CWE-285— Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
1,506 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 15 of 31
- CVE-2024-40783HIGHCVSS 5.5EG 7.12024-07-29
The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A malicious application may be able to bypass Privacy preferences.
- CVE-2024-40807MEDIUMCVSS 5.5EG 5.52024-07-29
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A shortcut may be able to use sensitive data with certain actions without prompting the user.
- CVE-2024-40814HIGHCVSS 7.1EG 7.12024-07-29
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.6, macOS Ventura 13.7. An app may be able to bypass Privacy preferences.
- CVE-2024-41670HIGHCVSS 7.5EG 7.52024-07-26
In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior to version 3.18.1, a malicious customer can confirm an order even if payment is finally declined by PayPal. A logical w…
- CVE-2024-41962MEDIUMCVSS 4.6EG 4.62024-08-01
Bostr is an nostr relay aggregator proxy that acts like a regular nostr relay. bostr let everyone in even having authorized_keys being set when noscraper is set to true. This vulnerability is fixed in 3.0.10.
- CVE-2024-42032MEDIUMCVSS 4.4EG 4.42024-08-08
Access permission verification vulnerability in the Contacts module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-42036LOWCVSS 2.5EG 2.52024-08-08
Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-42039MEDIUMCVSS 4.3EG 4.32024-09-04
Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-42490HIGHCVSS 7.5EG 7.52024-08-22
authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/certificatekeypairs/<uuid>/view_certific…
- CVE-2024-4254HIGHCVSS 7.1EG 7.12024-06-04
The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable to secrets exfiltration due to improper authorization. The vulnerability arises from the workflow's explicit checkout a…
- CVE-2024-43051MEDIUMCVSS 5.5EG 5.52025-03-03
Information disclosure while deriving keys for a session for any Widevine use case.
- CVE-2024-43460HIGHCVSS 8.1EG 8.12024-09-17
Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.
- CVE-2024-43482MEDIUMCVSS 6.5EG 6.52024-09-10
Microsoft Outlook for iOS Information Disclosure Vulnerability
- CVE-2024-43602CRITICALCVSS 9.9EG 9.92024-11-12
Azure CycleCloud Remote Code Execution Vulnerability
- CVE-2024-43706HIGHCVSS 7.6EG 7.62025-06-10
Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.
- CVE-2024-43729MEDIUMCVSS 6.5EG 6.52024-12-10
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security mea…
- CVE-2024-43731MEDIUMCVSS 4.3EG 4.32024-12-10
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security mea…
- CVE-2024-44314MEDIUMCVSS 6.5EG 6.52025-03-18
TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the index_onUpdateStatus() function within Orders.php, which f…
- CVE-2024-45044HIGHCVSS 8.8EG 8.82024-09-10
Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is in place and a user executes a command in bconsole using an abbreviation (i.e. "w" for "whoami") the ACL check did not …
- CVE-2024-45244MEDIUMCVSS 5.3EG 5.42024-08-25
Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.
- CVE-2024-45307HIGHCVSS 8.8EG 8.82024-09-03
SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration of the bot and potentially gain control ove…
- CVE-2024-45387CRITICALCVSS 9.9EG 9.92024-12-23
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sen…
- CVE-2024-45805MEDIUMCVSS 4.3EG 4.32024-12-26
OpenCTI is an open-source cyber threat intelligence platform. Before 6.3.0, general users can access information that can only be accessed by users with access privileges to admin and support information (SETTINGS_SUPPORT). This is due to …
- CVE-2024-46942MEDIUMCVSS 6.5EG 6.52024-09-15
In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries in an OpenDaylight clustering deployment.
- CVE-2024-46943HIGHCVSS 7.5EG 7.52024-09-15
An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cl…
- CVE-2024-47053HIGHCVSS 7.7EG 7.72025-02-26
This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data. * Improper Authorization: An authorization flaw exists in…
- CVE-2024-47084HIGHCVSS 8.3EG 8.32024-10-10
Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin validation**, where the Gradio server fails to validate the request origin when a cookie is present. This allows an atta…
- CVE-2024-47165MEDIUMCVSS 5.4EG 5.42024-10-10
Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **CORS origin validation accepting a null origin**. When a Gradio server is deployed locally, the `localhost_aliases` variable includes "…
- CVE-2024-47183HIGHCVSS 8.1EG 8.12024-10-04
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId: true is set, an attacker that is allowed to create a new user can set a custom object I…
- CVE-2024-47876HIGHCVSS 8.8EG 8.82024-10-15
Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in as a normal user. This can result in illegal access being granted to the system. Vers…
- CVE-2024-4819MEDIUMCVSS 4.3EG 4.32024-05-14
A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file admin_class.php. The manipulation of the argument type with the input 1 leads t…
- CVE-2024-48897MEDIUMCVSS 4.3EG 4.32024-11-18
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.
- CVE-2024-48901MEDIUMCVSS 4.3EG 4.32024-11-18
A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.
- CVE-2024-48921LOWCVSS 2.7EG 2.72024-10-29
Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can be overridden by the creation of a PolicyException in a random namespace. By design, PolicyExceptions are consumed from …
- CVE-2024-5053MEDIUMCVSS 4.2EG 4.22024-09-01
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp API key update due to an insufficient capability check on the verifyRequest function in …
- CVE-2024-50617HIGHCVSS 7.5EG 7.52026-02-11
Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authenticated user can easily change the file id parameter or pass the physical file p…
- CVE-2024-51479HIGHCVSS 7.5EG 7.52024-12-17
Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pag…
- CVE-2024-51525MEDIUMCVSS 6.2EG 6.22024-11-05
Permission control vulnerability in the clipboard module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-52287HIGHCVSS 7.2EG 7.22024-11-21
authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 20…
- CVE-2024-52528CRITICALCVSS 9.3EG 9.32024-11-15
Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for Budget Control. Budget Control Gateway does not properly validate auth tokens, which allows attackers to bypass intend…
- CVE-2024-55954HIGHCVSS 8.7EG 8.72025-01-16
OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Admin" role user to remove a "Root" user from the organization. This violates the intended pr…
- CVE-2024-56320HIGHCVSS 8.8EG 8.82025-01-03
GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, and its associated API. A malicious inside…
- CVE-2024-56323CRITICALCVSS 9.8EG 9.82025-01-13
OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass under the following conditions: 1. calling Check API…
- CVE-2024-56335HIGHCVSS 7.6EG 7.62024-12-20
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting groups from an organization given a few conditions: 1. The attack…
- CVE-2024-56802HIGHCVSS 8.7EG 8.72024-12-31
Tapir is a private Terraform registry. Tapir versions 0.9.0 and 0.9.1 are facing a critical issue with scope-able Deploykeys where attackers can guess the key to get write access to the registry. User must upgrade to 0.9.2.
- CVE-2024-57954MEDIUMCVSS 6.2EG 6.22025-02-06
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-58367HIGHCVSS 7.1EG 7.12026-07-18
SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to access unauthorized field values through various query techniques. Attackers can exploit …
- CVE-2024-6000HIGHCVSS 7.1EG 7.12024-06-15
The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability setting on the 'display_ticket_themes_page' function in versions up to, and including, 1.19.20. This make…
- CVE-2024-6347MEDIUMCVSS 6.5EG 6.52024-08-15
* Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Altima (2022) allows attackers to trigger denial-of-service (DoS) by unauthorized access to the ECU's programming session. …
- CVE-2024-6375MEDIUMCVSS 5.4EG 5.42024-07-01
A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to either degradation of query performance, or to revealing chunk boundaries through timing sid…
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →