before version 2239.3.7.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-30705MedAug 10, 2023
    risk 0.44cvss 6.8epss 0.00

    Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access privileged content providers as Galaxy Store permission.