CWE-285— Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
1,682 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 31 of 34
- CVE-2026-55775LOWCVSS 2.3EG 2.32026-06-19
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities on /sys/namespaces/root within a non-root namespace could exploit special handling of the literal root path in namespace…
- CVE-2026-55956MEDIUMCVSS 6.5EG 6.52026-06-29
Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0…
- CVE-2026-56160CRITICALCVSS 9.9EG 9.92026-07-23
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
- CVE-2026-56231HIGHCVSS 7.6EG 7.62026-06-24
Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId and POST /build/cancel/:jobId endpoints. The handlers authorize the request based only on the attacker-controlled app_i…
- CVE-2026-56240MEDIUMCVSS 4.3EG 4.32026-07-11
Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. Attackers can exploit the divergenc…
- CVE-2026-56241HIGHCVSS 8.3EG 8.32026-07-12
Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column not being clear…
- CVE-2026-56246HIGHCVSS 8.1EG 8.12026-07-08
Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped API key (limited_to_orgs) inherits its owner-user's permissions, allowing destructive cross-organization actions. When a…
- CVE-2026-56249HIGHCVSS 7.6EG 7.62026-07-01
Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authenticated users to overwrite existing channels by reusing their names. Attackers with app.create_channel permission can e…
- CVE-2026-56293MEDIUMCVSS 5.4EG 5.42026-07-08
Capgo before 12.128.2 contains an authorization flaw in transfer_app() that fails to update deploy_history.owner_org when transferring applications between organizations. Attackers can exploit this omission to retain unauthorized access to…
- CVE-2026-56295MEDIUMCVSS 6.3EG 6.32026-06-20
Capgo before 12.128.2 contains an authorization bypass vulnerability in webhook management endpoints that allows non-expiring API keys to bypass the require_apikey_expiration organization policy. The checkWebhookPermission function fails t…
- CVE-2026-56310MEDIUMCVSS 4.3EG 4.32026-06-24
Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that allows org-limited API keys to bypass limited_to_orgs restrictions. Attackers with org-limited API keys can read membershi…
- CVE-2026-56311MEDIUMCVSS 5.3EG 5.32026-06-22
Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.get_current_plan_max_org RPC function that allows unauthenticated attackers to retrieve arbitrary organization plan limits. Attackers can call the RPC endpo…
- CVE-2026-56313HIGHCVSS 8.1EG 8.12026-07-12
Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations. Attackers with org.upda…
- CVE-2026-56320HIGHCVSS 7.1EG 7.12026-07-01
Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied org_id parameter without validating it matches the target app's owner organization. Authenticated attackers can create devic…
- CVE-2026-56350HIGHCVSS 7.7EG 7.72026-07-01
n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizationa…
- CVE-2026-5642HIGHCVSS 7.3EG 7.32026-04-06
A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affects an unknown function of the file /viva/update.php of the component HTTP POST Request Handler. This manipulati…
- CVE-2026-5781HIGHCVSS 8.8EG 8.82026-04-28
An authorization vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/moUser/update' endpoint, could allow an authenticated user with user modification privileges to escalate their privileges by sending an HTTP request wi…
- CVE-2026-57983HIGHCVSS 8.7EG 8.72026-07-03
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-58251MEDIUMCVSS 6.5EG 6.52026-07-08
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user with subscription deny permissions could bypass a plain subject deny rule by usin…
- CVE-2026-58252MEDIUMCVSS 6.5EG 6.52026-07-08
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user could receive messages on denied subjects when a wildcard subscription overlapped…
- CVE-2026-58277HIGHCVSS 8.8EG 8.82026-07-14
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2026-58284HIGHCVSS 8.3EG 8.32026-07-03
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-5842HIGHCVSS 7.3EG 7.32026-04-09
A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The atta…
- CVE-2026-58424HIGHCVSS 8.9EG 8.92026-07-03
Permanent Fork PR Workflow Approval Gate Bypass
- CVE-2026-58540HIGHCVSS 7.8EG 7.82026-07-14
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
- CVE-2026-58611HIGHCVSS 7.8EG 7.82026-09-08
Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-58631HIGHCVSS 7.8EG 7.82026-07-14
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
- CVE-2026-58704CRITICALCVSS 8.8EG 9.0⚠ KEV2026-09-15
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed…
- CVE-2026-59118CRITICALCVSS 9.3EG 9.32026-08-06
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-59226MEDIUMCVSS 4.3EG 4.32026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rechecking that they were still active or still had features.automation…
- CVE-2026-5999MEDIUMCVSS 6.3EG 6.32026-04-10
A vulnerability has been found in JeecgBoot up to 3.9.1. This impacts an unknown function of the component SysAnnouncementController. Such manipulation leads to improper authorization. The attack can be launched remotely. The exploit has b…
- CVE-2026-60152MEDIUMCVSS 5.4EG 5.42026-07-21
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker wi…
- CVE-2026-60842MEDIUMCVSS 6.1EG 6.12026-07-21
Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with networ…
- CVE-2026-60844HIGHCVSS 8.1EG 8.12026-07-21
Vulnerability in the Oracle Customer Support product of Oracle E-Business Suite (component: Update Service Request). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker …
- CVE-2026-60886HIGHCVSS 7.6EG 7.62026-07-21
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with…
- CVE-2026-60911MEDIUMCVSS 5.4EG 5.42026-07-21
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wit…
- CVE-2026-60957MEDIUMCVSS 5.4EG 5.42026-07-21
Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged atta…
- CVE-2026-6105HIGHCVSS 7.3EG 7.32026-04-11
A security vulnerability has been detected in perfree go-fastdfs-web up to 1.3.7. This affects an unknown part of the file src/main/java/com/perfree/controller/InstallController.java of the component doInstall Interface. The manipulation l…
- CVE-2026-61082MEDIUMCVSS 6.5EG 6.52026-07-21
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multipl…
- CVE-2026-61487MEDIUMCVSS 6.5EG 6.52026-07-28
Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination wh…
- CVE-2026-61718MEDIUMCVSS 5.4EG 5.42026-07-16
bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb web UI BiscuitMiddleware authorization bypass list included the /cache/ URL prefix, so routes in src/ui/app/routes/cache…
- CVE-2026-61833HIGHCVSS 8.1EG 8.12026-09-18
zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to the …
- CVE-2026-62249MEDIUMCVSS 4.3EG 4.32026-08-26
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, an authenticated user with access to a project can retrieve the change history of restricted components in that proj…
- CVE-2026-62444MEDIUMCVSS 6.1EG 6.12026-07-21
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attack…
- CVE-2026-62563MEDIUMCVSS 5.4EG 5.42026-07-21
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with…
- CVE-2026-62835CRITICALCVSS 7.5EG 9.32026-07-24
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
- CVE-2026-63752MEDIUMCVSS 4.3EG 4.32026-07-20
SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated users with CREATE permission to overwrite existing edge records without UPDATE permission. Attackers can issue a RELATE…
- CVE-2026-6449MEDIUMCVSS 5.3EG 5.32026-05-02
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in authorization logic that c…
- CVE-2026-64642HIGHCVSS 8.2EG 8.22026-07-22
Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can …
- CVE-2026-64711MEDIUMCVSS 5.5EG 5.52026-07-27
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to leak sensitive user information.
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →