CWE-285

High likelihood

Improper Authorization

Parent: CWE-284 - Improper Access Control

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

1,461 vulnerabilities with CWE-285
CVE-2026-60911 MEDIUM
Oracle Property Manager 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-60886 HIGH
Oracle Work in Process 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP with User Interaction
CVSS 7.6
CVE-2026-60844 HIGH
Oracle Customer Support 12.2.3-12.2.15 Auth Bypass via Update Service Request Leads to Data Modification/Access
CVSS 8.1
CVE-2026-60842 MEDIUM
Oracle Knowledge Mgmt 12.2.5-12.2.15: Unauth CSRF & Data Disclosure via HTTP Search
CVSS 6.1
CVE-2026-60152 MEDIUM
PeopleSoft Enterprise PeopleTools 8.61 and 8.62 - Unauthenticated Cross-Site Request Forgery via Panel Processor
CVSS 5.4
CVE-2026-47053 MEDIUM
Oracle VM VirtualBox - Denial of Service
CVSS 5.6
CVE-2026-28312 CRITICAL
SolarWinds Serv-U Privilege Escalation Vulnerability
CVSS 9.1
CVE-2026-16450 MEDIUM
zsadmin2025 ZS-Admin MyBatis-Plus Tenant Plugin page getTenantId authorization
CVSS 4.3
CVE-2026-34239 HIGH
Chamilo Authenticated Remote Code Execution
CVE-2026-32821 HIGH
API Collection Impersonation Via user_email And Missing Object- Level Authorization
CVSS 8.1
CVE-2026-32819 MEDIUM
dataCycle User Directory Enumeration Via /users/search
CVSS 4.3
CVE-2026-32806 HIGH
dataCycle Authorization Bypass Via /remote_render
CVSS 7.5
CVE-2026-32807 HIGH
dataCycle Public DataLink Text File Download Ignores Validity And Authorization
CVSS 7.5
CVE-2026-27823 HIGH
EGroupware <= 23.1.20260131/26.2.20260216 - Remote Code Execution
CVE-2026-63752 MEDIUM
SurrealDB before 3.1.0 RELATE Statement Record Overwrite
CVSS 4.3
CVE-2026-16224 MEDIUM
jxxghp MoviePilot Application API improper authorization
CVSS 4.3
CVE-2026-16217 MEDIUM
guohongze adminset Delivery Deployment Endpoint deli.py authorization
CVSS 6.3
CVE-2026-16214 MEDIUM
geex-arts django-jet Dashboard views.py authorization
CVSS 6.3
CVE-2026-16200 HIGH
zevorn rt-claw RPC swarm.c claw_tool_invoke authorization
CVSS 7.3
CVE-2026-16199 MEDIUM
nextlevelbuilder GoClaw credentialed_exec.go ExecTool.Execute improper authorization
CVSS 6.3
CVE-2026-16195 MEDIUM
Sipeed PicoClaw Group Message wecom.go dispatchIncoming authorization
CVSS 6.3
CVE-2026-16126 HIGH
zevorn rt-claw Swarm RPC Receiver swarm.c handle_rpc_request authorization
CVSS 7.3
CVE-2026-16122 MEDIUM
nextlevelbuilder GoClaw exec_approval.go matchesAllowlist authorization
CVSS 4.3
CVE-2026-16121 MEDIUM
nextlevelbuilder GoClaw exec_approval.go isSafeBin improper authorization
CVSS 6.3
CVE-2026-16119 MEDIUM
nextlevelbuilder GoClaw WebSocket Approval Endpoint exec_approval.go RequestApproval authorization
CVSS 6.3
Details
Vulnerabilities 1,461
Exploit Likelihood High