← Back
CWE-285

1,566 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (1,566)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openwhyd
1Openwhyd
Jun 17, 2026
Jan 3, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
openwhyd is vulnerable to Improper Authorization
1Humhub
1Humhub
Jun 17, 2026
Dec 20, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 c...Show more
HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue.Show less
1Samsung
1Internet
Jun 17, 2026
Dec 8, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.
1Ivanti
1Avalanche
Jun 17, 2026
Dec 7, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
1Dell
1Emc Networker
Jun 17, 2026
Nov 23, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Dell EMC Networker versions prior to 19.5 contain an Improper Authorization vulnerability. Any local malicious user with networker user privileges may exploit this vulnerability to upload malicious file to unauthorized l...Show more
Dell EMC Networker versions prior to 19.5 contain an Improper Authorization vulnerability. Any local malicious user with networker user privileges may exploit this vulnerability to upload malicious file to unauthorized locations and execute it.Show less
14mosan
1Gcb Doctor
Jun 17, 2026
Nov 19, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrarily manipulate the system or interrupt s...Show more
4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrarily manipulate the system or interrupt services by upload and execution of arbitrary files.Show less
1Aifu
1Cashier Accounting Management System
Jun 17, 2026
Nov 16, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general user’s permission, the remote attacker can access account information except passwords by crafting URL...Show more
The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general user’s permission, the remote attacker can access account information except passwords by crafting URL parameters.Show less
1Samsung
1Samsung Flow
Jun 17, 2026
Nov 5, 2021
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure Folder without authori...Show more
Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure Folder without authorization.Show less
1Publify Project
1Publify
Jun 17, 2026
Nov 2, 2021
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only.
1Optinmonster
1Optinmonster
Jun 17, 2026
Nov 1, 2021
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/R...Show more
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to exploit inject malicious web scripts on sites with the plugin installed. This affects versions up to, and including, 2.6.4.Show less
1Atlassian
2Jira Data Center
Jira Server
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit email batch configurations via an Improper Authorization vulnerability in the /secure/admin/ConfigureB...Show more
Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit email batch configurations via an Improper Authorization vulnerability in the /secure/admin/ConfigureBatching!default.jspa endpoint. The affected versions are before version 8.20.7.Show less
1Atlassian
4Jira
Jira Data CenterJira Server+1 more
Jun 17, 2026
Oct 26, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File Replication settings via a Broken Access Control vulnerability in the `ReplicationSet...Show more
Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File Replication settings via a Broken Access Control vulnerability in the `ReplicationSettings!default.jspa` endpoint. The affected versions are before version 8.6.0, from version 8.7.0 before 8.13.12, and from version 8.14.0 before 8.20.1.Show less
1Juniper
1Junos
Jun 17, 2026
Oct 19, 2021
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempt...Show more
Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempts to access J-Web administrative interfaces can successfully do so from any device interface regardless of the web-management configuration and filter rules which may otherwise protect access to J-Web. This issue affects: Juniper Networks Junos OS SRX Series 20.4 version 20.4R1 and later versions prior to 20.4R2-S1, 20.4R3; 21.1 versions prior to 21.1R1-S1, 21.1R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.Show less
1Inhandnetworks
1Ir615 Firmware
Jun 17, 2026
Oct 19, 2021
N/A· v4
8.5 HIGH· v3
6.0 MEDIUM· v2
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product without any requirements to create an account, which may allow an attacker to have ful...Show more
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product without any requirements to create an account, which may allow an attacker to have full control over the product and execute code within the internal network to which the product is connected.Show less
1Huaju
1Easytest Online Learning Test Platform
Jun 17, 2026
Oct 15, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remote attackers can access other users’ and administrator’s account information except password by craft...Show more
The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remote attackers can access other users’ and administrator’s account information except password by crafting URL parameters.Show less
1Xinheinformation
1Xinhe Teaching Platform System
Jun 17, 2026
Oct 15, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The “List View” function of ShinHer StudyOnline System is not under authority control. After logging in with user’s privilege, remote attackers can access the content of other users’ message boards by crafting URL parame...Show more
The “List View” function of ShinHer StudyOnline System is not under authority control. After logging in with user’s privilege, remote attackers can access the content of other users’ message boards by crafting URL parameters.Show less
1Xinheinformation
1Xinhe Teaching Platform System
Jun 17, 2026
Oct 15, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers can access and edit other users’ tutorial schedule by crafting URL par...Show more
The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers can access and edit other users’ tutorial schedule by crafting URL parameters.Show less
1Xinheinformation
1Xinhe Teaching Platform System
Jun 17, 2026
Oct 15, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user’s privilege, remote attackers can access and edit other users’ credential and personal information...Show more
The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user’s privilege, remote attackers can access and edit other users’ credential and personal information by crafting URL parameters.Show less
1Minio
1Minio
Jun 17, 2026
Oct 13, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Minio is a Kubernetes native application for cloud storage. All users on release `RELEASE.2021-10-10T16-53-30Z` are affected by a vulnerability that involves bypassing policy restrictions on regular users. Normally, chec...Show more
Minio is a Kubernetes native application for cloud storage. All users on release `RELEASE.2021-10-10T16-53-30Z` are affected by a vulnerability that involves bypassing policy restrictions on regular users. Normally, checkKeyValid() should return owner true for rootCreds. In the affected version, policy restriction did not work properly for users who did not have service (svc) or security token service (STS) accounts. This issue is fixed in `RELEASE.2021-10-13T00-23-17Z`. A downgrade back to release `RELEASE.2021-10-08T23-58-24Z` is available as a workaround.Show less
1Siemens
1Sinec Nms
Jun 17, 2026
Oct 12, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could change the user profile of any user without proper authorization. With this, the attacker could change...Show more
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could change the user profile of any user without proper authorization. With this, the attacker could change the password of any user in the affected system.Show less