VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 99 of 187
  • CVE-2019-3403MedMay 22, 2019
    risk 0.39cvss 5.3epss 0.53

    The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.

  • CVE-2019-3827HigMar 25, 2019
    risk 0.39cvss 7.0epss 0.00

    An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious…

  • CVE-2018-15468MedAug 17, 2018
    risk 0.39cvss 6.0epss 0.00

    An issue was discovered in Xen through 4.11.x. The DEBUGCTL MSR contains several debugging features, some of which virtualise cleanly, but some do not. In particular, Branch Trace Store is not virtualised by the processor, and software has to be careful to configure it suitably…

  • CVE-2026-54180higAug 20, 2026
    risk 0.38cvss epss

    ## Summary Backpack CRUD's list and read operations correctly apply any query scopes registered via `addClause()` / `addBaseClause()` (e.g. tenant isolation, user ownership). However, the **Update**, **Delete**, and **Reorder** operations bypassed these scopes, fetching records…

  • CVE-2026-18674HigAug 17, 2026
    risk 0.38cvss epss 0.00

    On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone identity derived from the connection. Authenticated zones can have the global…

  • CVE-2026-73049MedAug 14, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks endpoint that consults the forbidden access list instead of the visibility list when filtering backlinks. Anonymous readers can supply a publicly visible database row…

  • CVE-2026-72792MedAug 12, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts from password-protected documents to unauthenticated readers. Attackers can enumerate tag vocabulary and internal terminology from…

  • CVE-2026-72788MedAug 12, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator workspace state from publish readers. Unauthenticated attackers can retrieve the administrator's open documents, search terms,…

  • CVE-2026-37171MedAug 7, 2026
    risk 0.38cvss 5.9epss 0.00

    A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant.

  • CVE-2026-54698MedJul 7, 2026
    risk 0.38cvss 5.9epss 0.00

    Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a where clause on a table computed field (returning SETOF some_table) to infer row values that ought to be filtered for their role based on some_table's…

  • CVE-2026-12352MedJul 7, 2026
    risk 0.38cvss 5.9epss 0.00

    This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.

  • CVE-2026-50008MedJun 12, 2026
    risk 0.38cvss epss 0.00

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, the routeAllowList server option restricts external client access to a configured list of REST API routes. The check is…

  • CVE-2026-41470MedMay 19, 2026
    risk 0.38cvss 5.9epss 0.00

    LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a…

  • CVE-2026-5384MedApr 7, 2026
    risk 0.38cvss 5.8epss 0.00

    An issue that could allow a credential to be updated and used for a task from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N…

  • CVE-2026-5378MedApr 7, 2026
    risk 0.38cvss 5.8epss 0.00

    An issue that allowed administrators to create and update users outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N (5.8…

  • CVE-2026-5374MedApr 7, 2026
    risk 0.38cvss 5.8epss 0.00

    An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A…

  • CVE-2025-66378MedDec 25, 2025
    risk 0.38cvss 5.9epss 0.00

    Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node.

  • CVE-2025-54265MedOct 14, 2025
    risk 0.38cvss 5.9epss 0.01

    Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit…

  • CVE-2024-49208MedOct 22, 2024
    risk 0.38cvss 5.9epss 0.00

    Archer Platform 2024.03 before version 2024.08 is affected by an authorization bypass vulnerability related to supporting application files. A remote unprivileged attacker could potentially exploit this vulnerability to elevate their privileges and delete system icons.

  • CVE-2024-28174MedMar 6, 2024
    risk 0.38cvss 5.8epss 0.00

    In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly