CWE-285— Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
1,506 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 19 of 31
- CVE-2025-23042HIGHCVSS 7.5EG 7.52025-01-14
Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Gradio's Access Control List (ACL) for file paths can be bypassed by alteri…
- CVE-2025-2320HIGHCVSS 7.3EG 7.32025-03-14
A vulnerability has been found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this vulnerability is the function submit of the file /api/blade-user/submit of the component User Handler. The manipulat…
- CVE-2025-2345CRITICALCVSS 9.8EG 9.82025-03-16
A vulnerability, which was classified as very critical, was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. This affects an unknown part. The manipulation leads to improper authorization. It is possible to initiate the attack re…
- CVE-2025-2359HIGHCVSS 7.3EG 7.32025-03-17
A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function SetDDNSSettings of the file /HNAP1/ of the component DDNS Service. The manipulation of the argument SOAPAction leads to im…
- CVE-2025-2360HIGHCVSS 7.3EG 7.32025-03-17
A vulnerability classified as critical was found in D-Link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is the function SetUpnpSettings of the file /HNAP1/ of the component UPnP Service. The manipulation of the argument SOAPA…
- CVE-2025-2397LOWCVSS 2.4EG 2.42025-03-17
A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been declared as problematic. This vulnerability affects unknown code of the component Telnet Service. …
- CVE-2025-24053HIGHCVSS 7.2EG 7.22025-03-13
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
- CVE-2025-24376MEDIUMCVSS 6.5EG 6.52025-01-30
kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. By design, AdmissionPolicy and AdmissionPolicyGroup can evaluate only namespaced resources. The resources to be evaluat…
- CVE-2025-24418HIGHCVSS 8.1EG 8.12025-02-11
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vuln…
- CVE-2025-24784MEDIUMCVSS 4.3EG 4.32025-01-30
kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. The policy group feature, added to by the 1.17.0 release. By being namespaced, the AdmissionPolicyGroup has a well cons…
- CVE-2025-25196CRITICALCVSS 9.8EG 9.82025-02-19
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, docker < v.1.8.4) are vulnerable to authorization bypass when c…
- CVE-2025-2528LOWCVSS 3.6EG 3.62025-03-26
Improper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a configuration different from the one mandated by the system administrators. This issue affec…
- CVE-2025-2589MEDIUMCVSS 5.5EG 5.52025-03-21
A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index of the file \handler\Account.go. The manipulation of the argument user_cookie leads to impr…
- CVE-2025-2600MEDIUMCVSS 6.8EG 6.82025-03-26
Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEVATED_PASSWORD variable even though not allowed by the "Allow password in variable policy". …
- CVE-2025-2637MEDIUMCVSS 4.3EG 4.32025-03-23
A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unknown functionality of the file /user/userinfo.html of the component Account Profile Page. The manipulation of t…
- CVE-2025-2638MEDIUMCVSS 4.3EG 4.32025-03-23
A vulnerability, which was classified as problematic, was found in JIZHICMS up to 1.7.0. This affects an unknown part of the file /user/release.html of the component Article Handler. The manipulation of the argument ishot with the input 1 …
- CVE-2025-2639MEDIUMCVSS 4.3EG 4.32025-03-23
A vulnerability has been found in JIZHICMS up to 1.7.0 and classified as problematic. This vulnerability affects unknown code of the file /user/release.html of the component Article Handler. The manipulation leads to improper authorization…
- CVE-2025-26430HIGHCVSS 7.8EG 7.82025-09-04
In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…
- CVE-2025-2653MEDIUMCVSS 4.3EG 4.32025-03-23
A vulnerability was found in FoxCMS 1.25 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been discl…
- CVE-2025-26683HIGHCVSS 8.1EG 8.12025-03-31
Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-27399MEDIUMCVSS 5.3EG 5.32025-02-27
Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/reasons is set to "users" (localized English string: "To logged-in users"), users that are n…
- CVE-2025-27509CRITICALCVSS 9.3EG 9.32025-03-06
fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to forge authentication assertions, provision a new administrative user account …
- CVE-2025-27601MEDIUMCVSS 4.3EG 4.32025-03-11
Umbraco is a free and open source .NET content management system. An improper API access control issue has been identified Umbraco's API management package prior to versions 15.2.3 and 14.3.3, allowing low-privilege, authenticated users to…
- CVE-2025-27602MEDIUMCVSS 4.9EG 4.92025-03-11
Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1, via manipulation of backoffice API URLs, it's possible for authenticated backoffice user…
- CVE-2025-28131MEDIUMCVSS 4.6EG 4.62025-04-01
A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw…
- CVE-2025-2850LOWCVSS 3.5EG 3.52025-04-26
A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-…
- CVE-2025-29659CRITICALCVSS 9.8EG 9.82025-04-21
Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.
- CVE-2025-29778MEDIUMCVSS 5.8EG 5.82025-03-24
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegExp while verifying artifact's sign with keyless mode. It allows the attacker to d…
- CVE-2025-29794HIGHCVSS 8.8EG 8.82025-04-08
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2025-29827CRITICALCVSS 9.9EG 9.92025-05-08
Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.
- CVE-2025-29922CRITICALCVSS 9.6EG 9.62025-03-20
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.26.3, the identified vulnerability allows creating or deleting an object via the APIExport VirtualWorkspace in any …
- CVE-2025-29926CRITICALCVSS 9.8EG 9.82025-03-19
XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. …
- CVE-2025-29927CRITICALCVSS 9.1EG 9.12025-03-21
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the…
- CVE-2025-30117HIGHCVSS 7.3EG 7.32025-03-18
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can be performed by unauthorized parties. After bypassing the device pairing, an attac…
- CVE-2025-3013HIGHCVSS 8.3EG 8.32025-03-31
Insecure Direct Object References (IDOR) in access control in Customer Portal before 2.1.4 on NightWolf Penetration Testing allows an attacker to access via manipulating request parameters or object references.
- CVE-2025-3014HIGHCVSS 8.3EG 8.32025-03-31
Insecure Direct Object References (IDOR) in access control in Tracking 2.1.4 on NightWolf Penetration Testing allows an attacker to access via manipulating request parameters or object references.
- CVE-2025-30373MEDIUMCVSS 6.5EG 6.52025-04-07
Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in ca…
- CVE-2025-30389HIGHCVSS 8.7EG 8.72025-04-30
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-30390CRITICALCVSS 9.9EG 9.92025-04-30
Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.
- CVE-2025-30392CRITICALCVSS 9.8EG 9.82025-04-30
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-30508MEDIUMCVSS 6.5EG 6.52026-02-10
Improper authorization in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attac…
- CVE-2025-31249HIGHCVSS 7.1EG 7.12025-05-12
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.
- CVE-2025-31255CRITICALCVSS 9.8EG 9.82025-09-15
An authorization issue was addressed with improved state management. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, watchOS 26. An app may be able to access sensitive user data.
- CVE-2025-3199HIGHCVSS 7.3EG 7.32025-04-04
A vulnerability was found in ageerle ruoyi-ai up to 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysModelCont…
- CVE-2025-3202HIGHCVSS 7.3EG 7.32025-04-04
A vulnerability classified as critical has been found in ageerle ruoyi-ai up to 2.0.0. Affected is an unknown function of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysNoticeController.java. The ma…
- CVE-2025-32964MEDIUMCVSS 4.6EG 4.62025-04-22
ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 00bebea, when enabling a conflicting extension, a restricted extension would be automatically disabled even if the user did not hold the ManageWiki-restric…
- CVE-2025-32972LOWCVSS 2.7EG 2.72025-04-30
XWiki is a generic wiki platform. In versions starting from 6.1-milestone-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the script API of the LESS compiler in XWiki is incorrectly chec…
- CVE-2025-32982HIGHCVSS 7.5EG 7.52025-04-25
NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.
- CVE-2025-3454MEDIUMCVSS 5.0EG 5.02025-06-02
This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Ale…
- CVE-2025-3536MEDIUMCVSS 6.5EG 6.52025-04-13
A vulnerability was found in Tutorials-Website Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/delete-user.php. The manipulation of the argument ID leads to…
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →