CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
5,070 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 1 of 102
- CVE-2025-54253CRITICALCVSS 10.0EG 10.0⚠ KEV2025-08-05
Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute co…
- CVE-2024-45519CRITICALCVSS 10.0EG 10.0⚠ KEV2024-10-02
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
- CVE-2021-28799CRITICALCVSS 10.0EG 10.0⚠ KEV2021-05-13
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 ve…
- CVE-2024-11680CRITICALCVSS 9.8EG 9.8⚠ KEV2024-11-26
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of th…
- CVE-2024-38856CRITICALCVSS 9.8EG 9.8⚠ KEV2024-08-05
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of sc…
- CVE-2023-22518CRITICALCVSS 9.8EG 9.8⚠ KEV2023-10-31
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrat…
- CVE-2023-38035CRITICALCVSS 9.8EG 9.8⚠ KEV2023-08-21
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache …
- CVE-2022-46169CRITICALCVSS 9.8EG 9.8⚠ KEV2022-12-05
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbit…
- CVE-2022-26501CRITICALCVSS 9.8EG 9.8⚠ KEV2022-03-17
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
- CVE-2022-26143CRITICALCVSS 9.8EG 9.8⚠ KEV2022-03-10
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive …
- CVE-2020-3952CRITICALCVSS 9.8EG 9.8⚠ KEV2020-04-10
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
- CVE-2019-7192CRITICALCVSS 9.8EG 9.8⚠ KEV2019-12-05
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
- CVE-2020-2506CRITICALCVSS 7.3EG 9.8⚠ KEV2021-02-03
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive i…
- CVE-2026-71362CRITICALCVSS 9.1EG 9.1⚠ KEV2026-08-11
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does…
- CVE-2023-20269CRITICALCVSS 9.1EG 9.1⚠ KEV2023-09-06
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an at…
- CVE-2018-13382CRITICALCVSS 9.1EG 9.1⚠ KEV2019-06-04
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker…
- CVE-2026-42016CRITICALCVSS 8.8EG 9.0⚠ KEV2026-07-27
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
- CVE-2021-21551CRITICALCVSS 8.8EG 9.0⚠ KEV2021-05-04
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
- CVE-2021-3493CRITICALCVSS 8.8EG 9.0⚠ KEV2021-04-17
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along…
- CVE-2025-21479CRITICALCVSS 8.6EG 9.0⚠ KEV2025-06-03
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
- CVE-2025-21480CRITICALCVSS 8.6EG 9.0⚠ KEV2025-06-03
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
- CVE-2021-3560CRITICALCVSS 7.8EG 9.0⚠ KEV2022-02-16
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, creat…
- CVE-2021-42292CRITICALCVSS 7.8EG 9.0⚠ KEV2021-11-10
Microsoft Excel Security Feature Bypass Vulnerability
- CVE-2021-30713CRITICALCVSS 7.8EG 9.0⚠ KEV2021-09-08
A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exp…
- CVE-2024-21287CRITICALCVSS 7.5EG 9.0⚠ KEV2024-11-18
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthentic…
- CVE-2021-40655CRITICALCVSS 7.5EG 9.0⚠ KEV2021-09-24
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
- CVE-2023-21715CRITICALCVSS 7.3EG 9.0⚠ KEV2023-02-14
Microsoft Publisher Security Feature Bypass Vulnerability
- CVE-2021-30533CRITICALCVSS 6.5EG 9.0⚠ KEV2021-06-07
Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted iframe.
- CVE-2021-25369CRITICALCVSS 6.2EG 9.0⚠ KEV2021-03-26
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
- CVE-2025-24200CRITICALCVSS 6.1EG 9.0⚠ KEV2025-02-10
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restri…
- CVE-2025-55177CRITICALCVSS 5.4EG 9.0⚠ KEV2025-08-29
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing…
- CVE-2022-44698CRITICALCVSS 5.4EG 9.0⚠ KEV2022-12-13
Windows SmartScreen Security Feature Bypass Vulnerability
- CVE-2022-41091CRITICALCVSS 5.4EG 9.0⚠ KEV2022-11-09
Windows Mark of the Web Security Feature Bypass Vulnerability
- CVE-2023-24880CRITICALCVSS 4.4EG 9.0⚠ KEV2023-03-14
Windows SmartScreen Security Feature Bypass Vulnerability
- CVE-2021-25337CRITICALCVSS 4.4EG 9.0⚠ KEV2021-03-04
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.
- CVE-2022-23134CRITICALCVSS 3.7EG 9.0⚠ KEV2022-01-13
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Fro…
- CVE-2026-101000CRITICALCVSS 10.0EG 10.02026-09-28
A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes…
- CVE-2026-75745CRITICALCVSS 10.0EG 10.02026-09-22
Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary …
- CVE-2026-75723CRITICALCVSS 10.0EG 10.02026-09-22
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. …
- CVE-2026-69555CRITICALCVSS 10.0EG 10.02026-08-20
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-71398CRITICALCVSS 10.0EG 10.02026-08-11
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. …
- CVE-2026-27302CRITICALCVSS 10.0EG 10.02026-08-11
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. …
- CVE-2026-48286CRITICALCVSS 10.0EG 10.02026-06-30
Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does n…
- CVE-2026-27604CRITICALCVSS 10.0EG 10.02026-06-23
FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypass in the API role handling allows unauthenticated access to privileged `/api/system/*` end…
- CVE-2026-48772CRITICALCVSS 10.0EG 10.02026-06-19
ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY UNKNOWN <addr> <addr> <port> <port>\r\n` PP1 frame as a well-formed PROXY protocol header. …
- CVE-2026-48303CRITICALCVSS 10.0EG 10.02026-06-09
Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does n…
- CVE-2026-44330CRITICALCVSS 10.0EG 10.02026-05-27
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-pfdmanagement route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can…
- CVE-2026-46595CRITICALCVSS 10.0EG 10.02026-05-22
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
- CVE-2026-42160CRITICALCVSS 10.0EG 10.02026-05-08
Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 to before version 7.3.2, there is insufficient authorization in the dataspace-portal backend regardin…
- CVE-2025-26853CRITICALCVSS 10.0EG 10.02025-03-20
DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →