CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
5,070 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 13 of 102
- CVE-2026-101880HIGHCVSS 8.8EG 8.82026-09-30
OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connect…
- CVE-2026-103105HIGHCVSS 8.8EG 8.82026-09-30
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as a…
- CVE-2026-61519HIGHCVSS 8.8EG 8.82026-09-29
Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to invite additional attacker-controlled accounts with elevated privileges by exploiting a flawed authoriz…
- CVE-2026-101062HIGHCVSS 8.8EG 8.82026-09-27
Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register.…
- CVE-2026-100623HIGHCVSS 8.8EG 8.82026-09-26
Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's row-level security policies "Allow org admin to insert" and "Allow org admin to update" only verify that the caller has…
- CVE-2026-100552HIGHCVSS 8.8EG 8.82026-09-26
OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, …
- CVE-2026-84399HIGHCVSS 8.8EG 8.82026-09-24
The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it,…
- CVE-2026-94609HIGHCVSS 8.8EG 8.82026-09-24
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing ro…
- CVE-2026-92801HIGHCVSS 8.8EG 8.82026-09-16
cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by triggering card actions in admitted chats, bypassing the per…
- CVE-2026-92796HIGHCVSS 8.8EG 8.82026-09-16
Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries. Attackers can append additional SELECT statements aft…
- CVE-2026-92788HIGHCVSS 8.8EG 8.82026-09-16
Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace. Authenticated attackers can enumerate predictable table identifiers and execute SQL statements against other…
- CVE-2026-16140HIGHCVSS 8.8EG 8.82026-09-15
OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption key…
- CVE-2026-88616HIGHCVSS 8.8EG 8.82026-09-15
An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /work…
- CVE-2026-72524HIGHCVSS 8.8EG 8.82026-09-14
Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to. This issue affects Apache Doris: from 3.1.0 through 3.1.*, from 4.0.0 th…
- CVE-2023-50461HIGHCVSS 8.8EG 8.82026-09-14
An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as…
- CVE-2026-75624HIGHCVSS 8.8EG 8.82026-09-10
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.
- CVE-2026-88862HIGHCVSS 8.8EG 8.82026-09-10
Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware.ts resolves the attacker-supplied numer…
- CVE-2026-87570HIGHCVSS 8.8EG 8.82026-09-09
Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted file. (Chromium sec…
- CVE-2026-81996HIGHCVSS 8.8EG 8.82026-09-08
Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access. Exploitation of this issue does not requi…
- CVE-2026-28666HIGHCVSS 8.8EG 8.82026-09-08
In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering check bypass. This could lead to remote escalation of privilege with no additional execution privileges …
- CVE-2026-73702HIGHCVSS 8.8EG 8.82026-09-01
A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, le…
- CVE-2026-58566HIGHCVSS 8.8EG 8.82026-09-01
Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
- CVE-2026-76111HIGHCVSS 8.8EG 8.82026-09-01
Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation.
- CVE-2026-55485HIGHCVSS 8.8EG 8.82026-08-28
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers b…
- CVE-2026-80202HIGHCVSS 8.8EG 8.82026-08-25
Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with ROLE_TEAMLEAD (or a role holding ed…
- CVE-2026-49050HIGHCVSS 8.8EG 8.82026-08-25
General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
- CVE-2026-76836HIGHCVSS 8.8EG 8.82026-08-24
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated with GROUP_GENERAL, and PUT /ap…
- CVE-2026-77234HIGHCVSS 8.8EG 8.82026-08-21
Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later.
- CVE-2026-68561HIGHCVSS 8.8EG 8.82026-08-19
Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permissions/boards.js called canUpdateBoardSort in server/lib/utils.js, which authorized any board member whenever fieldNames …
- CVE-2026-55643HIGHCVSS 8.8EG 8.82026-08-19
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserH…
- CVE-2026-44252HIGHCVSS 8.8EG 8.82026-08-19
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-privilege read-only API user with manager:read permission to retrieve the cluster key from th…
- CVE-2026-70408HIGHCVSS 8.8EG 8.82026-08-19
An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.
- CVE-2026-61574HIGHCVSS 8.8EG 8.82026-08-18
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and th…
- CVE-2026-72831HIGHCVSS 8.8EG 8.82026-08-14
The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex directory permission and does not apply th…
- CVE-2026-73841HIGHCVSS 8.8EG 8.82026-08-13
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 and 1.2.3, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view…
- CVE-2026-62872HIGHCVSS 8.8EG 8.82026-08-11
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
- CVE-2026-71387HIGHCVSS 8.8EG 8.82026-08-11
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable com…
- CVE-2026-69118HIGHCVSS 8.8EG 8.82026-08-10
Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create malicious incident templates with Blade directi…
- CVE-2026-70472HIGHCVSS 8.8EG 8.82026-08-04
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without ch…
- CVE-2026-7868HIGHCVSS 8.8EG 8.82026-07-28
IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrator privileges.
- CVE-2026-14167HIGHCVSS 8.8EG 8.82026-07-28
A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.
- CVE-2026-17568HIGHCVSS 8.8EG 8.82026-07-27
Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a …
- CVE-2026-73305HIGHCVSS 8.8EG 8.82026-07-24
Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in packages/server/src/api/controllers/public/globalRoleValida…
- CVE-2026-65602HIGHCVSS 8.8EG 8.82026-07-22
Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allowlist was only enforced for HTTP serversTransport references). A lo…
- CVE-2026-65601HIGHCVSS 8.8EG 8.82026-07-22
Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace…
- CVE-2026-65015HIGHCVSS 8.8EG 8.82026-07-22
n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that …
- CVE-2026-59851HIGHCVSS 8.8EG 8.82026-07-21
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in …
- CVE-2025-71390HIGHCVSS 8.8EG 8.82026-07-18
SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions. An authenticated user can invoke http::<fn>(<url>) w…
- CVE-2026-62228HIGHCVSS 8.8EG 8.82026-07-17
OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attacker…
- CVE-2026-62223HIGHCVSS 8.8EG 8.82026-07-17
OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execute actions beyond their intended authorization. Attackers can exploit misconfigured input p…
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →