CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
5,070 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 3 of 102
- CVE-2024-21010CRITICALCVSS 9.9EG 9.92024-04-16
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows low…
- CVE-2024-25108CRITICALCVSS 9.9EG 9.92024-02-12
Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative a…
- CVE-2023-20048CRITICALCVSS 9.9EG 9.92023-11-01
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) devi…
- CVE-2023-33190CRITICALCVSS 9.9EG 9.92023-06-29
Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior to 4.2.1-rc4 an improper configuration of role based access control (RBAC) permissions resulted in an attacker being a…
- CVE-2023-35166CRITICALCVSS 9.9EG 9.92023-06-20
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension. This has been patched…
- CVE-2023-32069CRITICALCVSS 9.9EG 9.92023-05-09
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-2 and prior to versions 14.10.4 and 15.0-rc-1, it's possible for a user to execute anything with the right of the author of the XWiki.ClassSheet document. This ha…
- CVE-2022-34827CRITICALCVSS 9.9EG 9.92022-11-18
Carel Boss Mini 1.5.0 has Improper Access Control.
- CVE-2022-2661CRITICALCVSS 9.9EG 9.92022-08-16
Sequi PortBloque S has an improper authorization vulnerability, which may allow a low-privileged user to perform administrative functions using specifically crafted requests.
- CVE-2022-29176CRITICALCVSS 9.9EG 9.92022-05-05
Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any RubyGems.org user to remove and replace certain gems even if that user was not authorized to d…
- CVE-2022-20777CRITICALCVSS 9.9EG 9.92022-05-04
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data…
- CVE-2021-23140CRITICALCVSS 9.9EG 9.92021-06-11
Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre Operator. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR…
- CVE-2019-11684CRITICALCVSS 9.9EG 9.92021-02-26
Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, stored in the underlying Microsoft Windows operating system. T…
- CVE-2021-26753CRITICALCVSS 9.9EG 9.92021-02-12
NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is instal…
- CVE-2020-35951CRITICALCVSS 9.9EG 9.92021-01-01
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall w…
- CVE-2020-35948CRITICALCVSS 9.9EG 9.92021-01-01
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote co…
- CVE-2020-3374CRITICALCVSS 9.9EG 9.92020-07-31
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization, enabling them to access sensitive information, modify the system configuration, o…
- CVE-2019-10458CRITICALCVSS 9.9EG 9.92019-10-16
Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to execute Script Security protected scripts to execute arbitrary code.
- CVE-2019-10418CRITICALCVSS 9.9EG 9.92019-09-25
Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.
- CVE-2019-10417CRITICALCVSS 9.9EG 9.92019-09-25
Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.
- CVE-2021-32829CRITICALCVSS 9.6EG 9.92021-08-17
ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of compute, storage, and networking all by APIs. Affected versions of ZStack REST API are vulnerable to post-authentication…
- CVE-2024-1738CRITICALCVSS 7.5EG 9.92024-04-16
An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.get route in the evaluations API endpoint. This vulnerability allows unauthorized users to retrieve the results of any …
- CVE-2026-94205CRITICALCVSS 9.8EG 9.82026-10-06
Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the event rather than the pull request author. For `pull_request` activity triggered by a maintainer during ordinary triage, such as addi…
- CVE-2026-106511CRITICALCVSS 9.8EG 9.82026-10-06
MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with…
- CVE-2026-100277CRITICALCVSS 9.8EG 9.82026-09-30
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
- CVE-2026-100273CRITICALCVSS 9.8EG 9.82026-09-30
In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
- CVE-2026-93643CRITICALCVSS 9.8EG 9.82026-09-25
When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zim…
- CVE-2026-88617CRITICALCVSS 9.8EG 9.82026-09-15
SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges.
- CVE-2026-82431CRITICALCVSS 9.8EG 9.82026-09-14
Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered. An operator who restricted cluster access by group alone, leaving `nimbus.user…
- CVE-2026-73370CRITICALCVSS 9.8EG 9.82026-09-14
Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks performed by Reconciliation service's pull and push, being incomplete, could accept calls by administrator not provided with adequate enti…
- CVE-2026-73579CRITICALCVSS 9.8EG 9.82026-09-14
Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important component of such transfo…
- CVE-2026-73668CRITICALCVSS 9.8EG 9.82026-09-14
Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another R…
- CVE-2026-77181CRITICALCVSS 9.8EG 9.82026-09-14
Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the related operation, while ClientApp's create entitlement is checked both for create and update operat…
- CVE-2026-85025CRITICALCVSS 9.8EG 9.82026-09-10
IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow se…
- CVE-2026-85978CRITICALCVSS 9.8EG 9.82026-09-09
An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to …
- CVE-2026-87544CRITICALCVSS 9.8EG 9.82026-09-09
Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-47892CRITICALCVSS 9.8EG 9.82026-08-27
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.…
- CVE-2026-80203CRITICALCVSS 9.8EG 9.82026-08-26
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting ac…
- CVE-2026-79152CRITICALCVSS 9.8EG 9.82026-08-25
Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Low)
- CVE-2026-56710CRITICALCVSS 9.8EG 9.82026-08-25
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accoun…
- CVE-2026-19685CRITICALCVSS 9.8EG 9.82026-08-24
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enter…
- CVE-2026-59318CRITICALCVSS 9.8EG 9.82026-08-21
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current r…
- CVE-2026-19598CRITICALCVSS 9.8EG 9.82026-08-15
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funne…
- CVE-2026-13738CRITICALCVSS 9.8EG 9.82026-08-11
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webse…
- CVE-2026-13737CRITICALCVSS 9.8EG 9.82026-08-11
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Cente…
- CVE-2026-52466CRITICALCVSS 9.8EG 9.82026-08-05
Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that co…
- CVE-2026-48333CRITICALCVSS 9.8EG 9.82026-08-03
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not r…
- CVE-2026-67341CRITICALCVSS 9.8EG 9.82026-08-01
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statem…
- CVE-2026-14537CRITICALCVSS 9.8EG 9.82026-07-31
Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation …
- CVE-2025-10656CRITICALCVSS 9.8EG 9.82026-07-29
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes it possible for unau…
- CVE-2026-15704CRITICALCVSS 9.8EG 9.82026-07-24
In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The sh…
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →