CWE-285

High likelihood

Improper Authorization

Parent: CWE-284 - Improper Access Control

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

1,461 vulnerabilities with CWE-285
CVE-2026-47673 MEDIUM
Hono: JWT middleware accepts any Authorization scheme, not only Bearer
CVSS 4.8
CVE-2026-6938 MEDIUM
IBM® Db2® is vulnerable to authorization bypass when uploading to a remote object storage path with a special query
CVSS 6.5
CVE-2026-46620 MEDIUM
e107: CSRF in comment.php moderation endpoints via token-optional validation in session_handler::check()
CVSS 6.5
CVE-2026-9484 MEDIUM
SourceCodester Student Grades Management System classroom.php removeStudentFromClassroom improper authorization
CVSS 6.3
CVE-2026-9483 MEDIUM
SourceCodester Student Grades Management System grades.php improper authorization
CVSS 6.3
CVE-2026-9410 MEDIUM
Sushmi-pal Invoice-System Profile Workflow profile improper authorization
CVSS 4.3
CVE-2026-9409 MEDIUM
Sushmi-pal Invoice-System User Management user improper authorization
CVSS 4.3
CVE-2026-9397 HIGH
Besen BS20 EV Charging Station OTA Update Installation improper authorization
CVSS 8.1
CVE-2026-9376 MEDIUM
JPress UCenter Article Submission Endpoint doWriteSave improper authorization
CVSS 6.3
CVE-2026-9306 LOW
QuantumNous new-api Midjourney Image Relay Endpoint relay-router.go GetByOnlyMJId authorization
CVSS 3.7
CVE-2026-45187 MEDIUM
Apache OFBiz: Improper Authorization in Scheduled Job Creation Allows Low-Privileged Users to Submit System Jobs
CVSS 6.5
CVE-2026-8786 MEDIUM
Tencent WeKnora Config API Endpoint initialization.go getKnowledgeBaseForInitialization authorization
CVSS 6.3
CVE-2026-8747 MEDIUM
Z-BlogPHP Commend Approval c_system_event.php CheckComment improper authorization
CVSS 6.3
CVE-2026-8743 MEDIUM
Open5GS AMF/MME context.c ran_ue_find_by_amf_ue_ngap_id improper authorization
CVSS 6.3
CVE-2026-45365 MEDIUM
Open WebUI: Authenticated users can bypass model access control via exposed query parameter
CVSS 5.4
CVE-2026-45345 MEDIUM
Open WebUI: Missing authorization check at the model update function - models from other users can be updated
CVSS 6.5
CVE-2026-45371 HIGH
SiYuan: SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs
CVE-2026-45147 MEDIUM
SiYuan: Broken access control in SiYuan `/api/tag/getTag` — Reader role can mutate `Conf.Tag.Sort` and persist to disk
CVSS 4.3
CVE-2026-44504 HIGH
Aegra: Cross-user run injection in /threads/{thread_id}/runs (IDOR)
CVE-2026-34656 MEDIUM
Adobe Commerce | Improper Authorization (CWE-285)
CVSS 4.3
CVE-2026-43515 CRITICAL
Apache Tomcat: Security constraints not correctly applied
CVSS 9.1
CVE-2026-43983 HIGH
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
CVSS 8.1
CVE-2026-43912 HIGH
Vaultwarden: Cross-Org Group Binding Enables Unauthorized Read And Write Access Into Another Organization
CVSS 8.7
CVE-2026-42876 MEDIUM
External Secrets Operator: Priviledge escalation with secret overwriting
CVSS 4.9
CVE-2026-42875 MEDIUM
External Secrets Operator: Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore
Details
Vulnerabilities 1,461
Exploit Likelihood High