Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-285 (授权机制不恰当) — Vulnerability Class 1216

1216 vulnerabilities classified as CWE-285 (授权机制不恰当). AI Chinese analysis included.

CWE-285 represents a critical access control weakness where an application fails to verify whether a user possesses the necessary permissions to access a specific resource or execute a particular action. Attackers typically exploit this vulnerability by manipulating request parameters, such as changing user IDs in URLs or API calls, to bypass security checks and access data belonging to other users or perform administrative tasks. This often leads to severe data breaches or unauthorized system modifications. To prevent such flaws, developers must implement robust, centralized authorization mechanisms that consistently validate user privileges for every sensitive operation. Relying solely on client-side checks is insufficient; instead, server-side enforcement using role-based or attribute-based access control ensures that only authenticated and authorized entities can interact with protected resources, thereby maintaining strict integrity and confidentiality.

MITRE CWE Description
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Common Consequences (3)
Confidentiality Read Application Data, Read Files or Directories
An attacker could read sensitive data, either by reading the data directly from a data store that is not properly restricted, or by accessing insufficiently-protected, privileged functionality to read the data.
Integrity Modify Application Data, Modify Files or Directories
An attacker could modify sensitive data, either by writing the data directly to a data store that is not properly restricted, or by accessing insufficiently-protected, privileged functionality to write the data.
Access Control Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands
When access control checks are not applied consistently - or not at all - an attacker could gain privileges and execute unauthorized code or commands by modifying or reading critical data directly, or by accessing insufficiently-protected, privileged functionality.
Mitigations (5)
Architecture and Design Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
Architecture and Design Ensure that you perform access control checks related to your business logic. These checks may be different than the access control checks that you apply to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to…
Architecture and Design Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid. For example, consider using authorization frameworks such as the JAAS Authorization Framework [REF-233] and the OWASP ESAPI Access Control feature [REF-45].
Architecture and Design For web applications, make sure that the access control mechanism is enforced correctly at the server side on every page. Users should not be able to access any unauthorized functionality or information by simply requesting direct access to that page. One way to do this is to ensure that all pages containing sensitive information are not cached, and that all such pages restrict access to requests …
System Configuration, Installation Use the access control capabilities of your operating system and server environment and define your access control lists accordingly. Use a "default deny" policy when defining these ACLs.
Examples (2)
This function runs an arbitrary SQL query on a given database, returning the result of the query.
function runEmployeeQuery($dbName, $name){ mysql_select_db($dbName,$globalDbHandle) or die("Could not open Database".$dbName); //Use a prepared statement to avoid CWE-89 $preparedStatement = $globalDbHandle->prepare('SELECT * FROM employees WHERE name = :name'); $preparedStatement->execute(array(':name' => $name)); return $preparedStatement->fetchAll(); } /.../ $employeeRecord = runEmployeeQuery('EmployeeDB',$_GET['EmployeeName']);
Bad · PHP
The following program could be part of a bulletin board system that allows users to send private messages to each other. This program intends to authenticate the user before deciding whether a private message should be displayed. Assume that LookupMessageObject() ensures that the $id argument is numeric, constructs a filename based on that id, and reads the message details from that file. Also ass…
sub DisplayPrivateMessage { my($id) = @_; my $Message = LookupMessageObject($id); print "From: " . encodeHTML($Message->{from}) . "<br>\n"; print "Subject: " . encodeHTML($Message->{subject}) . "\n"; print "<hr>\n"; print "Body: " . encodeHTML($Message->{body}) . "\n"; } my $q = new CGI; # For purposes of this example, assume that CWE-309 and # CWE-523 do not apply. if (! AuthenticateUser($q->param('username'), $q->param('password'))) { ExitError("invalid username or password"); } my $id = $q->param('id'); DisplayPrivateMessage($id);
Bad · Perl
CVE ID Title CVSS Severity Published
CVE-2026-90566 Rizwan17 inventory-management-system Registration register.php createUserAccount improper authorization — inventory-management-system 7.3 High 2026-09-13
CVE-2026-90520 jaychouchannel Tourism-Management-System Authorization Interceptor AuthorizationInterceptor.java improper authorization — Tourism-Management-System 6.3 Medium 2026-09-13
CVE-2026-90499 lenve vhr Password Update pass HrInfoController.updatePass improper authorization — vhr 5.4 Medium 2026-09-13
CVE-2026-44715 OpenMRS has Broken Access Control in HL7 Configuration — org.openmrs.module:legacyui-api 8.7 High 2026-09-11
CVE-2026-53952 GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creation via Setup Logic Flaw — GetSimpleCMS-CE 9.8 Critical 2026-09-11
CVE-2026-80378 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software — DataStage on Cloud Pak for Data 8.5 High 2026-09-10
CVE-2026-80436 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software — DataStage on Cloud Pak for Data 8.5 High 2026-09-10
CVE-2026-86804 seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization — CPA-Manager-Plus 5.3 Medium 2026-09-08
CVE-2026-58611 Xbox Gaming Services Elevation of Privilege Vulnerability — Xbox Gaming Services 7.8 High 2026-09-08
CVE-2026-86212 Open5GS AMF/MME improper authorization — Open5GS 4.3 Medium 2026-09-06
CVE-2026-17483 IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ] — Db2 Mirror for i 4.3 Medium 2026-09-04
CVE-2026-18175 IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ] — i 8.1 High 2026-09-04
CVE-2026-85241 SpecterOps BloodHound Graph Write Endpoint v2.go NewV2API improper authorization — BloodHound 6.3 Medium 2026-09-03
CVE-2026-79989 Arbitrary user password reset leading to administrator account takeover — cms 8.7 High 2026-09-02
CVE-2026-84799 Craft CMS before 5.11.0 PII Disclosure via GraphQL User Relations — cms 4.3 Medium 2026-09-02
CVE-2026-82594 LogNet grpc-spring-boot-starter Annotation Processing improper authorization — grpc-spring-boot-starter 5.0 Medium 2026-08-30
CVE-2026-82553 sambitraj Student Management System Student Dashboard student_dashboard.php mysqli_query improper authorization — Student Management System 6.3 Medium 2026-08-30
CVE-2026-82658 Admidio before 5.0.12 Broken Access Control via profile_function.php — admidio 4.3 Medium 2026-08-30
CVE-2026-55547 Yamcs: Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration — yamcs 4.3 Medium 2026-08-28
CVE-2026-55065 Vikunja: Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/api — vikunja 8.1 High 2026-08-28
CVE-2026-54766 Vikunja: Project duplication bypasses write-permission check on the target parent project — vikunja 5.3 Medium 2026-08-28
CVE-2026-50152 Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users — ceph 9.1 Critical 2026-08-27
CVE-2026-16279 Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x — 3DSwymer 9.3 Critical 2026-08-27
CVE-2026-35445 Winter: Authenticated backend users can bypass Users controller permission checks — winter 7.1 High 2026-08-26
CVE-2026-70665 Doorkeeper OpenID Connect: DCR endpoint persists unvalidated client-supplied scopes — doorkeeper-openid_connect 4.2 Medium 2026-08-25
CVE-2026-66422 Apache Tomcat: Servlet role references can bypass declarative role constraints — Apache Tomcat - - 2026-08-25
CVE-2026-55571 djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls — djust 8.2 High 2026-08-25
CVE-2026-79667 Ech0 before 4.4.3 Authentication Bypass via Scope Enforcement — Ech0 7.6 High 2026-08-25
CVE-2026-78158 Open5GS AMF UEContextReleaseRequest Path improper authorization — Open5GS 6.3 Medium 2026-08-24
CVE-2026-78115 SourceCodester Class and Exam Timetabling System User Account Update edit_user_account.php improper authorization — Class and Exam Timetabling System 5.4 Medium 2026-08-23

Vulnerabilities classified as CWE-285 (授权机制不恰当) represent 1216 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.