← Back
CWE-285

1,566 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (1,566)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Catalyst Center
Jun 17, 2026
May 18, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in...Show more
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
1Catalyst Center
Jun 17, 2026
May 18, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in...Show more
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more information about these vulnerabilities, see the Details section of this advisory.Show less
2Checkmk
Tribe29
2Checkmk
Checkmk
Jun 17, 2026
May 17, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs.
1Rocketchat
1Rocket.chat
Jun 17, 2026
May 11, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit messag...Show more
An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit message in the target room.Show less
1Intel
1Endpoint Management Assistant
Jun 17, 2026
May 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service via local access.
1Intel
1Setup And Configuration Software
Jun 17, 2026
May 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service via local access.
1Intel
2Endpoint Management Assistant Configuration Tool
Manageability Commander
Jun 17, 2026
May 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated user to potentially enable denial of service via local access.
1Rocketchat
1Rocket.chat
Jun 17, 2026
May 9, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus server configuration. This allows users to bypass the intended message d...Show more
A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus server configuration. This allows users to bypass the intended message deletion behavior, hiding messages and deletion notices.Show less
1Rocketchat
1Rocket.chat
Jun 17, 2026
May 9, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing the UI to display messages in an incorrect order.
1Microsoft
1Visual Studio Code
Jun 17, 2026
May 9, 2023
N/A· v4
6.6 MEDIUM· v3
N/A· v2
Visual Studio Code Spoofing Vulnerability
1Otrs
1Otrs
Jun 17, 2026
May 8, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into overall system usage. User IDs can easily be...Show more
Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into overall system usage. User IDs can easily be correlated with real names e. g. via ticket histories by any user. (Fuzzing for garnering other adjacent user/sensitive data). Subscribing to all possible push events could also lead to performance implications on the server side, depending on the size of the installation and the number of active users. (Flooding)This issue affects OTRS: from 8.0.X before 8.0.32. Show less
1Samsung
1Samsung Core Services
Jun 17, 2026
May 4, 2023
N/A· v4
8.6 HIGH· v3
N/A· v2
Improper access control in Samsung Core Service prior to version 2.1.00.36 allows attacker to write arbitrary file in sandbox.
1Milesight
21Ms N1004 Uc Firmware
Ms N1004 Upc FirmwareMs N1008 Uc Firmware+18 more
Jun 17, 2026
Apr 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to improper authorization at the Milesight NVR web-based management interfa...Show more
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to improper authorization at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests on the targeted device. Successful exploitation of this vulnerability could allow remote attacker to perform unauthorized activities on the targeted device. Show less
1Oretnom23
1Service Provider Management System
Jun 17, 2026
Apr 27, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability was found in SourceCodester Service Provider Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_inquiry. The ma...Show more
A vulnerability was found in SourceCodester Service Provider Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_inquiry. The manipulation leads to improper authorization. The attack may be launched remotely. The identifier of this vulnerability is VDB-227588.Show less
1Modoboa
1Modoboa
Jun 17, 2026
Apr 21, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.
1Juniper
1Junos Os Evolved
Jun 17, 2026
Apr 17, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a local, authenticated attacker to execute administrative commands that could impact the integrity of t...Show more
An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a local, authenticated attacker to execute administrative commands that could impact the integrity of the system or system availability. Administrative functions such as daemon restarting, routing engine (RE) switchover, and node shutdown can all be performed through exploitation of the 'sysmanctl' command. Access to the 'sysmanctl' command is only available from the Junos shell. Neither direct nor indirect access to 'sysmanctl' is available from the Junos CLI. This issue affects Juniper Networks Junos OS Evolved: All versions prior to 20.4R3-S5-EVO; 21.2 versions prior to 21.2R3-EVO; 21.3 versions prior to 21.3R2-EVO; 21.4 versions prior to 21.4R1-S2-EVO, 21.4R2-EVO.Show less
1Forgerock
1Access Management
Jun 17, 2026
Apr 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.
1Pega
1Synchronization Engine
Jun 17, 2026
Apr 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A user with non-Admin access can change a configuration file on the client to modify the Server URL.
1Gitlab
1Gitlab
Jun 17, 2026
Apr 5, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to securi...Show more
Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.Show less
1Glpi Project
1Glpi
Jun 17, 2026
Apr 5, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, a user who has the Technician profile could see and generate a Personal token for a Super-Admin....Show more
GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, a user who has the Technician profile could see and generate a Personal token for a Super-Admin. Using such token it is possible to negotiate a GLPI session and hijack the Super-Admin account, resulting in a Privilege Escalation. Versions 9.5.13 and 10.0.7 contain a patch for this issue.Show less