CVEbaza.plSłownik CWECWE-939
Common Weakness Enumeration

CWE-939

Improper Authorization in Handler for Custom URL Scheme

Kategoria: BaseCVE: 28
Opis

Produkt używa obsługi dla niestandardowego schematu URL, ale nie ogranicza prawidłowo, którzy użytkownicy mogą wywołać obsługę za pośrednictwem tego schematu. Może to prowadzić do nieautoryzowanego dostępu do funkcjonalności lub danych aplikacji.

Description (EN)

The product uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme.

Podatności CVE z CWE-939 (28)
8.7
CVSS
HIGH
CVE-2026-6445

A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated user with low privileges.

pub. 2026-06-09
8.6
CVSS
HIGH
CVE-2024-33606

An attacker could retrieve sensitive files (medical images) as well as plant new medical images or overwrite existing medical images on a MicroDicom DICOM Viewer system. User interaction is required to exploit this vulnerability.

pub. 2024-06-11
8.3
CVSS
HIGH
CVE-2026-35394

Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-mcp passes user-supplied URLs directly to Android's intent system without any scheme validation, allowing execution of arbitrary Android intents, including USSD codes, phone calls, SMS messages, and content provider access. This vulnerability is fixed in 0.0.50.

pub. 2026-04-06
8.1
CVSS
HIGH
CVE-2026-53407

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

pub. 2026-06-12
8.1
CVSS
HIGH
CVE-2026-53408

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

pub. 2026-06-12
7.6
CVSS
HIGH
CVE-2026-1046

Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577

pub. 2026-02-16
7.2
CVSS
HIGH
CVE-2021-31384

Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempts to access J-Web administrative interfaces can successfully do so from any device interface regardless of the web-management configuration and filter rules which may otherwise protect access to J-Web. This issue affects: Juniper Networks Junos OS SRX Series 20.4 version 20.4R1 and later versions prior to 20.4R2-S1, 20.4R3; 21.1 versions prior to 21.1R1-S1, 21.1R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.

pub. 2021-10-19
6.5
CVSS
MEDIUM
CVE-2026-3471

Aplikacja Mattermost Desktop w wersji <=6.1, 6.0.1 oraz 5.4.13.0 nie zapobiega załadowaniu nieprawidłowego adresu URL w oknie pop-up, co pozwala złośliwemu administratorowi serwera na wielokrotne awarie aplikacji poprzez wywołanie {{window.open('javascript:alert()');}}.

pub. 2026-05-18
6.4
CVSS
MEDIUM
CVE-2026-33335

Vikunja to platforma typu open-source do zarządzania zadaniami z możliwością samodzielnego hostowania. Od wersji 0.21.0 do wersji 2.2.0 wrapper Electron dla Vikunja Desktop przekazuje adresy URL z wywołań `window.open()` bezpośrednio do `shell.openExternal()` bez żadnej walidacji lub whitelisty protokołów. Atakujący, który umieści link z atrybutem `target="_blank"` (lub inny element wyzwalający `window.open`) w zawartości tworzonej przez użytkownika, może skłonić system operacyjny ofiary do otwarcia dowolnych schematów URI, co prowadzi do wywoływania lokalnych aplikacji, otwierania lokalnych plików lub uruchamiania niestandardowych procedur obsługi protokołów. Wersja 2.2.0 zawiera poprawkę.

pub. 2026-03-24
6.1
CVSS
MEDIUM
CVE-2024-41918

'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme. An arbitrary site may be displayed on the WebView of the product via Intent from another application installed on the user's device. As a result, the user may be redirected to an unauthorized site, and the user may become a victim of a phishing attack.

pub. 2024-08-29
5.7
CVSS
MEDIUM
CVE-2020-11000

GreenBrowser before version 1.2 has a vulnerability where apps that rely on URL Parsing to verify that a given URL is pointing to a trust server may be susceptible to many different ways to get URL parsing and verification wrong, which allows an attacker to circumvent the access control. This problem has been patched in version 1.2.

pub. 2020-04-08
5.5
CVSS
MEDIUM
CVE-2026-26123

Brak CWE w kategorii RCA w Microsoft Authenticator pozwala nieuprawnionym atakującym na ujawnienie informacji lokalnie.

pub. 2026-03-10
5.5
CVSS
MEDIUM
CVE-2023-43582

Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

pub. 2023-11-15
5.3
CVSS
MEDIUM
CVE-2026-21075

Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.

pub. 2026-08-10
5.3
CVSS
MEDIUM
CVE-2025-41408

Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remote unauthenticated attacker may lead a user to access an arbitrary website on the vulnerable App. As a result, the user may become a victim of a phishing attack.

pub. 2025-09-05
5.3
CVSS
MEDIUM
CVE-2022-20736

A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to access a configuration file and the login page for an administrative console that they would not normally have authorization to access. This vulnerability is due to improper authorization checking for HTTP requests that are submitted to the affected web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected instance of AppDynamics Controller. A successful exploit could allow the attacker to access the login page for an administrative console. AppDynamics has released software updates that address this vulnerability.

pub. 2022-06-15
4.8
CVSS
MEDIUM
CVE-2026-21062

Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.

pub. 2026-08-10
4.8
CVSS
MEDIUM
CVE-2026-12190

W aplikacji Genspark AI Workspace App 2.8.4 na Androida wykryto podatność wpływającą na nieznany kod komponentu ai.mainfunc.genspark. Manipulacja prowadzi do improper authorization w handler obsługującym niestandardowy schemat URL. Atak można przeprowadzić wyłącznie z lokalnego środowiska. Producent został wcześnie powiadomiony o ujawnieniu, ale nie udzielił żadnej odpowiedzi.

pub. 2026-06-14
4.6
CVSS
MEDIUM
CVE-2026-73335

Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing arbitrary JavaScript to be executed within the affected application.

pub. 2026-08-26
4.3
CVSS
MEDIUM
CVE-2026-59717

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Android Companion app is vulnerable to an open redirect. The app passes the URL fragment from a homeassistant://invite deep link into the onboarding flow without ever displaying the destination hostname. Because no screen in the invitation or onboarding flow shows the parsed server URL before onboarding commits to it, a victim has no way to distinguish a legitimate invite from a malicious one. An attacker can craft an invite so that a single tap on the legitimate-looking "Connect to my Home Assistant server" button opens their /auth/authorize endpoint in the URL-less onboarding WebView, presenting a look-alike login page that captures the victim's credentials. Since invitations are intended to onboard brand-new users, targets are especially unlikely to notice the substitution. This issue is fixed in version 2026.6.1.

pub. 2026-08-07
Pokazano 20 z 28 podatności
Informacje
ID: CWE-939
Typ: Base
Podatności: 28
MITRE CWE ↗
← Słownik CWE