CWE-285— Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
1,407 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 26 of 29
- CVE-2026-42202MEDIUMCVSS 6.5EG 6.52026-05-08
nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-toggle/toggle/{resource}/{resourceId}) was protected only by web + auth:<guard> middleware. Any user authenticated on t…
- CVE-2026-4248HIGHCVSS 8.0EG 8.02026-03-27
The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag being processed within post content via…
- CVE-2026-42609HIGHCVSS 8.1EG 8.12026-05-11
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with only user creation permissions) to overwrite existing accounts, including the primary admin…
- CVE-2026-42875MEDIUMCVSS 5.3EG 5.32026-05-11
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.0, Namespaced SecretStore resources that used CAProvider with type ConfigMap could resolve CA m…
- CVE-2026-42876MEDIUMCVSS 4.9EG 4.92026-05-11
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.1, a user who only has permission to create ExternalSecret resources can cause the operator to …
- CVE-2026-42902HIGHCVSS 7.8EG 7.82026-06-09
Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.
- CVE-2026-43515CRITICALCVSS 9.1EG 9.12026-05-12
Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.…
- CVE-2026-43912HIGHCVSS 8.7EG 8.72026-05-11
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the same organization as groups.groups_uuid, or a collections_groups.…
- CVE-2026-43983HIGHCVSS 8.1EG 8.12026-05-12
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) validates the refresh token's cryptographic integrity but does…
- CVE-2026-44208MEDIUMCVSS 6.9EG 6.92026-06-12
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "submit_discussion()" endpoint allows for unauthorized access to resources. This issue has been patched in versions 15.107…
- CVE-2026-44362MEDIUMCVSS 5.5EG 5.52026-07-06
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.20.0 and prior to version 4.11.0, a vulnerability in OP…
- CVE-2026-44504HIGHCVSS 8.6EG 8.62026-05-14
Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared instance are vulnerable to a cross-tenant IDOR. Any authenticated attacker, given another user's thread_id, can execute…
- CVE-2026-45147MEDIUMCVSS 4.3EG 4.32026-05-14
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with model.CheckAuth only, omitting both model.CheckAdminRole and model.CheckReadonly, despite the handler performing a confi…
- CVE-2026-45187MEDIUMCVSS 6.5EG 6.52026-05-19
Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
- CVE-2026-45275MEDIUMCVSS 6.5EG 6.52026-06-01
Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to force the system to share a file with app…
- CVE-2026-45297MEDIUMCVSS 5.3EG 5.32026-05-28
OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assist-stats routes via {project_id} case mismatch. ProjectAuthorizer.__call__ (OSS api/auth/auth_project.py:14-38 and EE e…
- CVE-2026-45337HIGHCVSS 7.6EG 7.62026-06-04
Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorization plugin treats any authenticated session as the owner of any pending device code because GET /device does not claim …
- CVE-2026-45345MEDIUMCVSS 6.5EG 6.52026-05-15
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.5.7, a user can modify another user's model even if its visibility is set to Private. By changing the access permissions during e…
- CVE-2026-45365MEDIUMCVSS 5.4EG 5.42026-05-15
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, an internal-only bypass_filter parameter is exposed on the /openai/chat/completions and /ollama/api/chat HTTP endpoints via…
- CVE-2026-45371HIGHCVSS 7.2EG 7.22026-05-14
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs. POST /api/graph/getGraph, POST /api/graph/getLocalGraph, POST /api/sync/setSyncInte…
- CVE-2026-4549LOWCVSS 3.1EG 3.12026-03-22
A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization byp…
- CVE-2026-45490HIGHCVSS 7.8EG 7.82026-06-09
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
- CVE-2026-45503MEDIUMCVSS 6.5EG 8.12026-06-09
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
- CVE-2026-45620MEDIUMCVSS 5.3EG 5.32026-05-18
WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: preg_match('/^@/', $_REQUEST['term']) and hard-coded rowCount=10. This enables…
- CVE-2026-4563MEDIUMCVSS 4.3EG 4.32026-03-23
A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the file application/index/controller/User.php of the component Member Order Detail Interface. This manipulation of the ar…
- CVE-2026-46484HIGHCVSS 8.1EG 8.12026-06-08
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This i…
- CVE-2026-46552MEDIUMCVSS 5.8EG 5.82026-05-21
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, shared-base sessions were granted the same base-member capabilities as authenticated viewers. Using only the shared-base UUID (xc-shared-base-id), an attacker c…
- CVE-2026-46605MEDIUMCVSS 4.3EG 4.32026-06-01
Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache ActiveMQ Broker: before 5.19.7, from…
- CVE-2026-46620MEDIUMCVSS 6.5EG 6.52026-05-26
e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on comment moderation actions. The problem comes down to how session_handler::check() handles CSRF tokens. Instead of requi…
- CVE-2026-46656HIGHCVSS 8.8EG 8.82026-06-08
Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding user account has been physically deleted from the database. This "Ghost Sess…
- CVE-2026-46668LOWCVSS 2.3EG 2.32026-05-21
SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested lists can result in improper cache reuse. This issue…
- CVE-2026-46700MEDIUMCVSS 4.3EG 4.32026-06-22
Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session and does not verify the caller is an admin, while the sibling POST /s…
- CVE-2026-47053MEDIUMCVSS 5.6EG 5.62026-07-21
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastruct…
- CVE-2026-47298HIGHCVSS 8.0EG 8.02026-06-09
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-47342HIGHCVSS 8.8EG 8.82026-06-11
A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which f…
- CVE-2026-47673MEDIUMCVSS 4.8EG 4.82026-05-28
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer scheme. Any two-part header value — rega…
- CVE-2026-47713MEDIUMCVSS 4.3EG 4.32026-05-28
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, an approved mobile device token created in single-user mode can survive single-user -> multi-user …
- CVE-2026-47740HIGHCVSS 8.1EG 8.12026-05-29
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orde…
- CVE-2026-47744CRITICALCVSS 9.9EG 9.92026-05-29
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/Index had no mount() authorization. Any …
- CVE-2026-48089HIGHCVSS 7.1EG 7.12026-06-11
DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instance with one or more public assets, any authenticated user — including users from a different organization with no memb…
- CVE-2026-4818HIGHCVSS 8.1EG 6.82026-03-31
In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.
- CVE-2026-48579HIGHCVSS 7.5EG 9.12026-06-04
Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.
- CVE-2026-48810MEDIUMCVSS 4.3EG 4.32026-05-29
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, while investigating the ThreadPolicy::delete issue reported previously, the same missing mailbox membership check was found in the sibling…
- CVE-2026-49170HIGHCVSS 7.8EG 7.82026-07-14
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
- CVE-2026-49278MEDIUMCVSS 6.7EG 6.72026-06-24
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, in the visitors.info endpoint, https://developer.rocket.chat/apidocs/get-visitor-inf…
- CVE-2026-49338HIGHCVSS 7.1EG 7.12026-06-19
gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subsonic API endpoints `/rest/deletePlaylist.view` and `/rest/getPlaylist.view` perform no per-resource authorization. Once …
- CVE-2026-49397MEDIUMCVSS 5.3EG 5.32026-06-10
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to before version 2.0.14, private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking n…
- CVE-2026-4958LOWCVSS 3.1EG 3.12026-03-27
A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.send_data of the file XAgentServer/application/websockets/replayer.py of the component WebSocket Endpoint. Such manipula…
- CVE-2026-49877HIGHCVSS 8.1EG 8.12026-06-30
Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only adm…
- CVE-2026-49977MEDIUMCVSS 4.3EG 4.32026-07-10
tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on any element with the purgeBtn class and does not check whether the element is a legitimate tarteaucitron button or whe…
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →