CWE-285— Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
1,506 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 21 of 31
- CVE-2025-53792CRITICALCVSS 9.1EG 9.12025-08-07
Azure Portal Elevation of Privilege Vulnerability
- CVE-2025-53795CRITICALCVSS 9.1EG 9.12025-08-21
Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-53944HIGHCVSS 7.7EG 7.72025-07-30
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6.15 and below, the external API's get_graph_execution_results endpoint has an authorization bypass vulnerability. While…
- CVE-2025-54130HIGHCVSS 7.5EG 7.52025-08-05
Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions less than 1.3.9. If the file is a dotfile, editing it requires approval but creating a new one doesn't. Hence…
- CVE-2025-54378HIGHCVSS 8.3EG 8.32025-07-26
HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 and below of haxcms-php, API endpoints do not perform authorization checks when interactin…
- CVE-2025-54585MEDIUMCVSS 6.5EG 6.52025-07-30
GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can exploit the way GitProxy handles new branch creation to bypass the approval of prior commits on the parent bra…
- CVE-2025-54787LOWCVSS 3.7EG 3.72025-08-07
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vulnerability in SuiteCRM version 7.14.6 which allows unauthenticated downloads of any file from the upload-directory, as …
- CVE-2025-54822MEDIUMCVSS 4.3EG 4.32025-10-14
An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.8, FortiOS 7.0.0 through 7.0.11, FortiProxy 7.4.0 through 7.4.8, FortiProxy 7.2 all versions, FortiProxy 7.0…
- CVE-2025-54868HIGHCVSS 7.5EG 7.52025-08-05
LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint allows reading arbitrary chats directly from the Meilisearch engine. The endpoint /api/search/test allows for direct ac…
- CVE-2025-5511HIGHCVSS 7.5EG 7.52025-06-03
A vulnerability, which was classified as critical, has been found in quequnlong shiyi-blog up to 1.2.1. This issue affects some unknown processing of the file /dev api/app/album/photos/. The manipulation leads to improper authorization. Th…
- CVE-2025-5522HIGHCVSS 7.3EG 7.32025-06-03
A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sa/addUser of the …
- CVE-2025-55675MEDIUMCVSS 6.5EG 6.52025-08-14
Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources they do not have permission to access. By iterati…
- CVE-2025-57438MEDIUMCVSS 6.8EG 6.82025-09-22
The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intended to be accessible only after the admin explicitly grants access to a manager-level account. However, a manager-level …
- CVE-2025-58156LOWCVSS 1.9EG 1.92025-08-29
Centurion ERP is an ERP with a focus on ITSM and automation. In versions starting from 1.12.0 to before 1.21.0, an authenticated user can view all authentication token details within the database. This includes the actual token, although o…
- CVE-2025-58386CRITICALCVSS 9.8EG 9.82025-12-02
In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks. A Power User can intercept and modify this parameter to assign the Administrator role to …
- CVE-2025-59100MEDIUMCVSS 5.9EG 5.92026-01-26
The web interface offers a functionality to export the internal SQLite database. After executing the database export, an automatic download is started and the device reboots. After rebooting, the exported database is deleted and cannot be …
- CVE-2025-59271HIGHCVSS 8.7EG 8.72025-10-09
Redis Enterprise Elevation of Privilege Vulnerability
- CVE-2025-59305HIGHCVSS 7.6EG 7.62025-09-24
Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to data corruption or denial of service through unauthorized acc…
- CVE-2025-59686MEDIUMCVSS 6.5EG 6.52025-10-01
Kazaar 1.25.12 allows /api/v1/org-id/orders/order-id/documents calls with a modified order-id.
- CVE-2025-60784MEDIUMCVSS 6.5EG 6.52025-11-05
A vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou parameter in the /topfirst.php Pay module, enabling unauthorized discounts. By sending a crafted HTTP POST request with zhekou…
- CVE-2025-6088MEDIUMCVSS 3.1EG 4.22025-09-11
In version 0.7.8 of danny-avila/librechat, improper authorization controls in the conversation sharing feature allow unauthorized access to other users' conversations if the conversation ID is known. Although UUIDv4 conversation IDs are ge…
- CVE-2025-6099MEDIUMCVSS 5.3EG 5.32025-06-16
A vulnerability was found in szluyu99 gin-vue-blog up to 61dd11ccd296e8642a318ada3ef7b3f7776d2410. It has been declared as critical. This vulnerability affects unknown code of the file gin-blog-server/internal/manager.go of the component P…
- CVE-2025-61524HIGHCVSS 7.2EG 7.22025-10-08
An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.2.63.0, allows remote authenticated administrators of any organization within the system to bypass …
- CVE-2025-61781HIGHCVSS 9.1EG 7.12026-01-05
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "WorkspacePopoverDeletionMutation" allows users to delete workspace-related objects such as d…
- CVE-2025-61928CRITICALCVSS 9.3EG 9.32025-10-09
Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modify API keys for any user by passing that user's id in the request body to the `api/auth/api…
- CVE-2025-62401MEDIUMCVSS 4.3EG 4.32025-10-23
An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment.
- CVE-2025-62520MEDIUMCVSS 4.3EG 4.32025-11-04
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, due to insufficient access-level checks, any non-admin user with access to manage_config_columns_page.php can use the Copy From action to retrieve…
- CVE-2025-62610HIGHCVSS 8.1EG 8.12025-10-22
Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middleware does not provide a built-in aud (Audience) verification option, which can cause con…
- CVE-2025-63218CRITICALCVSS 9.8EG 9.82025-11-19
The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user …
- CVE-2025-6329HIGHCVSS 8.1EG 8.12025-06-20
A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file userdelete.php of the component User Delete Handler. The manipulation of t…
- CVE-2025-63691CRITICALCVSS 9.6EG 9.62025-11-07
In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the token query interface (/api/admin/sys-token/page) has an improper permission verification issue, which leads to inform…
- CVE-2025-64062HIGHCVSS 8.8EG 8.82025-11-25
The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the authenticated session. By manipulating the email parameter to an arbitrary value (e.g., other…
- CVE-2025-64063CRITICALCVSS 9.8EG 9.82025-11-25
Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specifically, a standard user can exploit this flaw by sending direct HTTP requests to administrative endpoints, bypassing th…
- CVE-2025-64065HIGHCVSS 8.8EG 8.82025-11-25
The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The administrative LoginAs or user impersonation feature is vulnerable to a access control failure. This flaw allows any a…
- CVE-2025-6431MEDIUMCVSS 6.5EG 6.52025-06-24
When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed this prompt, potentially exposing the user to security vulnerabilities or privacy …
- CVE-2025-64523HIGHCVSS 8.8EG 8.82025-11-12
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Versions prior to 2.45.1 have an Insecure Direct Object Reference (IDOR) vulnerability in th…
- CVE-2025-64655CRITICALCVSS 9.8EG 9.82025-11-20
Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-64751HIGHCVSS 8.8EG 8.82025-11-21
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <= docker <= v.1.11.0) are…
- CVE-2025-65020MEDIUMCVSS 6.5EG 6.52025-11-19
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability in the poll duplication endpoint (/api/trpc/polls.duplicate) allows any authenticated user to dupl…
- CVE-2025-65021CRITICALCVSS 9.1EG 9.12025-11-19
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability exists in the poll finalization feature of the application. Any authenticated user can finalize a …
- CVE-2025-65028MEDIUMCVSS 6.5EG 6.52025-11-19
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows any authenticated user to modify other participants’ votes in polls without authorization…
- CVE-2025-65029HIGHCVSS 8.1EG 8.12025-11-19
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows any authenticated user to delete arbitrary participants from polls without ownership verifi…
- CVE-2025-65030HIGHCVSS 7.1EG 7.12025-11-19
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the comment deletion API allows any authenticated user to delete comments belonging to other users, including poll owners and admi…
- CVE-2025-65031MEDIUMCVSS 6.5EG 6.52025-11-19
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization flaw in the comment creation endpoint allows authenticated users to impersonate any other user by altering the authorName field i…
- CVE-2025-65033HIGHCVSS 8.1EG 8.12025-11-19
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll management feature allows any authenticated user to pause or resume any poll, regardless of ownership. The system only us…
- CVE-2025-65041CRITICALCVSS 10.0EG 10.02025-12-18
Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-65094HIGHCVSS 8.8EG 8.82025-11-19
WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrators group by manipulating the groups[] parameter in the /admin/users/save.php request. The U…
- CVE-2025-65107MEDIUMCVSS 6.5EG 6.52025-11-21
Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in SSO provider configurations without an explicit AUTH_<PROVIDER>_CHECK setting, a potentia…
- CVE-2025-6525MEDIUMCVSS 4.3EG 4.32025-06-23
A vulnerability classified as problematic was found in 70mai 1S up to 20250611. This vulnerability affects unknown code of the file /cgi-bin/Config.cgi?action=set of the component Configuration Handler. The manipulation leads to improper a…
- CVE-2025-65782MEDIUMCVSS 6.5EG 6.52025-12-15
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling allows board members (and potentially other authenticated users) to add/remove arbitrary u…
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →