You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
authorization flaw
About this tag
The authorization flaw tag covers security vulnerabilities where missing or improper access controls allow users to perform actions beyond their intended privileges. Recent discussions highlight CVE-2025-11862 in Rockwell Automation's Verve Asset Manager, where read-only API users can escalate privileges to modify or delete accounts, and CVE-2025-21416 in Azure Virtual Desktop, which enables privilege escalation due to missing authorization controls. These threads emphasize the critical nature of such flaws, often scoring high on CVSS, and provide guidance on patching and mitigation. The tag is relevant for IT administrators and security professionals managing enterprise software and cloud services.
Rockwell Automation has released a security advisory confirming a serious access-control vulnerability in Verve Asset Manager that lets read-only API users perform administrative actions on user accounts — including reading, updating, and deleting users. Tracked as CVE-2025-11862, the bug is...
In April 2025, Microsoft disclosed a critical security vulnerability in Azure Machine Learning (Azure ML), identified as CVE-2025-30390. This flaw, stemming from improper authorization mechanisms, allows authorized attackers to escalate their privileges over a network, potentially compromising...
A critical security vulnerability identified as CVE-2025-21416 has been disclosed in Azure Virtual Desktop, Microsoft’s cloud-based remote desktop solution, drawing the attention of enterprises and security professionals worldwide. This vulnerability centers on an elevation of privilege risk...
In April 2025, a critical security vulnerability identified as CVE-2025-30389 was discovered in the Azure Bot Framework SDK. This flaw allowed unauthorized attackers to elevate their privileges over a network due to improper authorization mechanisms within the SDK.
Understanding the...