← Back
CWE-285

1,566 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (1,566)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Sep 9, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.
1Xwiki
1Xwiki
Jun 17, 2026
Sep 8, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 13.1.0.5 and 14.3-rc-1, some resources are missing a check for inactive (not yet activated or disabled) users in XW...Show more
XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 13.1.0.5 and 14.3-rc-1, some resources are missing a check for inactive (not yet activated or disabled) users in XWiki, including the REST service. This means a disabled user can enable themselves using a REST call. On the same way some resources handler created by extensions are not protected by default, so an inactive user could perform actions for such extensions. This issue has existed since at least version 1.1 of XWiki for instance configured with the email activation required for new users. Now it's more critical for versions 11.3-rc-1 and later since the maintainers provided the capability to disable user without deleting them and encouraged using that feature. XWiki 14.3-rc-1 and XWiki 13.10.5 contain a patch. There is no workaround for this other than upgrading XWiki.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Sep 7, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.10.11, 13.10.1, and 13.4.6, a bug in the security cache stores rules as...Show more
XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.10.11, 13.10.1, and 13.4.6, a bug in the security cache stores rules associated to document Page1.Page2 and space Page1.Page2 in the same cache entry. That means that it's possible to overwrite the rights of a space or a document by creating the page of the space with the same name and checking the right of the new one first so that they end up in the security cache and are used for the other too. The problem has been patched in XWiki 12.10.11, 13.10.1, and 13.4.6. There are no known workarounds.Show less
1Suse
1Rancher
Jun 17, 2026
Sep 7, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members,...Show more
An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage project members) to gain owner permission in another project in the same cluster or in another project on a different downstream cluster. This issue affects: SUSE Rancher Rancher versions prior to 2.6.7; Rancher versions prior to 2.5.16.Show less
1Chatwoot
1Chatwoot
Jun 17, 2026
Sep 6, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.
1Cisco
1Aci Multi Site Orchestrator
Jun 17, 2026
Aug 25, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability in the API implementation of Cisco ACI Multi-Site Orchestrator (MSO) could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to improper author...Show more
A vulnerability in the API implementation of Cisco ACI Multi-Site Orchestrator (MSO) could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to improper authorization on specific APIs. An attacker could exploit this vulnerability by sending crafted HTTP requests. A successful exploit could allow an attacker who is authenticated with non-Administrator privileges to elevate to Administrator privileges on an affected device.Show less
1Apple
4Ipados
Iphone OsMac Os X+1 more
Jun 17, 2026
Aug 24, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6. An app may be able to read arbitr...Show more
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6. An app may be able to read arbitrary files.Show less
2Adobe
Magento
2Commerce
Magento
Jun 17, 2026
Aug 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage...Show more
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to access other user's data. Exploitation of this issue does not require user interaction.Show less
1Sequi
1Portbloque S Firmware
Jun 17, 2026
Aug 16, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Sequi PortBloque S has an improper authorization vulnerability, which may allow a low-privileged user to perform administrative functions using specifically crafted requests.
1Nvidia
1Virtual Gpu
Jun 17, 2026
Aug 5, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources for which the guest is not authorized. This vulnerability may lead to loss of dat...Show more
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources for which the guest is not authorized. This vulnerability may lead to loss of data integrity and confidentiality, denial of service, or information disclosure.Show less
1Unitree
1Go 1 Firmware
Jun 17, 2026
Aug 5, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered down by an attacker within normal RF range without authentication. Other...Show more
Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered down by an attacker within normal RF range without authentication. Other versions may be affected, such as the A1.Show less
1Samsung
1Galaxy Wearable
Jun 17, 2026
Aug 5, 2022
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Implicit Intent hijacking vulnerability in Galaxy Wearable prior to version 2.2.50 allows attacker to get sensitive information.
1Samsung
1Samsung Email
Jun 17, 2026
Aug 5, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Intent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to get sensitive information.
1Google
1Android
Jun 17, 2026
Aug 5, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Implicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC address.
1Kromit
1Titra
Jun 17, 2026
Aug 1, 2022
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.
1Pandorafms
1Pandora Fms
Jun 17, 2026
Aug 1, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management module could create, modify or delete any user with full admin privileg...Show more
Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management module could create, modify or delete any user with full admin privilege. The impact could lead to a vertical privilege escalation to access the privileges of a higher-level user or typically an admin user.Show less
1Pega
1Infinity
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.
1Zulip
1Zulip
Jun 17, 2026
Jul 22, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administrator privileges to on...Show more
Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administrator privileges to one of their bots. The vulnerability is fixed in Zulip Server 5.5. Members who don’t own any bots, and lack permission to create them, can’t exploit the vulnerability. As a workaround for the vulnerability, an organization administrator can restrict the `Who can create bots` permission to administrators only, and change the ownership of existing bots.Show less
2Pki Core Project
Redhat
3Certificate System
Enterprise LinuxPki Core
Jun 17, 2026
Jul 14, 2022
N/A· v4
5.7 MEDIUM· v3
N/A· v2
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to...Show more
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.Show less
1Samsung
1Cloud
Jun 17, 2026
Jul 12, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Implicit Intent hijacking vulnerability in Samsung Cloud prior to version 5.2.0 allows attacker to get sensitive information.