CWE-285

High likelihood

Improper Authorization

Parent: CWE-284 - Improper Access Control

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

1,461 vulnerabilities with CWE-285
CVE-2026-40248 HIGH
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions
CVSS 7.5
CVE-2026-40247 HIGH
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions
CVSS 7.5
CVE-2026-40246 HIGH
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions
CVSS 7.5
CVE-2026-34370 MEDIUM
Chamilo LMS: IDOR in the Notebook Module allows an attacker to view other users' private notes
CVSS 6.5
CVE-2026-33146 MEDIUM
Docmost's Public Share Search Exposes Metadata of Restricted Children
CVSS 4.3
CVE-2026-27912 HIGH
Windows Kerberos Elevation of Privilege Vulnerability
CVSS 8.0
CVE-2026-38533 MEDIUM
Snipe-IT 8.4.0 - Privilege Escalation
CVSS 6.5
CVE-2026-6105 HIGH
perfree go-fastdfs-web doInstall InstallController.java improper authorization
CVSS 7.3
CVE-2026-32252 HIGH
Chartbrew Cross-Tenant Template Export and Secret Disclosure in `GET /team/:team_id/template/generate/:project_id`
CVSS 7.7
CVE-2026-5412 CRITICAL
Juju CloudSpec API could leak senstive information
CVSS 9.9
CVE-2026-5999 MEDIUM
JeecgBoot SysAnnouncementController improper authorization
CVSS 6.3
CVE-2026-5842 HIGH
decolua 9router Administrative API Endpoint api authorization
CVSS 7.3
CVE-2026-39901 MEDIUM
monetr: Protected Transactions Deletable via PUT
CVSS 5.7
CVE-2026-35479 MEDIUM
InvenTree Plugin Installation - Insufficient Permissions
CVSS 6.6
CVE-2026-35476 HIGH
InvenTree Affected by Privilege Escalation via API
CVSS 7.2
CVE-2026-35407 MEDIUM
Saleor has Cross-Account Email Change via Unbound Confirmation Token
CVSS 6.5
CVE-2026-39389 MEDIUM
CI4MS <0.31.4.0 Fileeditor Hidden Items - Authorization Bypass
CVSS 6.7
CVE-2026-39347 LOW
OrangeHRM's Self‑Appraisal Submission of Admin Users Can Be Modified After Completion
CVSS 2.7
CVE-2026-35610 HIGH
PolarLearn <=0-PRERELEASE-14 Account Management - Admin Bypass
CVSS 8.8
CVE-2026-5642 HIGH
Cyber-III Student-Management-System HTTP POST Request update.php improper authorization
CVSS 7.3
CVE-2026-5529 MEDIUM
Dromara lamp-cloud DefUserController pageUser improper authorization
CVSS 4.3
CVE-2026-33105 CRITICAL
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-32213 CRITICAL
Azure AI Foundry Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-33950 CRITICAL
signalk-server: Privilege Escalation by Admin Role Injection via /enableSecurity
CVSS 9.4
CVE-2026-5326 MEDIUM
SourceCodester Leave Application System User Information index.php authorization
CVSS 5.3
Details
Vulnerabilities 1,461
Exploit Likelihood High