CWE-285

High likelihood

Improper Authorization

Parent: CWE-284 - Improper Access Control

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

1,461 vulnerabilities with CWE-285
CVE-2026-46668 LOW
SpiceDB: Caveat structures with nested lists can result in improper cache reuse
CVE-2026-47298 HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVSS 8.0
CVE-2026-45503 HIGH
Microsoft Exchange Server Information Disclosure Vulnerability
CVSS 8.1
CVE-2026-45490 HIGH
Microsoft .NET - Local Privilege Escalation
CVSS 7.8
CVE-2026-42902 HIGH
Microsoft PowerToys Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-11619 MEDIUM
Dolibarr ERP CRM Legacy Filemanager config.inc.php improper authorization
CVSS 6.3
CVE-2026-46484 HIGH
Headplane renameNode - Authenticated Path Traversal and RBAC Bypass
CVSS 8.1
CVE-2026-11533 MEDIUM
imvks786 student_management_system Student Deletion Endpoint see.php improper authorization
CVSS 5.4
CVE-2026-46656 HIGH
Bludit CMS has improper authorization and mediation failure leading to persistent ghost sessions
CVSS 8.8
CVE-2026-11521 MEDIUM
Mohammed-eid35 bank-management-system-springboot Transaction Endpoint TransactionController.java improper authorization
CVSS 6.3
CVE-2026-11519 MEDIUM
SourceCodester Inventory System Account Creation users_handler.php improper authorization
CVSS 6.3
CVE-2026-11500 MEDIUM
Weaviate Static API Key client.go validateConfig authorization
CVSS 5.0
CVE-2026-11476 MEDIUM
Kushan2k student-management-system Profile Update Endpoint AdminController.php edit-admin improper authorization
CVSS 6.3
CVE-2026-11462 HIGH
Chengdu Everbrite Network Technology BeikeShop Stripe Plugin StripeController.php callback improper authorization
CVSS 7.3
CVE-2026-11461 MEDIUM
NousResearch hermes-agent resume Endpoint hermes_state.py resolve_session_by_title authorization
CVSS 6.3
CVE-2026-11441 MEDIUM
theonedev Pull Request issues canAccessIssue improper authorization
CVSS 6.3
CVE-2026-11440 MEDIUM
theonedev REST API default-branch improper authorization
CVSS 6.3
CVE-2026-11439 MEDIUM
theonedev Parent Project projects improper authorization
CVSS 6.3
CVE-2026-11438 MEDIUM
theonedev projects improper authorization
CVSS 6.3
CVE-2026-10580 CRITICAL
Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API
CVSS 9.8
CVE-2026-11336 MEDIUM
tittuvarghese CollegeManagementSystem Admin admin_page.php improper authorization
CVSS 6.3
CVE-2026-10876 MEDIUM
SourceCodester Ship Ferry Ticket Reservation System admin improper authorization
CVSS 6.3
CVE-2026-48579 CRITICAL
Microsoft Exchange Online Information Disclosure Vulnerability
CVSS 9.1
CVE-2026-41522 HIGH
DFIR-IRIS < 2.4.28 - GraphQL Authorization Bypass
CVE-2026-10693 MEDIUM
SourceCodester Online Boat Reservation System Administrative Endpoint improper authorization
CVSS 6.3
Details
Vulnerabilities 1,461
Exploit Likelihood High