← Back
CWE-285

1,566 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (1,566)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Galaxy Store
Jun 17, 2026
Apr 11, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without user interactions.
1Phpipam
1Phpipam
Jun 17, 2026
Apr 4, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
1Janeczku
1Calibre Web
Jun 17, 2026
Apr 3, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
2Cobbler Project
Fedoraproject
2Cobbler
Fedora
Jun 17, 2026
Mar 11, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
1Orchardcore
1Orchardcore
Jun 17, 2026
Mar 11, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.
1Webmin
1Webmin
Jun 17, 2026
Mar 2, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Improper Authorization in GitHub repository webmin/webmin prior to 1.990.
1Airspan
5A5x Firmware
C5c FirmwareC5x Firmware+2 more
Jun 17, 2026
Feb 18, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple...Show more
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An attacker may gain access to these API routes and achieve remote code execution, create a denial-of-service condition, and obtain sensitive information.Show less
1Librenms
1Librenms
Jun 17, 2026
Feb 15, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper Authorization in Packagist librenms/librenms prior to 22.2.0.
1Samsung
1Link Sharing
Jun 17, 2026
Feb 11, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Improper Authorization vulnerability in Link Sharing prior to version 12.4.00.3 allows attackers to open protected activity via PreconditionActivity.
1Pingidentity
1Pingfederate
Jun 17, 2026
Feb 10, 2022
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing...Show more
When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password.Show less
1Acronis
4Agent
Cyber ProtectCyber Protect Home Office+1 more
Jun 17, 2026
Feb 4, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147, Acr...Show more
Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147, Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287Show less
1Arista
1Eos
Jun 17, 2026
Jan 14, 2022
N/A· v4
9.1 CRITICAL· v3
9.4 HIGH· v2
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
1Arista
1Terminattr
Jun 17, 2026
Jan 14, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword con...Show more
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.Show less
1Arista
1Eos
Jun 17, 2026
Jan 14, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword con...Show more
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.Show less
1Samsung
1Galaxy Store
Jun 17, 2026
Jan 10, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.
1Google
1Android
Jun 17, 2026
Jan 10, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission
1Google
1Android
Jun 17, 2026
Jan 10, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address.
1Google
1Android
Jun 17, 2026
Jan 10, 2022
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via Samsung DeX mode.
1Google
1Android
Jun 17, 2026
Jan 10, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.
4Aeotec
SamsungSilabs+1 more
6500 Series Firmware
700 Series FirmwareSth Eth 200+3 more
Jun 17, 2026
Jan 10, 2022
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10 version 6.04, Aeon Labs ZW090-A version 3.95, and Samsung STH-ETH-200 version 6...Show more
Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10 version 6.04, Aeon Labs ZW090-A version 3.95, and Samsung STH-ETH-200 version 6.04, are susceptible to denial of service via malformed routing messages.Show less