CWE-285: Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
1,375 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-66301 — Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
- CVE-2026-43515 — Apache Tomcat: Security constraints not correctly applied
- CVE-2026-30956 — OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header
- CVE-2026-25893 — FUXA Unauthenticated Remote Code Execution via Admin JWT Minting
- CVE-2026-25885 — PolarLearn allows Unauthenticated WebSocket access allows subscribing to and posting in arbitrary group chats
- CVE-2025-2345 — IROAD Dash Cam X5/Dash Cam X6 improper authorization
- CVE-2024-24830 — OpenObserve Privilege Escalation Vulnerability in Users API
- CVE-2025-7778 — Icons Factory <= 1.6.12 - Missing Authorization to Unauthenticated Arbitrary File Deletion via delete_files() Function
- CVE-2025-4104 — Frontend Dashboard 1.0 - 2.2.6 - Missing Authorization to Unauthenticated Privilege Escalation via fed_wp_ajax_fed_login_form_post Function
- CVE-2024-36108 — Multiple Broken Function-Level Authorization vulnerabilities in casgate
- CVE-2024-32881 — Unauthorized access to GET/SET of Slack Bot Tokens in Danswer
- CVE-2025-29922 — kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace
- CVE-2026-33950 — signalk-server: Privilege Escalation by Admin Role Injection via /enableSecurity
- CVE-2026-26020 — AutoGPT Affected by Remote Code Execution via Dynamic Module Import in Block Loading (__import__)
- CVE-2024-56320 — GoCD vulnerable to admin privilege escalation by a malicious internal/existing authenticated user
- CVE-2026-30847 — Wekan Credential Leak via notificationUsers Publication Exposes Password Hashes and Session Tokens
- CVE-2026-30793 — RustDesk Flutter URI Handler Sets Permanent Password Without Privilege Check or User Confirmation
- CVE-2025-61928 — Better Auth: Unauthenticated API key creation through api-key plugin
- CVE-2025-27509 — SAML authentication vulnerability due to improper SAML response validation
- CVE-2024-52528 — Auth Token can be passed dummy or wrong the middleware response is 200 OK
Recently published
- CVE-2026-86804 — seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization
- CVE-2026-86277 — SourceCodester Syllabus-Aligned Learning Management & Examination System delete_exam.php authorization
- CVE-2026-86263 — sfturing hosp_order Order Cancellation OrderController.java orderRecordsService.cancelOrder authorization
- CVE-2026-86262 — sfturing hosp_order Order OrderController.java updateOrderdiseaseInfo authorization
- CVE-2026-86261 — sfturing hosp_order Order Controller OrderController.java authorization
- CVE-2026-86283 — MISP UiBeta Collection View Bypasses Event ACL, Exposing Unauthorized Event Data
- CVE-2026-86212 — Open5GS AMF/MME improper authorization
- CVE-2026-86183 — diem-project diem dmWidget BasedmWidgetActions.class.php authorization
- CVE-2026-53602 — nebula-mesh - Host revocation is not durable: blocked/offboarded hosts can regain a valid certificate
- CVE-2026-85638 — jofpin trape user.py authorization
- CVE-2026-17483 — IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ]
- CVE-2026-18175 — IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ]
- CVE-2026-85381 — light0011 cms Chapter Controller ChapterController.class.php authorization
- CVE-2026-85378 — light0011 cms Chapter Controller ChapterController.class.php _initialize authorization
- CVE-2026-85241 — SpecterOps BloodHound Graph Write Endpoint v2.go NewV2API improper authorization
- CVE-2026-50554 — Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books in note-mark
- CVE-2026-85105 — NousResearch hermes-agent Session Management s71.py _sess_nowait authorization
- CVE-2026-79989 — Arbitrary user password reset leading to administrator account takeover
- CVE-2026-84799 — Craft CMS before 5.11.0 PII Disclosure via GraphQL User Relations
- CVE-2026-83743 — invoiceninja Invoice Ninja Vendor Portal Profile Update profile authorization
More specific weaknesses
- CWE-1230 — Exposure of Sensitive Information Through Metadata
- CWE-1256 — Improper Restriction of Software Interfaces to Hardware Features
- CWE-1297 — Unprotected Confidential Information on Device is Accessible by OSAT Vendors
- CWE-1328 — Security Version Number Mutable to Older Versions
- CWE-732 — Incorrect Permission Assignment for Critical Resource
- CWE-862 — Missing Authorization
- CWE-863 — Incorrect Authorization
- CWE-926 — Improper Export of Android Application Components
- CWE-927 — Use of Implicit Intent for Sensitive Communication