CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
5,070 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 12 of 102
- CVE-2020-28050CRITICALCVSS 9.1EG 9.12021-03-05
Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server.
- CVE-2020-35547CRITICALCVSS 9.1EG 9.12021-01-29
A library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 could allow an unauthenticated attacker to gain access (view and modify) to user data.
- CVE-2020-25251CRITICALCVSS 9.1EG 9.12020-09-11
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Client-side authentication is used for critical functions such as adding users or r…
- CVE-2020-10117CRITICALCVSS 9.1EG 9.12020-03-17
cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542).
- CVE-2013-1350CRITICALCVSS 9.1EG 9.12020-01-30
Verax NMS prior to 2.1.0 has multiple security bypass vulnerabilities
- CVE-2010-2548CRITICALCVSS 9.1EG 9.12019-10-31
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
- CVE-2019-1912CRITICALCVSS 9.1EG 9.12019-08-07
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files. The vulnerability is due to incomplete authorization checks in the…
- CVE-2018-7245CRITICALCVSS 9.1EG 9.12018-04-18
An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote …
- CVE-2026-6290CRITICALCVSS 8.0EG 9.12026-04-15
Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token. This allows an authenticated GUI user with access in one org, to use the query() plugin,…
- CVE-2024-57432CRITICALCVSS 7.5EG 9.12025-01-31
macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it i…
- CVE-2021-41975CRITICALCVSS 7.5EG 9.12021-10-08
TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the system without logging in.
- CVE-2021-3563CRITICALCVSS 7.4EG 9.12022-08-26
A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerabili…
- CVE-2026-13238CRITICALCVSS 4.8EG 9.12026-07-10
Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2.
- CVE-2026-13237CRITICALCVSS 4.8EG 9.12026-07-10
Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.
- CVE-2024-44136CRITICALCVSS 4.6EG 9.12025-01-15
This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to a device may be able to disable Stolen Device Protection.
- CVE-2024-23255CRITICALCVSS 2.4EG 9.12024-03-08
An authentication issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Photos in the Hidden Photos Album may be viewed without authentication.
- CVE-2026-55176CRITICALCVSS 9.0EG 9.02026-09-30
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the glob…
- CVE-2026-82378CRITICALCVSS 9.0EG 9.02026-09-28
Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer to bind that token to an arbitrar…
- CVE-2026-100721CRITICALCVSS 9.0EG 9.02026-09-27
vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat…
- CVE-2026-48327CRITICALCVSS 9.0EG 9.02026-07-14
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
- CVE-2026-44221CRITICALCVSS 9.0EG 9.02026-05-12
ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database on the same server. Two di…
- CVE-2026-42571CRITICALCVSS 9.0EG 9.02026-05-09
Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.24.0 to before 7.24.2, there is a a privilege escalation vulnerability affecting Pelican's …
- CVE-2025-55205CRITICALCVSS 9.0EG 9.02025-08-18
Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsule v0.10.3 and earlier allows authenticated tenant users to inject arbitrary labels into system namespaces (kube-system…
- CVE-2025-30171CRITICALCVSS 9.0EG 9.02025-05-22
System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; M…
- CVE-2024-38002CRITICALCVSS 9.0EG 9.02024-10-22
The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions befo…
- CVE-2023-46241CRITICALCVSS 9.0EG 9.02024-02-21
`discourse-microsoft-auth` is a plugin that enables authentication via Microsoft. On sites with the `discourse-microsoft-auth` plugin enabled, an attack can potentially take control of a victim's Discourse account. Sites that have configur…
- CVE-2017-9453CRITICALCVSS 9.0EG 9.02023-09-05
BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.
- CVE-2023-31997CRITICALCVSS 9.0EG 9.02023-07-01
UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2) hosting the UniFi Network application…
- CVE-2023-22482CRITICALCVSS 9.0EG 9.02023-01-26
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and prior to 2.3.13, 2.4.19, 2.5.6, and 2.6.0-rc-3 are vulnerable to an improper authorization bug causing the API to accep…
- CVE-2022-26857CRITICALCVSS 9.0EG 9.02022-05-26
Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass blocked functionalities and…
- CVE-2018-1245CRITICALCVSS 9.0EG 9.02018-07-13
RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect component (ACM). A remote authenticated malicious user with non-admin privileges could poten…
- CVE-2022-0824CRITICALCVSS 8.8EG 9.02022-03-02
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.
- CVE-2020-36289CRITICALCVSS 5.3EG 9.02021-05-12
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint. The affected versions are bef…
- CVE-2026-55563HIGHCVSS 8.9EG 8.92026-09-21
Feast is the open source feature store for AI and machine learning. Prior to 0.65.0, .github/workflows/pr_integration_tests.yml uses pull_request_target with the synchronize event and preserves ok-to-test, approved, or lgtm labels across n…
- CVE-2026-80515HIGHCVSS 8.9EG 8.92026-09-03
In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat…
- CVE-2026-58424HIGHCVSS 8.9EG 8.92026-07-03
Permanent Fork PR Workflow Approval Gate Bypass
- CVE-2026-43947HIGHCVSS 8.9EG 8.92026-05-26
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Code Execution vulnerability when `secureEnabled` is set to `true`. The `POST /api/runscript` endpoint checks authorizati…
- CVE-2026-43945HIGHCVSS 8.9EG 8.92026-05-26
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform…
- CVE-2021-3577HIGHCVSS 8.8EG 8.92021-11-12
An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device.
- CVE-2026-108746HIGHCVSS 8.8EG 8.82026-10-11
Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role.HasPermissionForResources that ignores stored ReadOnly or None privilege levels for resources listed in a role. Authenticated non-root users can upsert an…
- CVE-2026-108550HIGHCVSS 8.8EG 8.82026-10-10
SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers to take over other accounts by abusing the merge flow. Attackers can call the me…
- CVE-2026-106371HIGHCVSS 8.8EG 8.82026-10-06
Incorrect authorization in Transactions Platform in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-106350HIGHCVSS 8.8EG 8.82026-10-06
Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-106249HIGHCVSS 8.8EG 8.82026-10-06
Incorrect authorization in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-106309HIGHCVSS 8.8EG 8.82026-10-06
Incorrect authorization in Selection in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-106352HIGHCVSS 8.8EG 8.82026-10-06
Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-106212HIGHCVSS 8.8EG 8.82026-10-06
Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-106314HIGHCVSS 8.8EG 8.82026-10-06
Incorrect authorization in Bluetooth in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-105797HIGHCVSS 8.8EG 8.82026-10-06
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. In versions 0.261.003 and 0.261.027, an authorization ordering flaw in POST /api/user/plugins allows an authenticated…
- CVE-2026-82828HIGHCVSS 8.8EG 8.82026-10-01
Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unprivileged user to perform administrator-level operations. This issue affects Hitachi Coding Software Suite: through 3.3.0.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →