← Back
CWE-285

1,566 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (1,566)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dell
1Powerpath Management Appliance
Jun 17, 2026
Feb 11, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privileges (e.g., of role Monitoring) can exploit this issue and gain access...Show more
PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privileges (e.g., of role Monitoring) can exploit this issue and gain access to sensitive information, and modify the configuration. Show less
1Samsung
1Android
Jun 17, 2026
Feb 9, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture.
1Samsung
1Android
Jun 17, 2026
Feb 9, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.
1Samsung
1Galaxy Store
Jun 17, 2026
Feb 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store.
1Samsung
1Smart Things
Jun 17, 2026
Feb 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the owner.
1Samsung
1Android
Jun 17, 2026
Feb 9, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.
1Samsung
1Android
Jun 17, 2026
Feb 9, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator bran...Show more
Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand.Show less
1Samsung
1Android
Jun 17, 2026
Feb 9, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission using unprotected action.
1Samsung
1Android
Jun 17, 2026
Feb 9, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.
1Dell
1Command | Intel Vpro Out Of Band
Jun 17, 2026
Feb 7, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locally authenticated malicious users could potentially exploit this vulnerability in order to write arbit...Show more
Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locally authenticated malicious users could potentially exploit this vulnerability in order to write arbitrary files to the system. Show less
1Unifiedremote
1Unified Remote
Jun 17, 2026
Feb 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unifi...Show more
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated access to run code of the attacker's choosing.Show less
1Sensiolabs
1Symfony
Jun 17, 2026
Feb 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers) and returns them to...Show more
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers) and returns them to the clients. In a recent change in the `AbstractSessionListener`, the response might contain a `Set-Cookie` header. If the Symfony HTTP cache system is enabled, this response might bill stored and return to the next clients. An attacker can use this vulnerability to retrieve the victim's session. This issue has been patched and is available for branch 4.4.Show less
1Wallabag
1Wallabag
Jun 17, 2026
Feb 1, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
1Wallabag
1Wallabag
Jun 17, 2026
Feb 1, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
1Schneider Electric
1Ecostruxure Power Commission
Jun 17, 2026
Feb 1, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software functions when an attacker gets access to localhost interface of the EcoStruxure Power Commission applicatio...Show more
A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software functions when an attacker gets access to localhost interface of the EcoStruxure Power Commission application. Affected Products: EcoStruxure Power Commission (Versions prior to V2.25)Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 26, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if...Show more
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git repositories and package registries by using Deploy tokens or Deploy keys .Show less
1Dell
1Realtek High Definition Audio Driver
Jun 17, 2026
Jan 26, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious user may potentially exploit this vulnerability by waiting for an administrator to launch the applicati...Show more
An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious user may potentially exploit this vulnerability by waiting for an administrator to launch the application and attach to the process to elevate privileges on the system. Show less
1Fit2cloud
1Kubeoperator
Jun 17, 2026
Jan 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized en...Show more
KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak sensitive information. This vulnerability could be used to take over the cluster under certain conditions. This issue has been patched in version 3.16.4. Show less
1Microsoft
14Windows 10 1607
Windows 10 1809Windows 10 20h2+11 more
Jun 17, 2026
Jan 10, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Windows SMB Witness Service Elevation of Privilege Vulnerability
1Royal Elementor Addons
1Royal Elementor Addons
Jun 17, 2026
Jan 10, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user...Show more
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'contact-form-7', 'media-library-assistant', or 'woocommerce' plugins if they are installed on the site.Show less