VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 75 of 187
  • CVE-2026-71518HigAug 17, 2026
    risk 0.42cvss 7.5epss 0.00

    Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash…

  • CVE-2026-19726MedAug 16, 2026
    risk 0.42cvss 6.5epss 0.00

    The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above to read the full configuration of any chart on the site, including charts the Visualizer WordPress plugin…

  • CVE-2026-58427HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

  • CVE-2026-58417HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    REST API exposes organization membership of private organizations to public

  • CVE-2026-73285HigAug 12, 2026
    risk 0.42cvss 7.5epss 0.00

    RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_tag incorrectly for PreparedIamMode::Opa,…

  • CVE-2026-64952MedAug 12, 2026
    risk 0.42cvss 6.5epss 0.00

    The hunt_delete() VQL function allows deleting hunts.  Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned to the "investigator" role) instead of the "DELETE_RESULTS" permission (usually only assigned to "administrators").

  • CVE-2026-18696MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is…

  • CVE-2026-48411MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue…

  • CVE-2026-63512MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.

  • CVE-2026-48375MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue…

  • CVE-2026-19345MedAug 9, 2026
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in missing authorization. It is possible to launch the attack remotely. The exploit…

  • CVE-2026-48076MedAug 6, 2026
    risk 0.42cvss 6.5epss 0.00

    OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1.0.1 and prior consists of three calls: `bootstrap-challenge` (returns a 16-bit PoW challenge with `difficulty=4` leading hex…

  • CVE-2026-64640MedAug 6, 2026
    risk 0.42cvss 6.5epss 0.00

    Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog's…

  • CVE-2026-50749MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. Users are…

  • CVE-2026-71247MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields belonging to any later-or-equal-order, not-yet-signed recipient in the same envelope, with no restriction on field type. A newer V2…

  • CVE-2026-62927HigAug 4, 2026
    risk 0.42cvss 7.5epss 0.00

    In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.

  • CVE-2026-18572MedAug 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request…

  • CVE-2026-18203MedJul 31, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a…

  • CVE-2026-54719HigJul 28, 2026
    risk 0.42cvss 7.5epss 0.00

    goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticated reads of files protected only…

  • CVE-2026-13060MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and during execution. Affected scenarios…