← Back
CWE-285

1,563 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (1,563)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mcafee
1Threat Intelligence Exchange Server
Jun 17, 2026
Nov 13, 2019
N/A· v4
4.5 MEDIUM· v3
3.5 LOW· v2
Abuse of Authorization vulnerability in APIs exposed by TIE server in McAfee Threat Intelligence Exchange Server (TIE Server) 3.0.0 allows remote authenticated users to modify stored reputation data via specially crafted...Show more
Abuse of Authorization vulnerability in APIs exposed by TIE server in McAfee Threat Intelligence Exchange Server (TIE Server) 3.0.0 allows remote authenticated users to modify stored reputation data via specially crafted messages.Show less
1Dell
3Idrac7 Firmware
Idrac8 FirmwareIdrac9 Firmware
Jun 17, 2026
Nov 7, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 contain an improper authorization vulnerability. A remote authenticated malicious iDRAC user with...Show more
Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 contain an improper authorization vulnerability. A remote authenticated malicious iDRAC user with low privileges may potentially exploit this vulnerability to obtain sensitive information such as password hashes.Show less
2Eclipse
Redhat
7Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Eus+4 more
Jun 17, 2026
Oct 17, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks.
1Cisco
1Ios Xe
Jun 17, 2026
Sep 25, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS). The vulnerability...Show more
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS). The vulnerability is due to insufficient enforcement of the consent token in authorizing shell access. An attacker could exploit this vulnerability by authenticating to the CLI and requesting shell access on an affected device. A successful exploit could allow the attacker to gain shell access on the affected device and execute commands on the underlying OS.Show less
1Tridium
2Niagara4
Niagara Ax
Jun 17, 2026
Sep 24, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
A specific utility may allow an attacker to gain read access to privileged files in the Niagara AX 3.8u4 (JACE 3e, JACE 6e, JACE 7, JACE-8000), Niagara 4.4u3 (JACE 3e, JACE 6e, JACE 7, JACE-8000), and Niagara 4.7u1 (JACE...Show more
A specific utility may allow an attacker to gain read access to privileged files in the Niagara AX 3.8u4 (JACE 3e, JACE 6e, JACE 7, JACE-8000), Niagara 4.4u3 (JACE 3e, JACE 6e, JACE 7, JACE-8000), and Niagara 4.7u1 (JACE-8000, Edge 10).Show less
1Advantech
1Webaccess
Jun 17, 2026
Sep 18, 2019
N/A· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensitive information, cause improper control of generation of code, which may allow remote code execution...Show more
In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensitive information, cause improper control of generation of code, which may allow remote code execution or cause a system crash.Show less
1Cisco
1Content Security Management Appliance
Jun 17, 2026
Sep 5, 2019
N/A· v4
4.3 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email. The vulnerability exists becau...Show more
A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email. The vulnerability exists because the affected software does not correctly implement role permission controls. An attacker could exploit this vulnerability by using a custom role with specific permissions. A successful exploit could allow the attacker to access the spam quarantine of other users.Show less
1Cisco
2Integrated Management Controller Supervisor
Unified Computing System
Jun 17, 2026
Aug 21, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is due...Show more
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is due to improper handling of substring comparison operations that are performed by the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker with read-only privileges to gain administrator privileges.Show less
1Cisco
2Integrated Management Controller Supervisor
Unified Computing System
Jun 17, 2026
Aug 21, 2019
N/A· v4
8.1 HIGH· v3
9.0 HIGH· v2
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to make unauthorized changes to the system configuration. The v...Show more
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to make unauthorized changes to the system configuration. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow a user with read-only privileges to change critical system configurations using administrator privileges.Show less
1Clickhouse
1Clickhouse
Jun 25, 2025
Aug 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.
1Search Guard
1Search Guard
Jun 17, 2026
Aug 13, 2019
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s).
1Cisco
1Adaptive Security Appliance Software
Jun 17, 2026
Aug 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to elevate privileges and execute administrative functions on an aff...Show more
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to elevate privileges and execute administrative functions on an affected device. The vulnerability is due to insufficient authorization validation. An attacker could exploit this vulnerability by logging in to an affected device as a low-privileged user and then sending specific HTTPS requests to execute administrative functions using the information retrieved during initial login.Show less
1Cisco
11Sf 220 24 Firmware
Sf220 24p FirmwareSf220 48 Firmware+8 more
Jun 17, 2026
Aug 7, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files. The vulnerability is due to incomplete authoriz...Show more
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files. The vulnerability is due to incomplete authorization checks in the web management interface. An attacker could exploit this vulnerability by sending a malicious request to certain parts of the web management interface. Depending on the configuration of the affected switch, the malicious request must be sent via HTTP or HTTPS. A successful exploit could allow the attacker to modify the configuration of an affected device or to inject a reverse shell. This vulnerability affects Cisco Small Business 220 Series Smart Switches running firmware versions prior to 1.1.4.4 with the web management interface enabled. The web management interface is enabled via both HTTP and HTTPS by default.Show less
1Mongodb
1Mongodb
Jun 17, 2026
Aug 6, 2019
N/A· v4
7.1 HIGH· v3
6.0 MEDIUM· v2
After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and become conflated with new accounts, if those accounts reuse the names of del...Show more
After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and become conflated with new accounts, if those accounts reuse the names of deleted ones. This issue affects MongoDB Server v4.0 versions prior to 4.0.9; MongoDB Server v3.6 versions prior to 3.6.13 and MongoDB Server v3.4 versions prior to 3.4.22. Workaround: After deleting one or more users, restart any nodes which may have had active user authorization sessions. Refrain from creating user accounts with the same name as previously deleted accounts.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
5.7 MEDIUM· v3
7.9 HIGH· v2
bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
3.8 LOW· v3
2.1 LOW· v2
cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).
1Printeron
1Central Print Services
Nov 21, 2024
Jul 20, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them....Show more
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them. As a result, an attacker with guest/pseudo-guest level permissions can bypass the session checks (that would otherwise logout a low-privileged user) by calling the core print job components directly via crafted HTTP GET and POST requests.Show less
1Gitlab
1Gitlab
Nov 21, 2024
Jul 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they creat...Show more
GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.Show less