CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
5,070 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 11 of 102
- CVE-2024-13278CRITICALCVSS 9.1EG 9.12025-01-09
Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.
- CVE-2024-13277CRITICALCVSS 9.1EG 9.12025-01-09
Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: from 7.X-1.0 before 7.X-1.1.
- CVE-2024-13253CRITICALCVSS 9.1EG 9.12025-01-09
Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue affects Advanced PWA inc Push Notifications: from 0.0.0 before 1.5.0.
- CVE-2024-54662CRITICALCVSS 9.1EG 9.12024-12-17
Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving socksmethod.
- CVE-2024-52732CRITICALCVSS 9.1EG 9.12024-12-02
Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value of the zeqp system being reused.
- CVE-2024-44217CRITICALCVSS 9.1EG 9.12024-10-28
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 18 and iPadOS 18. Password autofill may fill in passwords after failing authentication.
- CVE-2024-48772CRITICALCVSS 9.1EG 9.12024-10-11
An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firmware update process.
- CVE-2024-48787CRITICALCVSS 9.1EG 9.12024-10-11
An issue in Revic Optics Revic Ops (us.revic.revicops) 1.12.5 allows a remote attacker to obtain sensitive information via the firmware update process.
- CVE-2024-48786CRITICALCVSS 9.1EG 9.12024-10-11
An issue in SWITCHBOT INC SwitchBot (com.theswitchbot.switchbot) 5.0.4 allows a remote attacker to obtain sensitive information via the firmware update process.
- CVE-2024-48778CRITICALCVSS 9.1EG 9.12024-10-11
An issue in GIANT MANUFACTURING CO., LTD RideLink (tw.giant.ridelink) 2.0.7 allows a remote attacker to obtain sensitive information via the firmware update process.
- CVE-2024-48769CRITICALCVSS 9.1EG 9.12024-10-11
An issue in BURG-WCHTER KG de.burgwachter.keyapp.app 4.5.0 allows a remote attacker to obtain sensitve information via the firmware update process.
- CVE-2024-45160CRITICALCVSS 9.1EG 9.12024-10-09
Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret).
- CVE-2024-6593CRITICALCVSS 9.1EG 9.12024-09-25
Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained network…
- CVE-2024-6592CRITICALCVSS 9.1EG 9.12024-09-25
An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker wit…
- CVE-2024-42773CRITICALCVSS 9.1EG 9.12024-08-22
An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel room entries in the administrator section.
- CVE-2024-35187CRITICALCVSS 9.1EG 9.12024-05-16
Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execution as the stalwart-mail user (including web interface admins) can gain complete root access to the system. Usually, sy…
- CVE-2024-1741CRITICALCVSS 9.1EG 9.12024-04-10
lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates using an old authorization token. Despite being removed from an organization, these membe…
- CVE-2024-1740CRITICALCVSS 9.1EG 9.12024-04-10
In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, create, modify, and delete logs by re-using an old authorization token. The lunary web application communicates with the se…
- CVE-2023-52538CRITICALCVSS 9.1EG 9.12024-04-08
Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2024-25170CRITICALCVSS 9.1EG 9.12024-02-28
An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.
- CVE-2023-33468CRITICALCVSS 9.1EG 9.12023-08-09
KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, by…
- CVE-2023-34218CRITICALCVSS 9.1EG 9.12023-05-31
In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
- CVE-2023-23304CRITICALCVSS 9.1EG 9.12023-05-23
The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybox.SensorHistory` module without permission. A malicious application could call any functions from …
- CVE-2023-27578CRITICALCVSS 9.1EG 9.12023-03-20
Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an insufficient permission check. Unsupported versions are likely affected as far back as th…
- CVE-2023-23947CRITICALCVSS 9.1EG 9.12023-02-16
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23 2.5.11, and 2.6.2 are vulnerable to an improper authorization bug which allows users who ha…
- CVE-2023-22610CRITICALCVSS 9.1EG 9.12023-01-31
A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server when specific messages are sent to the server over the database server TCP port.
- CVE-2022-45891CRITICALCVSS 9.1EG 9.12022-12-25
Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList).
- CVE-2022-41923CRITICALCVSS 9.1EG 9.12022-11-23
Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to one endpoint (i.e. the targeted endpoint) using the authorization requirements of a different endpoint (i.e. the donor…
- CVE-2022-27583CRITICALCVSS 9.1EG 9.12022-10-31
A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affected firmware version to potentially impact the availability of the FlexiCompact.
- CVE-2022-39322CRITICALCVSS 9.1EG 9.12022-10-25
@keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, users who expected their `multiselect` fields to use the field-level access control - if co…
- CVE-2022-35924CRITICALCVSS 9.1EG 9.12022-08-02
NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in versions before `4.10.3` or `3.29.10` are affected. If an attacker could forge a request …
- CVE-2022-36129CRITICALCVSS 9.1EG 9.12022-07-26
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing …
- CVE-2022-0670CRITICALCVSS 9.1EG 9.12022-07-25
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows …
- CVE-2021-46419CRITICALCVSS 9.1EG 9.12022-04-07
An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.
- CVE-2022-26629CRITICALCVSS 9.1EG 9.12022-03-24
An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.
- CVE-2022-0860CRITICALCVSS 9.1EG 9.12022-03-11
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
- CVE-2022-0482CRITICALCVSS 9.1EG 9.12022-03-09
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
- CVE-2022-25402CRITICALCVSS 9.1EG 9.12022-02-24
An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.
- CVE-2021-28506CRITICALCVSS 9.1EG 9.12022-01-14
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
- CVE-2021-28501CRITICALCVSS 9.1EG 9.12022-01-14
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
- CVE-2021-28500CRITICALCVSS 9.1EG 9.12022-01-14
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
- CVE-2021-41244CRITICALCVSS 9.1EG 9.12021-11-15
Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enabled and there is more than one organization in the Grafana instance admins are able to acces…
- CVE-2021-20599CRITICALCVSS 9.1EG 9.12021-10-14
Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior and MELSEC iQ-R series SIL2 Process CPU R08/1…
- CVE-2021-1577CRITICALCVSS 9.1EG 9.12021-08-25
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an unauthenticated, remote attacker to read or write arbi…
- CVE-2021-30925CRITICALCVSS 9.1EG 9.12021-08-24
The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 and iPadOS 15. A malicious application may be able to bypass Privacy preferences.
- CVE-2021-30856CRITICALCVSS 9.1EG 9.12021-08-24
This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions. This issue is fixed in macOS Big Sur 11.3. A malicious unsandboxed app on a system with Remote Login enabled may bypas…
- CVE-2021-26040CRITICALCVSS 9.1EG 9.12021-08-24
An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.
- CVE-2021-20538CRITICALCVSS 9.1EG 9.12021-05-10
IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have access to due to incorrect authorization mechanisms. IBM X-Force ID: 198919.
- CVE-2021-29943CRITICALCVSS 9.1EG 9.12021-04-13
When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorre…
- CVE-2020-29020CRITICALCVSS 9.1EG 9.12021-03-05
Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All versions prior to 9.4.6…
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →