CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
5,070 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 9 of 102
- CVE-2026-87492CRITICALCVSS 9.6EG 9.62026-09-09
Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-84354CRITICALCVSS 9.6EG 9.62026-09-01
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-71424CRITICALCVSS 9.6EG 9.62026-08-17
Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_token…
- CVE-2026-71193CRITICALCVSS 9.6EG 9.62026-08-12
In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a diffe…
- CVE-2026-71384CRITICALCVSS 9.6EG 9.62026-08-11
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resu…
- CVE-2026-56443CRITICALCVSS 9.6EG 9.62026-07-21
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
- CVE-2026-53552CRITICALCVSS 9.6EG 9.62026-07-07
Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row id from …
- CVE-2026-53492CRITICALCVSS 9.6EG 9.62026-06-19
containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during cont…
- CVE-2026-55518CRITICALCVSS 9.6EG 9.62026-06-17
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the UI and GET /resources/:resource/:id/:related/new path, but the actua…
- CVE-2026-54307CRITICALCVSS 9.6EG 9.62026-06-16
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with editor access to a shared workflow could reference credentials they do not own via specific public API endpoints. Credentia…
- CVE-2026-25293CRITICALCVSS 9.6EG 9.62026-05-04
Buffer overflow due to incorrect authorization in PLC FW
- CVE-2024-23629CRITICALCVSS 9.6EG 9.62024-01-26
An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve sensitive information.
- CVE-2023-31403CRITICALCVSS 9.6EG 9.62023-11-14
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any malicious user can read and write to the SMB shared folder. Additionally, the files in th…
- CVE-2023-30429CRITICALCVSS 9.6EG 9.62023-07-12
Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. When a client connects to the Pulsar Function Worker via the Pulsar Proxy where the Pulsar Pr…
- CVE-2023-0971CRITICALCVSS 9.6EG 9.62023-06-21
A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.
- CVE-2022-39214CRITICALCVSS 9.6EG 9.62023-03-14
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in ve…
- CVE-2022-1309CRITICALCVSS 9.6EG 9.62022-07-25
Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
- CVE-2022-30584CRITICALCVSS 9.6EG 9.62022-05-26
Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentially be exploited by malicious users to compromise the affected system. 6.10 P3 (6.10.0.3) and 6.9…
- CVE-2021-30571CRITICALCVSS 9.6EG 9.62021-08-03
Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.
- CVE-2017-3891CRITICALCVSS 9.6EG 9.62017-11-14
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with QNet enabled on networks comprising two or more QNet nodes could allow an attacker to acc…
- CVE-2024-3379CRITICALCVSS 8.1EG 9.62024-11-14
In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key for projects they do not have access to. Specifically, a user with a 'Member' role can issu…
- CVE-2023-5356CRITICALCVSS 7.3EG 9.62024-01-12
Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integr…
- CVE-2026-104480CRITICALCVSS 9.4EG 9.42026-10-02
Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able …
- CVE-2026-19759CRITICALCVSS 9.4EG 9.42026-09-28
An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google Cloud Platform allows an authenticated Google Cloud user to execute arbitrary internal RPCs …
- CVE-2026-47407CRITICALCVSS 9.4EG 9.42026-05-29
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and protects them with a `require_workspace_me…
- CVE-2026-42882CRITICALCVSS 9.4EG 9.42026-05-11
oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path interpretation between the authentication middleware and the bucket handler. The authenticatio…
- CVE-2025-29757CRITICALCVSS 9.4EG 9.42025-07-19
An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her account.
- CVE-2025-3476CRITICALCVSS 9.4EG 9.42025-05-07
Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege escalation by authenticated users.This issue affects Operations Bridge Manager: 2023.05, 23.4, 24.2, 24.4.
- CVE-2024-3033CRITICALCVSS 9.4EG 9.42024-06-06
An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-routes. This flaw allows unauthenticated users to perform destructive actions on the Vecto…
- CVE-2021-41592CRITICALCVSS 9.4EG 9.42021-10-04
Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure.
- CVE-2021-41591CRITICALCVSS 9.4EG 9.42021-10-04
ACINQ Eclair before 0.6.3 allows loss of funds because of dust HTLC exposure.
- CVE-2026-59270CRITICALCVSS 9.1EG 9.42026-08-27
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Sp…
- CVE-2026-105851CRITICALCVSS 9.3EG 9.32026-10-06
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, the duplicate operation copies values from a source document even when a field is hidden…
- CVE-2026-86102CRITICALCVSS 9.3EG 9.32026-09-28
An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.
- CVE-2026-73090CRITICALCVSS 9.3EG 9.32026-08-11
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying that byActor.url is authorized for the hos…
- CVE-2026-18236CRITICALCVSS 9.3EG 9.32026-07-29
A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool conf…
- CVE-2026-65049CRITICALCVSS 9.3EG 9.32026-07-21
Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped …
- CVE-2026-48321CRITICALCVSS 9.3EG 9.32026-07-14
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. The vulnerable component is restricted …
- CVE-2026-34660CRITICALCVSS 9.3EG 9.32026-05-12
Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerabilit…
- CVE-2025-26850CRITICALCVSS 9.3EG 9.32025-07-05
The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on managed systems.
- CVE-2025-53391CRITICALCVSS 9.3EG 9.32025-06-28
The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inactive/allow_active settings that allow a local user to escalate their privileges to root.
- CVE-2025-48757CRITICALCVSS 9.3EG 9.32025-05-30
An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites. NOTE: this is disputed by the Supplier because each …
- CVE-2025-1542CRITICALCVSS 9.3EG 9.32025-03-26
Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions in the application.This issue affects …
- CVE-2024-48548CRITICALCVSS 9.3EG 9.32024-10-24
The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulnerability allows attackers to arbitrarily construct a request to use the app to bind to unknown devices by finding a val…
- CVE-2021-21276CRITICALCVSS 9.3EG 9.32021-02-01
Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attackers to gain admin access to site instances, even if they do not possess an existing account. This vulnerability exists re…
- CVE-2025-9803CRITICALCVSS 8.8EG 9.32025-11-25
lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application fails to verify the 'aud' (audience) field in the access token issued by Google, which is …
- CVE-2011-1207HIGHCVSS v2 9.3EG 9.32011-05-05
The ActiveBar1 ActiveX control in the Data Dynamics ActiveBar ActiveX controls, as distributed in ActBar.ocx 1.0.6.5 in IBM Rational System Architect 11.4.0.2, 11.4.0.1, and earlier, does not properly restrict the SetLayoutData method, whi…
- CVE-2007-2586HIGHCVSS v2 9.3EG 9.32007-05-10
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD com…
- CVE-2026-103547CRITICALCVSS 9.2EG 9.22026-09-30
In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connecti…
- CVE-2024-5539CRITICALCVSS 9.2EG 9.22025-11-27
The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building…
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →