CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
5,070 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 5 of 102
- CVE-2024-6695CRITICALCVSS 9.8EG 9.82024-07-31
it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.
- CVE-2024-36536CRITICALCVSS 9.8EG 9.82024-07-24
Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
- CVE-2023-38389CRITICALCVSS 9.8EG 9.82024-06-21
Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JupiterX Core: from n/a through 3.3.8.
- CVE-2024-36265CRITICALCVSS 9.8EG 9.82024-06-12
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. An attacker can bypass authentication by sending specially crafted REST r…
- CVE-2024-4146CRITICALCVSS 9.8EG 9.82024-06-08
In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to access and manipulate projects within an organization they should not have access to. Specifically, the vulnerability is…
- CVE-2024-31682CRITICALCVSS 9.8EG 9.82024-06-03
Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint authentication due to the use of a deprecated API.
- CVE-2024-35353CRITICALCVSS 9.8EG 9.82024-05-30
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Users.php?f=save. Manipulating the argument id can result in improper authorization.
- CVE-2024-28394CRITICALCVSS 9.8EG 9.82024-03-19
An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & Export module.
- CVE-2023-6036CRITICALCVSS 9.8EG 9.82024-02-12
The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authen…
- CVE-2024-23653CRITICALCVSS 9.8EG 9.82024-01-31
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based o…
- CVE-2023-52077CRITICALCVSS 9.8EG 9.82023-12-27
Nexkey is a lightweight fork of Misskey v12 optimized for small to medium size servers. Prior to 12.23Q4.5, Nexkey allows external apps using tokens issued by administrators and moderators to call admin APIs. This allows malicious third-p…
- CVE-2023-24052CRITICALCVSS 9.8EG 9.82023-12-04
An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as it does not prompt for the current password.
- CVE-2023-24051CRITICALCVSS 9.8EG 9.82023-12-04
A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style attacks.
- CVE-2023-34051CRITICALCVSS 9.8EG 9.82023-10-20
VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
- CVE-2023-43119CRITICALCVSS 9.8EG 9.82023-10-16
An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain escalated privileges using crafted telnet commands via Redis server.
- CVE-2023-5521CRITICALCVSS 9.8EG 9.82023-10-11
Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.
- CVE-2023-5009CRITICALCVSS 9.8EG 9.82023-09-19
An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled secu…
- CVE-2023-40309CRITICALCVSS 9.8EG 9.82023-09-12
SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of…
- CVE-2023-32748CRITICALCVSS 9.8EG 9.82023-08-14
The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.
- CVE-2023-36092CRITICALCVSS 9.8EG 9.82023-07-31
Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
- CVE-2023-36091CRITICALCVSS 9.8EG 9.82023-07-31
Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the …
- CVE-2023-36090CRITICALCVSS 9.8EG 9.82023-07-31
Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain escalated privileges via phpcgi. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
- CVE-2023-36089CRITICALCVSS 9.8EG 9.82023-07-31
Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supporte…
- CVE-2023-31704CRITICALCVSS 9.8EG 9.82023-07-13
Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to the administrator's role.
- CVE-2023-36994CRITICALCVSS 9.8EG 9.82023-07-07
In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the server configuration and inject PHP code.
- CVE-2023-29381CRITICALCVSS 9.8EG 9.82023-07-06
An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information via the password and 2FA parameters.
- CVE-2022-46080CRITICALCVSS 9.8EG 9.82023-07-06
Nexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable TELNET.
- CVE-2021-46891CRITICALCVSS 9.8EG 9.82023-07-05
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
- CVE-2021-46890CRITICALCVSS 9.8EG 9.82023-07-05
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
- CVE-2023-26258CRITICALCVSS 9.8EG 9.82023-07-03
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obt…
- CVE-2023-27716CRITICALCVSS 9.8EG 9.82023-06-12
An issue was discovered in freakchicken kafkaUI-lite 1.2.11 allows attackers on the same network to gain escalated privileges for the nodes running on it.
- CVE-2023-28698CRITICALCVSS 9.8EG 9.82023-06-02
Wade Graphic Design FANTSY has a vulnerability of insufficient authorization check. An unauthenticated remote user can exploit this vulnerability by modifying URL parameters to gain administrator privileges to perform arbitrary system oper…
- CVE-2023-27388CRITICALCVSS 9.8EG 9.82023-05-23
Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user. Affected products and versions are as follows: T&D Cor…
- CVE-2023-30771CRITICALCVSS 9.8EG 9.82023-04-17
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database…
- CVE-2023-23594CRITICALCVSS 9.8EG 9.82023-03-31
An authentication bypass vulnerability in the web client interface for the CL4NX printer before firmware version 1.13.3-u724_r2 provides remote unauthenticated attackers with access to execute commands intended only for valid/authenticated…
- CVE-2023-26829CRITICALCVSS 9.8EG 9.82023-03-31
An authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows remote attackers to set a new password for any valid user account, without needing the previous known password, resultin…
- CVE-2023-1136CRITICALCVSS 9.8EG 9.82023-03-27
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass.
- CVE-2023-28611CRITICALCVSS 9.8EG 9.82023-03-23
Incorrect authorization in OMICRON StationGuard 1.10 through 2.20 and StationScout 1.30 through 2.20 allows an attacker to bypass intended access restrictions.
- CVE-2022-48284CRITICALCVSS 9.8EG 9.82023-02-27
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.
- CVE-2022-48283CRITICALCVSS 9.8EG 9.82023-02-27
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.
- CVE-2023-23064CRITICALCVSS 9.8EG 9.82023-02-17
TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.
- CVE-2021-32163CRITICALCVSS 9.8EG 9.82023-02-17
Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.
- CVE-2021-31577CRITICALCVSS 9.8EG 9.82023-02-06
In Boa, there is a possible escalation of privilege due to a missing permission check. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not neede…
- CVE-2022-47714CRITICALCVSS 9.8EG 9.82023-02-01
Last Yard 22.09.8-1 does not enforce HSTS headers
- CVE-2022-47003CRITICALCVSS 9.8EG 9.82023-02-01
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.
- CVE-2022-47002CRITICALCVSS 9.8EG 9.82023-02-01
A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.
- CVE-2022-45172CRITICALCVSS 9.8EG 9.82023-01-31
An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/registration/validateEmail endpoint, the /api/v1/vdeskintegration/user/adduser endpoint, and the /api/v1/registration/cha…
- CVE-2022-48066CRITICALCVSS 9.8EG 9.82023-01-27
An issue in the component global.so of Totolink A830R V4.1.2cu.5182 allows attackers to bypass authentication via a crafted cookie.
- CVE-2022-23739CRITICALCVSS 9.8EG 9.82023-01-17
An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileges in GraphQL API requests from GitHub Apps. This vulnerability allowed an app installed on an organization to gain acc…
- CVE-2022-45778CRITICALCVSS 9.8EG 9.82022-12-27
https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There is a permission bypass vulnerability in the Hillstone WEB application firewall. An attacker can enter the background of…
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →