VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 84 of 209
  • CVE-2026-86073HigSep 8, 2026
    risk 0.42cvss 7.6epss 0.00

    n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to the consented resource but did not bind its refresh token. Refreshing checked only that the requested resource was…

  • CVE-2026-82074MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.00

    MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that causes the server's authorization subsystem to evaluate a different operation…

  • CVE-2026-82073MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.00

    A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges to bypass view-level authorization checks and access data from unauthorized collections when Atlas Search features are in use. The issue stems from insufficient…

  • CVE-2026-86493MedSep 7, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards

  • CVE-2026-86490MedSep 7, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint

  • CVE-2026-76560HigSep 7, 2026
    risk 0.42cvss 7.5epss 0.00

    A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching…

  • CVE-2026-82299MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

  • CVE-2026-85093MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers with MEMORY:READ permission can retrieve all users' stored conversation messages and personal data by…

  • CVE-2026-74769MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit this vulnerability, leading to Protection mechanism bypass.

  • CVE-2026-2688MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access…

  • CVE-2026-84332MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-84327MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-73727MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access sensitive information. A successful exploit allows an attacker to access data beyond what is authorized by the user's existing privilege level, which…

  • CVE-2026-82724HigAug 31, 2026
    risk 0.42cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash_phoenix invokes the SubdomainHook authorization callback with a nil tenant, so tenant-scoped access checks never see the tenant they are meant to enforce. AshPhoenix.LiveView.SubdomainHook.on_mount/4 attached a…

  • CVE-2026-56854HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback,…

  • CVE-2026-77438HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHiddenFromTree controls, allowing an unauthenticated visitor to read the titles, tree…

  • CVE-2026-80184HigAug 25, 2026
    risk 0.42cvss —epss 0.01

    In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentication path for reauthentication to escape their intended project scope. When an…

  • CVE-2026-80182HigAug 25, 2026
    risk 0.42cvss —epss 0.01

    In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain…

  • CVE-2026-79258MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79179MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low)