CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
5,070 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 8 of 102
- CVE-2020-3227CRITICALCVSS 9.8EG 9.82020-06-03
A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute Cisco IOx API commands without proper authorization. The…
- CVE-2020-12874CRITICALCVSS 9.8EG 9.82020-05-14
Veritas APTARE versions prior to 10.4 included code that bypassed the normal login process when specific authentication credentials were provided to the server.
- CVE-2020-12720CRITICALCVSS 9.8EG 9.82020-05-08
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
- CVE-2019-20772CRITICALCVSS 9.8EG 9.82020-04-17
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. The Account subsystem allows authorization bypass. The LG ID is LVE-SMP-190007 (August 2019).
- CVE-2020-10534CRITICALCVSS 9.8EG 9.82020-03-12
In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to the case in which an IP address is contai…
- CVE-2013-2198CRITICALCVSS 9.8EG 9.82020-01-30
The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows attackers to bypass intended restrictions via a crafted username.
- CVE-2020-8086CRITICALCVSS 9.8EG 9.82020-01-28
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches th…
- CVE-2012-6094CRITICALCVSS 9.8EG 9.82019-12-20
cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system
- CVE-2019-12419CRITICALCVSS 9.8EG 9.82019-11-06
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated p…
- CVE-2019-15900CRITICALCVSS 9.8EG 9.82019-10-18
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used without checking for error cases. Instead, the uninitialized variable errstr was checked and in …
- CVE-2019-15941CRITICALCVSS 9.8EG 9.82019-09-25
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDA…
- CVE-2019-14237CRITICALCVSS 9.8EG 9.82019-09-12
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by observing CPU registers and the effect of code/instruction execution.
- CVE-2019-14236CRITICALCVSS 9.8EG 9.82019-09-12
On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated by observing CPU registers and the effect of code/instru…
- CVE-2019-16114CRITICALCVSS 9.8EG 9.82019-09-09
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain access to the application. Next, he can change the directory that the application uploads f…
- CVE-2019-14813CRITICALCVSS 9.8EG 9.82019-09-06
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could…
- CVE-2019-7304CRITICALCVSS 9.8EG 9.82019-04-23
Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37.1.
- CVE-2018-19515CRITICALCVSS 9.8EG 9.82019-03-21
In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator. However, by using one of the bgsend, atment_sddd1xGz, or xls_bgimport query parameters, most of these methods become available t…
- CVE-2018-13324CRITICALCVSS 9.8EG 9.82018-11-26
Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified HTTP Host header.
- CVE-2018-12369CRITICALCVSS 9.8EG 9.82018-10-18
WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain full browser permissions. This vulnerability affects Firefox ESR < 60.1 and Firefox < 61.
- CVE-2018-1000155CRITICALCVSS 9.8EG 9.82018-05-24
OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake: The DPID (DataPath IDentifier) in the features_reply message are inherently trusted by the controller. that can resul…
- CVE-2017-16743CRITICALCVSS 9.8EG 9.82018-01-12
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing a…
- CVE-2017-17067CRITICALCVSS 9.8EG 9.82017-11-30
Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the SAML authType is enabled, mishandles SAML, which allows remote attackers to bypass intend…
- CVE-2017-9653CRITICALCVSS 9.8EG 9.82017-08-14
An Improper Authorization issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft Azure before 2016 R2 SP1, and PI Integrator for SAP HANA before 2017. An attacker is able to gain pr…
- CVE-2017-9855CRITICALCVSS 9.8EG 9.82017-08-05
An issue was discovered in SMA Solar Technology products. A secondary authentication system is available for Installers called the Grid Guard system. This system uses predictable codes, and a single Grid Guard code can be used on any SMA i…
- CVE-2017-7512CRITICALCVSS 9.8EG 9.82017-07-07
Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attacker could use this flaw to circumvent authentication controls and gain access to restricted…
- CVE-2010-2965CRITICALCVSS 9.8EG 9.82010-08-05
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote attackers to read or modify arbitrary mem…
- CVE-2001-1155CRITICALCVSS 9.8EG 9.82001-08-23
TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restrictions via DNS spo…
- CVE-2022-0143CRITICALCVSS 9.3EG 9.82022-09-19
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remo…
- CVE-2022-38375CRITICALCVSS 9.1EG 9.82023-02-16
An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST…
- CVE-2021-27663CRITICALCVSS 8.2EG 9.82021-08-30
A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequate authorization. This issue affects: Johnson Controls CEM Systems AC2000 10.1; 10.2; 10.3;…
- CVE-2024-25652CRITICALCVSS 7.6EG 9.82024-03-14
In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access…
- CVE-2022-36387CRITICALCVSS 7.6EG 9.82022-09-06
Broken Access Control vulnerability in Alessio Caiazza's About Me plugin <= 1.0.12 at WordPress.
- CVE-2024-40530CRITICALCVSS 7.5EG 9.82024-08-05
A vulnerability in Pantera CRM versions 401.152 and 402.072 allows unauthorized attackers to bypass IP-based access controls by manipulating the X-Forwarded-For header.
- CVE-2022-39956CRITICALCVSS 7.3EG 9.82022-09-20
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding m…
- CVE-2022-39955CRITICALCVSS 7.3EG 9.82022-09-20
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable back-end can potentially b…
- CVE-2024-45509CRITICALCVSS 6.5EG 9.82024-09-01
In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.
- CVE-2017-7470CRITICALCVSS 6.5EG 9.82018-07-27
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py.
- CVE-2022-43515CRITICALCVSS 5.3EG 9.82022-12-05
Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained a…
- CVE-2022-41155CRITICALCVSS 5.3EG 9.82022-11-19
Block BYPASS vulnerability in iQ Block Country plugin <= 1.2.18 on WordPress.
- CVE-2022-39862CRITICALCVSS 5.3EG 9.82022-10-07
Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S(12) allows unauthorized use of javascript interface api.
- CVE-2024-46918CRITICALCVSS 4.9EG 9.82024-09-15
app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.
- CVE-2022-29423CRITICALCVSS 3.8EG 9.82022-05-06
Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.
- CVE-2026-13232CRITICALCVSS 3.1EG 9.82026-07-10
Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0.
- CVE-2026-106372CRITICALCVSS 9.6EG 9.62026-10-06
Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-106241CRITICALCVSS 9.6EG 9.62026-10-06
Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium se…
- CVE-2026-106329CRITICALCVSS 9.6EG 9.62026-10-06
Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security sev…
- CVE-2026-102322CRITICALCVSS 9.6EG 9.62026-10-06
Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-103626CRITICALCVSS 9.6EG 9.62026-10-02
Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromiu…
- CVE-2026-85724CRITICALCVSS 9.6EG 9.62026-09-23
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then tre…
- CVE-2026-90942CRITICALCVSS 9.6EG 9.62026-09-14
Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key t…
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →