CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
5,070 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 6 of 102
- CVE-2021-45466CRITICALCVSS 9.8EG 9.82022-12-26
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder.
- CVE-2022-44039CRITICALCVSS 9.8EG 9.82022-12-05
Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker can overwrite system files like [system.conf] and [passwd], this occurs because the insecu…
- CVE-2022-41326CRITICALCVSS 9.8EG 9.82022-11-22
The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code execution within the…
- CVE-2022-43400CRITICALCVSS 9.8EG 9.82022-10-21
A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)). The mobile server component of affected applications improperly handles the log in for Active Directory accounts that are part of…
- CVE-2022-2778CRITICALCVSS 9.8EG 9.82022-09-30
In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.
- CVE-2022-28321CRITICALCVSS 9.8EG 9.82022-09-19
The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via …
- CVE-2022-38768CRITICALCVSS 9.8EG 9.82022-09-13
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to bypass authorization.
- CVE-2022-37767CRITICALCVSS 9.8EG 9.82022-09-12
Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok. NOTE: the vendor disputes this because input to the Pebble templating engine is intended to include arbitrary J…
- CVE-2022-37176CRITICALCVSS 9.8EG 9.82022-08-30
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi-Fi password and force the device into open security mode via a crafted packet sent to goform/setWizard.
- CVE-2022-36755CRITICALCVSS 9.8EG 9.82022-08-28
D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.
- CVE-2022-25899CRITICALCVSS 9.8EG 9.82022-08-18
Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before versions 2.0.2 and 2.2.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
- CVE-2022-37002CRITICALCVSS 9.8EG 9.82022-08-10
The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background.
- CVE-2022-34487CRITICALCVSS 9.8EG 9.82022-07-21
Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.
- CVE-2022-33198CRITICALCVSS 9.8EG 9.82022-07-21
Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.
- CVE-2022-26479CRITICALCVSS 9.8EG 9.82022-07-17
An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authentication.
- CVE-2022-35890CRITICALCVSS 9.8EG 9.82022-07-15
An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client Session IDs are mishandled. An attacker can determine which session IDs were generated in the past and then hijack ses…
- CVE-2022-32294CRITICALCVSS 9.8EG 9.82022-07-11
Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible in cleartext on port UDP 514 (aka the syslog port). NOTE: a third party reports that this c…
- CVE-2022-32310CRITICALCVSS 9.8EG 9.82022-07-05
An access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a crafted POST request to /isms/classes/Users.php.
- CVE-2022-32295CRITICALCVSS 9.8EG 9.82022-07-01
On Ampere Altra and AltraMax devices before SRP 1.09, the Altra reference design of UEFI accesses allows insecure access to SPI-NOR by the OS/hypervisor component.
- CVE-2022-32532CRITICALCVSS 9.8EG 9.82022-06-29
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
- CVE-2022-27668CRITICALCVSS 9.8EG 9.82022-06-14
Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77,…
- CVE-2022-33174CRITICALCVSS 9.8EG 9.82022-06-13
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interf…
- CVE-2022-30311CRITICALCVSS 9.8EG 9.82022-06-13
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges d…
- CVE-2022-30310CRITICALCVSS 9.8EG 9.82022-06-13
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges d…
- CVE-2022-30309CRITICALCVSS 9.8EG 9.82022-06-13
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privi…
- CVE-2022-30308CRITICALCVSS 9.8EG 9.82022-06-13
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privil…
- CVE-2022-25237CRITICALCVSS 9.8EG 9.82022-06-02
Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /../i18ntranslation/ to the end of a URL, …
- CVE-2022-29633CRITICALCVSS 9.8EG 9.82022-05-26
An access control issue in Linglong v1.0 allows attackers to access the background of the application via a crafted cookie.
- CVE-2022-23775CRITICALCVSS 9.8EG 9.82022-05-25
TrueStack Direct Connect 1.4.7 has Incorrect Access Control.
- CVE-2022-22978CRITICALCVSS 9.8EG 9.82022-05-19
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the…
- CVE-2022-29906CRITICALCVSS 9.8EG 9.82022-04-29
The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user.
- CVE-2022-29081CRITICALCVSS 9.8EG 9.82022-04-28
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDash…
- CVE-2022-27128CRITICALCVSS 9.8EG 9.82022-04-10
An incorrect access control issue at /admin/run_ajax.php in zbzcms v1.0 allows attackers to arbitrarily add administrator accounts.
- CVE-2022-26676CRITICALCVSS 9.8EG 9.82022-04-07
aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scripts to control the system or disrupt service.
- CVE-2021-32986CRITICALCVSS 9.8EG 9.82022-04-04
After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not timeout. If the programming software is interrupted, the PLC remains unlocked. All subseq…
- CVE-2022-26279CRITICALCVSS 9.8EG 9.82022-03-24
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
- CVE-2022-23730CRITICALCVSS 9.8EG 9.82022-03-11
The public API error causes for the attacker to be able to bypass API access control.
- CVE-2022-24609CRITICALCVSS 9.8EG 9.82022-03-10
Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file.
- CVE-2022-24306CRITICALCVSS 9.8EG 9.82022-03-02
Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.
- CVE-2021-39994CRITICALCVSS 9.8EG 9.82022-02-09
There is an arbitrary address access vulnerability with the product line test code.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
- CVE-2022-24307CRITICALCVSS 9.8EG 9.82022-02-03
Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since version 1.6.0.)
- CVE-2021-39070CRITICALCVSS 9.8EG 9.82022-02-02
IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system. IBM X-Force ID: 215353.
- CVE-2020-4877CRITICALCVSS 9.8EG 9.82022-01-21
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Force ID: 190843.
- CVE-2021-20149CRITICALCVSS 9.8EG 9.82021-12-30
Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default iptables ruleset for governing access to services on the device only apply to IPv4. All services running on the devices …
- CVE-2021-23803CRITICALCVSS 9.8EG 9.82021-12-17
This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of certain functions, adding control character…
- CVE-2021-39052CRITICALCVSS 9.8EG 9.82021-12-13
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console without authorization. IBM X-Force ID: 214523.
- CVE-2021-43703CRITICALCVSS 9.8EG 9.82021-12-09
An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console.
- CVE-2021-42002CRITICALCVSS 9.8EG 9.82021-11-11
Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution.
- CVE-2021-42837CRITICALCVSS 9.8EG 9.82021-11-05
An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the native login page. Any valid user from the SAML/OAuth provider can be used as the username wit…
- CVE-2021-35368CRITICALCVSS 9.8EG 9.82021-11-05
OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →