Threats Tagged 'cwe-285'
View all threats tagged with 'cwe-285'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-285'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-59118: CWE-285: Improper Authorization in Microsoft Microsoft Power AppsCVE-2026-59118 0 Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network. Join the discussion | CVE Database V5 | 08/06/2026, 22:37:37 UTC Added: 08/07/2026, 00:27:01 UTC |
CVE-2026-18367: CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action. in Sophos Sophos Endpoint for macOSCVE-2026-18367 0 CVE-2026-18367 is a critical privilege escalation vulnerability in Sophos Endpoint for macOS and Sophos Home for macOS. It allows local users to execute arbitrary code with root privileges due to improper or missing authorization checks. The vulnerability affects versions older than 2026.1.1 for Sophos Endpoint and older than 10.11.6 for Sophos Home. The CVSS score is 9.3, indicating a high severity with complete confidentiality, integrity, and availability impact. No official patch or remediation guidance is currently provided by the vendor. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 08/06/2026, 20:30:39 UTC Added: 08/06/2026, 22:13:09 UTC |
CVE-2026-18997: Incorrect Authorization in cosmicstack-labs mercury-agentCVE-2026-18997 0 A vulnerability in cosmicstack-labs mercury-agent up to version 1.1.12 allows remote attackers to cause incorrect authorization via manipulation of the Agent.handleBgCommand function. The issue affects the background command handler component and could lead to limited confidentiality, integrity, and availability impacts. The vulnerability has a CVSS score of 6.3 and is classified as low severity. No patch or official fix has been reported yet, and the project has not responded to the issue report. Exploit code has been made public, but no known exploitation in the wild has been confirmed. Join the discussion | GCVE Database | 08/06/2026, 04:30:10 UTC Added: 08/06/2026, 18:17:13 UTC |
CVE-2026-18992: Incorrect Authorization in zhayujie CowAgentCVE-2026-18992 0 CVE-2026-18992 is a vulnerability in zhayujie CowAgent up to version 2.1.1 affecting the _select_tools function in the Self-Evolution Review Agent component. It allows remote attackers to cause incorrect authorization. The vulnerability has a CVSS score of 6.3, indicating a moderate impact on confidentiality, integrity, and availability. Exploit code is publicly available, but no known exploitation in the wild has been reported. No patch or official remediation information is provided. Join the discussion | GCVE Database | 08/06/2026, 03:30:10 UTC Added: 08/06/2026, 18:17:13 UTC |
CVE-2026-18998: Improper Authorization in cosmicstack-labs mercury-agentCVE-2026-18998 0 A vulnerability exists in cosmicstack-labs mercury-agent up to version 1.1.12 affecting the SubAgent.run function in the delegate_task Tool component. This vulnerability allows improper authorization through a remotely executable manipulation. The issue was reported early to the project, but no response or fix has been provided yet. The vulnerability has a CVSS score of 6.3, indicating a medium severity level. Exploit code has been publicly disclosed, but there are no known exploits in the wild at this time. Join the discussion | GCVE Database | 08/06/2026, 04:45:09 UTC Added: 08/06/2026, 18:17:13 UTC |
CVE-2026-19006: Incorrect Authorization in mf-yang openclaw-cnCVE-2026-19006 0 CVE-2026-19006 is a vulnerability in mf-yang openclaw-cn 2026.2.5 affecting the Ggateway Exec Approval Flow component. It involves incorrect authorization due to manipulation in the src/agents/bash-tools.exec.ts file. The vulnerability can be exploited remotely and the exploit code has been publicly disclosed. The project has been notified but has not yet responded or issued a fix. The CVSS score is 6.3, indicating a medium severity impact. Join the discussion | GCVE Database | 08/06/2026, 06:00:11 UTC Added: 08/06/2026, 18:17:07 UTC |
CVE-2026-70472: CWE-285: Improper Authorization in FlowiseAI FlowiseCVE-2026-70472 0 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without checking whether that credential belongs to the caller workspace. Route permissions assistants:* only check feature access. The controller passes req.query.credential straight to the service, and the service uses findOneBy({ id: credentialId }), decrypts the credential, and calls OpenAI APIs without a workspaceId check. If an attacker knows another workspace credentialId, the attacker can use that workspace OpenAI key, read, modify, or delete victim vector stores and files, cause billing impact on the victim OpenAI account, and violate multi-tenant boundaries. This issue is fixed in version 3.1.3. Join the discussion | CVE Database V5 | 08/04/2026, 17:46:05 UTC Added: 08/04/2026, 18:34:00 UTC |
CVE-2026-48115: CWE-285: Improper Authorization in misskey-dev misskeyCVE-2026-48115 0 Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in the Server Announcements API where insufficient permission checks allow attackers to access limited portions of data that they normally couldn't view. This vulnerability occurs whether or not federation is enabled. This issue has been fixed in version 2026.5.4. Join the discussion | CVE Database V5 | 08/03/2026, 21:21:59 UTC Added: 08/03/2026, 21:48:52 UTC |
CVE-2026-14538: CWE-285 (Improper Authorization) in Google mcp-toolboxCVE-2026-14538 0 An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery dry-run API to enforce dataset restrictions, but due to a fail-open logic flaw, it bypasses validation when the API returns an empty array for specialized constructs. This allows the attacker to extract structural DDL schemas for explicitly excluded datasets via INFORMATION_SCHEMA, and access downstream federated row data via EXTERNAL_QUERY connections. Join the discussion | CVE Database V5 | 07/31/2026, 01:42:29 UTC Added: 07/31/2026, 01:52:38 UTC |
CVE-2026-41187: CWE-285 Improper Authorization in Tigera CalicoCVE-2026-41187 0 CVE-2026-41187 is a medium severity vulnerability in Tigera Calico 3.32.0 involving improper authorization. The issue arises because the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. This allows users with deletecollection or wildcard delete permissions on tier-scoped policy resources to bulk-delete policies in tiers where they do not have explicit rights, breaking the tier authorization boundary. Join the discussion | CVE Database V5 | 07/30/2026, 14:45:04 UTC Added: 07/30/2026, 16:52:57 UTC |
Showing 1 to 10 of 37 results