CWE-285

High likelihood

Improper Authorization

Parent: CWE-284 - Improper Access Control

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

1,461 vulnerabilities with CWE-285
CVE-2026-13490 LOW
glpi-project glpi Document document.send.php canViewFile authorization
CVSS 3.7
CVE-2026-49278 MEDIUM
Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor Impersonation
CVSS 6.7
CVE-2026-56310 MEDIUM
Cap-go - Authorization Bypass in Organization Members Endpoint via API Key Scope Bypass
CVSS 4.3
CVE-2026-56231 HIGH
Capgo - Broken Object Level Authorization in Build Job Control via jobId Parameter
CVSS 7.6
CVE-2026-46552 MEDIUM
NocoDB: Shared-base link access can invite arbitrary users as persistent base members
CVSS 5.8
CVE-2026-54012 HIGH
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
CVSS 7.1
CVE-2026-56311 MEDIUM
Capgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPC
CVSS 5.3
CVE-2026-12799 MEDIUM
BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization
CVSS 4.3
CVE-2026-12797 MEDIUM
BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization
CVSS 6.3
CVE-2026-12771 MEDIUM
BerriAI litellm M2M JWT user_api_key_auth.py improper authorization
CVSS 5.0
CVE-2026-12770 MEDIUM
BerriAI litellm Admin Key key_management_endpoints.py improper authorization
CVSS 5.4
CVE-2026-56295 MEDIUM
Capgo - Policy Enforcement Bypass in Webhook Management Endpoints via Non-Expiring API Keys
CVSS 6.3
CVE-2026-12673 MEDIUM
Liquidfiles < 4.2.12 - Improper Authorization
CVE-2026-48089 HIGH
DevGuard has improper authorization on public assets
CVE-2026-49338 HIGH
Sentriz Gonic < 0.21.0 - Authenticated Private Playlist Disclosure and Deletion
CVSS 7.1
CVE-2026-50201 MEDIUM
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
CVSS 6.5
CVE-2026-20190 HIGH
Cisco Identity Services Engine Information Disclosure Vulnerability
CVSS 7.5
CVE-2026-12213 MEDIUM
hcengineering Huly Platform User Information operations.ts getAccountInfo improper authorization
CVSS 4.3
CVE-2026-12204 HIGH
ShopXO Scheduled Task Endpoint Crontab.php GoodsGiveIntegral authorization
CVSS 7.3
CVE-2026-12190 MEDIUM
Genspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for custom url scheme
CVSS 5.3
CVE-2026-12189 MEDIUM
Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme
CVSS 5.3
CVE-2026-49397 MEDIUM
Nezha Monitoring: Private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
CVSS 5.3
CVE-2026-44208 MEDIUM
Frappe: IDOR in `submit_discussion()`
CVE-2026-12065 LOW
Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
CVSS 1.8
CVE-2026-47342 HIGH
Apache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass
CVSS 8.8
Details
Vulnerabilities 1,461
Exploit Likelihood High