CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
5,070 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 10 of 102
- CVE-2026-81649CRITICALCVSS 9.1EG 9.12026-10-11
The Fundiin cho WooCommerce WordPress plugin through 3.4.0 does not have proper authorisation on several of its REST API routes, relying instead on a credential that is identical on every installation, allowing unauthenticated attackers to…
- CVE-2026-106195CRITICALCVSS 9.1EG 9.12026-10-06
Incorrect authorization in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)
- CVE-2026-75728CRITICALCVSS 9.1EG 9.12026-09-22
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. …
- CVE-2026-88044CRITICALCVSS 9.1EG 9.12026-09-10
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constru…
- CVE-2026-88008CRITICALCVSS 9.1EG 9.12026-09-10
Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend.…
- CVE-2026-88007CRITICALCVSS 9.1EG 9.12026-09-10
Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport in…
- CVE-2026-85597CRITICALCVSS 9.1EG 9.12026-09-04
Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host r…
- CVE-2026-73475CRITICALCVSS 9.1EG 9.12026-09-02
Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
- CVE-2026-18918CRITICALCVSS 9.1EG 9.12026-08-28
In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server. In those cases, application that based their authz filters upon Lyo-provided `AbstractAdapterCrede…
- CVE-2026-16644CRITICALCVSS 9.1EG 9.12026-08-25
Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.
- CVE-2026-68525CRITICALCVSS 9.1EG 9.12026-08-25
Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11…
- CVE-2026-65182CRITICALCVSS 9.1EG 9.12026-08-25
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue a…
- CVE-2026-68980CRITICALCVSS 9.1EG 9.12026-08-03
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parame…
- CVE-2026-58443CRITICALCVSS 9.1EG 9.12026-07-21
Public-only repository tokens can update private PR head branches
- CVE-2026-44231CRITICALCVSS 9.1EG 9.12026-07-20
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (…
- CVE-2026-53512CRITICALCVSS 9.1EG 9.12026-07-07
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession of the bound refreshTo…
- CVE-2026-48807CRITICALCVSS 9.1EG 9.12026-06-30
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringa…
- CVE-2026-48806CRITICALCVSS 9.1EG 9.12026-06-30
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling Sandbox…
- CVE-2026-32967CRITICALCVSS 9.1EG 9.12026-06-17
Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
- CVE-2026-48776CRITICALCVSS 9.1EG 9.12026-06-17
LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior have unsafe URL path construction through unsanitized caller-supplied …
- CVE-2026-45550CRITICALCVSS 9.1EG 9.12026-06-10
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() — which va…
- CVE-2026-35482CRITICALCVSS 9.1EG 9.12026-06-02
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox escape vulnerability in the alf.io extension script engine allows an authenticated administrat…
- CVE-2026-48501CRITICALCVSS 9.1EG 9.12026-05-29
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh release verify-asset co…
- CVE-2026-22872CRITICALCVSS 9.1EG 9.12026-05-28
Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantResource RawItems processing logic forcibly sets the namespace, this is ineffective for clu…
- CVE-2026-42032CRITICALCVSS 9.1EG 9.12026-05-13
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to bypass authorization in order to gain access to private …
- CVE-2026-42889CRITICALCVSS 9.1EG 9.12026-05-12
Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSocket endpoints. When authentication is configured, WebSocket connections without a token …
- CVE-2026-41248CRITICALCVSS 9.1EG 9.12026-04-24
Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and re…
- CVE-2026-5574CRITICALCVSS 9.1EG 9.12026-04-05
A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBrowseClean. The manipulation of the argument dir/path leads to missing authorization. The a…
- CVE-2026-34953CRITICALCVSS 9.1EG 9.12026-04-03
PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal store, which is empty by default. Any HTTP request to the MCP server with an arbitrary Bea…
- CVE-2026-34532CRITICALCVSS 9.1EG 9.12026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.co…
- CVE-2026-30965CRITICALCVSS 9.1EG 9.12026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerability in Parse Server's query handling allows an authenticated or unauthenticated attacker…
- CVE-2026-27607CRITICALCVSS 9.1EG 9.12026-02-25
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy conditions in presigned POST uploads (PostObject), allowing attackers to bypass content-length-…
- CVE-2026-25811CRITICALCVSS 9.1EG 9.12026-02-09
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derives the tenant identifier directly from the email domain provided by the user, without validating domain ownership or reg…
- CVE-2026-22806CRITICALCVSS 9.1EG 9.12026-01-29
vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to versions 4.6.0, 4.5.4, 4.4.2, and 4.3.10, when an access key is created with a limited scope, the scope can be byp…
- CVE-2025-66719CRITICALCVSS 9.1EG 9.12026-01-23
An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/sbi/processor/access_token.go bypasses all scope validation when the attacker uses a craft…
- CVE-2026-22909CRITICALCVSS 9.1EG 9.12026-01-15
Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations.
- CVE-2025-61781CRITICALCVSS 9.1EG 9.12026-01-05
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "WorkspacePopoverDeletionMutation" allows users to delete workspace-related objects such as d…
- CVE-2025-59683CRITICALCVSS 9.1EG 9.12025-12-25
Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and e…
- CVE-2025-21450CRITICALCVSS 9.1EG 9.12025-07-08
Cryptographic issue occurs due to use of insecure connection method while downloading.
- CVE-2025-48935CRITICALCVSS 9.1EG 9.12025-06-04
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is possible to bypass Deno's permission read/write db permission check by using `ATTACH DATABASE` statement. Version 2.2.5…
- CVE-2025-48373CRITICALCVSS 9.1EG 9.12025-05-22
Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to redirect users to different panels based on their role. Prior to version 1.0.1, this implementation poses a serious sec…
- CVE-2025-43564CRITICALCVSS 9.1EG 9.12025-05-13
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged attacker could leverage this vulnerability to access or mo…
- CVE-2025-43561CRITICALCVSS 9.1EG 9.12025-05-13
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage t…
- CVE-2024-38392CRITICALCVSS 9.1EG 9.12025-04-02
Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the application to run untrusted code.
- CVE-2025-29927CRITICALCVSS 9.1EG 9.12025-03-21
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the…
- CVE-2025-24434CRITICALCVSS 9.1EG 9.12025-02-11
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to …
- CVE-2024-54530CRITICALCVSS 9.1EG 9.12025-01-27
The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, visionOS 2.2, watchOS 11.2. Password autofill may fill in passwords after failing authentication.
- CVE-2024-54512CRITICALCVSS 9.1EG 9.12025-01-27
The issue was addressed by removing the relevant flags. This issue is fixed in iOS 18.2 and iPadOS 18.2, watchOS 11.2. A system binary could be used to fingerprint a user's Apple Account.
- CVE-2024-53553CRITICALCVSS 9.1EG 9.12025-01-16
An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web requests.
- CVE-2024-13281CRITICALCVSS 9.1EG 9.12025-01-09
Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus: from 0.0.0 before 9.3.2.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →