CWE-285— Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
1,751 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 2 of 36
- CVE-2025-63218CRITICALCVSS 9.8EG 9.82025-11-19
The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user …
- CVE-2025-31255CRITICALCVSS 9.8EG 9.82025-09-15
An authorization issue was addressed with improved state management. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, watchOS 26. An app may be able to access sensitive user data.
- CVE-2025-7778CRITICALCVSS 9.8EG 9.82025-08-15
The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and improper path validation within the delete_files() function in all versions up to, and including, 1.6.12. This makes it p…
- CVE-2025-8261CRITICALCVSS 9.8EG 9.82025-07-28
A weakness has been identified in Vaelsys VaelsysV4 4.1.0. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the component User Creation Handler. Executing a manipulation can lead to improper authorization. The …
- CVE-2025-4631CRITICALCVSS 9.8EG 9.82025-05-31
The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stocktend_object endpoint in versions 2.0.6.0 to 2.1.1.3. This makes it possible to trigger the save_object_as_user() functio…
- CVE-2025-4104CRITICALCVSS 9.8EG 9.82025-05-07
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form_post() function in versions 1.0 to 2.2.6. This makes it possible for unauthenticated atta…
- CVE-2025-3918CRITICALCVSS 9.8EG 9.82025-05-03
The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the register_action() function in versions 0.1 to 0.1.1. The plugin’s registration handler reads the client-supplied $_POST[…
- CVE-2025-30392CRITICALCVSS 9.8EG 9.82025-04-30
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-29659CRITICALCVSS 9.8EG 9.82025-04-21
Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.
- CVE-2024-9095CRITICALCVSS 9.8EG 9.82025-03-20
In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to create a Datastream to Google BigQuery and export the entire database. This includes sensitive data such as password h…
- CVE-2025-29926CRITICALCVSS 9.8EG 9.82025-03-19
XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. …
- CVE-2025-2345CRITICALCVSS 9.8EG 9.82025-03-16
A vulnerability, which was classified as very critical, was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. This affects an unknown part. The manipulation leads to improper authorization. It is possible to initiate the attack re…
- CVE-2025-25196CRITICALCVSS 9.8EG 9.82025-02-19
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, docker < v.1.8.4) are vulnerable to authorization bypass when c…
- CVE-2024-56323CRITICALCVSS 9.8EG 9.82025-01-13
OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass under the following conditions: 1. calling Check API…
- CVE-2024-7015CRITICALCVSS 9.8EG 9.82024-09-09
Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse. This issue affects PassBox: before v1.2.
- CVE-2024-8181CRITICALCVSS 9.8EG 9.82024-08-27
An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.
- CVE-2024-36130CRITICALCVSS 9.8EG 9.82024-08-07
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.
- CVE-2024-36108CRITICALCVSS 9.8EG 9.82024-05-31
casgate is an Open Source Identity and Access Management system. In affected versions `casgate` allows remote unauthenticated attacker to obtain sensitive information via GET request to an API endpoint. This issue has been addressed in PR …
- CVE-2024-28285CRITICALCVSS 9.8EG 9.82024-05-14
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges.
- CVE-2024-34257CRITICALCVSS 9.8EG 9.82024-05-08
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges.
- CVE-2024-32881CRITICALCVSS 9.8EG 9.82024-04-26
Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Tokens. Anyone with network access can steal slack bot tokens and set them. This implies full c…
- CVE-2023-42491CRITICALCVSS 9.8EG 9.82023-10-25
EisBaer Scada - CWE-285: Improper Authorization
- CVE-2022-3748CRITICALCVSS 9.8EG 9.82023-04-14
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.
- CVE-2023-1256CRITICALCVSS 9.8EG 9.82023-03-16
The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.
- CVE-2022-3229CRITICALCVSS 9.8EG 9.82023-02-06
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol,…
- CVE-2022-24083CRITICALCVSS 9.8EG 9.82022-07-25
Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.
- CVE-2021-42338CRITICALCVSS 9.8EG 9.82021-11-19
4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrarily manipulate the system or interrupt services by upload…
- CVE-2021-3044CRITICALCVSS 9.8EG 9.82021-06-22
An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: C…
- CVE-2021-32619CRITICALCVSS 9.8EG 9.82021-05-28
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, modules that are dynamically imported through `import()` or `new Worker` might have been able to bypass network and file s…
- CVE-2020-12500CRITICALCVSS 9.8EG 9.82020-10-15
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated …
- CVE-2020-10516CRITICALCVSS 9.8EG 9.82020-06-03
An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization. This vulnerability…
- CVE-2020-10620CRITICALCVSS 9.8EG 9.82020-05-14
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for example, stopping the service remotely.
- CVE-2019-7489CRITICALCVSS 9.8EG 9.82019-12-23
A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.
- CVE-2019-13550CRITICALCVSS 9.8EG 9.82019-09-18
In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensitive information, cause improper control of generation of code, which may allow remote code execution or cause a system …
- CVE-2018-14670CRITICALCVSS 9.8EG 9.82019-08-15
Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.
- CVE-2015-5463CRITICALCVSS 9.8EG 9.82019-04-03
AxiomSL's Axiom java applet module (used for editing uploaded Excel files and associated Java RMI services) 9.5.3 and earlier allows remote attackers to (1) access data of other basic users through arbitrary SQL commands, (2) perform a hor…
- CVE-2015-3954CRITICALCVSS 9.8EG 9.82019-03-25
Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior give unauthenticated users root privileges on Port 23/TELNET by default. An unautho…
- CVE-2016-10734CRITICALCVSS 9.8EG 9.82018-10-29
ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
- CVE-2017-16743CRITICALCVSS 9.8EG 9.82018-01-12
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing a…
- CVE-2017-6044CRITICALCVSS 9.8EG 9.82017-06-30
An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, whi…
- CVE-2016-0922CRITICALCVSS 9.8EG 9.82016-09-18
EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force guessing attack.
- CVE-2016-6825CRITICALCVSS 9.8EG 9.82016-09-07
Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, and RH2288H V3 servers with softwar…
- CVE-2016-5799CRITICALCVSS 9.8EG 9.82016-08-24
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
- CVE-2022-38375CRITICALCVSS 9.1EG 9.82023-02-16
An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST…
- CVE-2021-27663CRITICALCVSS 8.2EG 9.82021-08-30
A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequate authorization. This issue affects: Johnson Controls CEM Systems AC2000 10.1; 10.2; 10.3;…
- CVE-2024-37282CRITICALCVSS 8.1EG 9.82024-06-28
It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create new API keys that have elevated privileges.
- CVE-2022-0993CRITICALCVSS 8.1EG 9.82022-04-19
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs u…
- CVE-2021-35964CRITICALCVSS 7.3EG 9.82021-07-19
The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modify and delete the…
- CVE-2022-30722CRITICALCVSS 6.2EG 9.82022-06-07
Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.
- CVE-2022-39862CRITICALCVSS 5.3EG 9.82022-10-07
Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S(12) allows unauthorized use of javascript interface api.
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →