VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 85 of 209
  • CVE-2026-79177MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79134MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79133MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79107MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in TabGroups in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially leak sensitive information via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-79088MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79060MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79038MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79023MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79005MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-78975MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78907MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-59318MedAug 21, 2026
    risk 0.42cvss 6.5epss 0.00

    In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invoked, potentially…

  • CVE-2026-14949MedAug 20, 2026
    risk 0.42cvss 6.5epss 0.00

    A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.

  • CVE-2026-55643HigAug 19, 2026
    risk 0.42cvss —epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserHasAccess. The /api/v1/users and…

  • CVE-2026-75480MedAug 17, 2026
    risk 0.42cvss 6.5epss 0.00

    OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret…

  • CVE-2026-71518HigAug 17, 2026
    risk 0.42cvss 7.5epss 0.00

    Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash…

  • CVE-2026-19726MedAug 16, 2026
    risk 0.42cvss 6.5epss 0.00

    The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above to read the full configuration of any chart on the site, including charts the Visualizer WordPress plugin…

  • CVE-2026-58427HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

  • CVE-2026-58417HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    REST API exposes organization membership of private organizations to public

  • CVE-2026-73285HigAug 12, 2026
    risk 0.42cvss 7.5epss 0.00

    RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_tag incorrectly for PreparedIamMode::Opa,…