VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 83 of 209
  • CVE-2026-86043HigSep 16, 2026
    risk 0.42cvss 7.5epss 0.01

    Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper truncates the body presented to Open Policy Agent because the input.truncated_body signal is…

  • CVE-2026-90971MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection…

  • CVE-2026-54180HigSep 14, 2026
    risk 0.42cvss 7.6epss 0.00

    backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, the Update, Delete, and Reorder operations resolve records from the…

  • CVE-2026-68570MedSep 14, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information. This issue affects Apache Doris: from 2.0.0 through 2.1.*, from…

  • CVE-2026-89013HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.00

    Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip…

  • CVE-2026-19840MedSep 10, 2026
    risk 0.42cvss 6.5epss 0.00

    The Notiqoo WordPress plugin before 1.4.14 does not have capability checks on several of its AJAX actions and builds the name of the option to write from user input, allowing users with a role as low as contributor to modify arbitrary WordPress options, which can be used to…

  • CVE-2026-87629MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Sources in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-87626MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-87610MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87591MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

  • CVE-2026-87589MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87584MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87580MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in WebAppInstalls in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87519MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-87515MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87483MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Browser in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87476MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87473MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in FileHandling in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-87468MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87447MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: High)