CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,103 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 38 of 83
- CVE-2022-45778CRITICALCVSS 9.8EG 9.82022-12-27
https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There is a permission bypass vulnerability in the Hillstone WEB application firewall. An attacker can enter the background of…
- CVE-2022-45874MEDIUMCVSS 5.5EG 5.52022-12-28
Huawei Aslan Children's Watch has an improper authorization vulnerability. Successful exploit could allow the attacker to access certain file.
- CVE-2022-45891CRITICALCVSS 9.1EG 9.12022-12-25
Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList).
- CVE-2022-45956MEDIUMCVSS 5.3EG 5.32022-12-12
Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.
- CVE-2022-46076HIGHCVSS 7.5EG 7.52022-12-20
D-Link DIR-869 DIR869Ax_FW102B15 is vulnerable to Authentication Bypass via phpcgi.
- CVE-2022-46080CRITICALCVSS 9.8EG 9.82023-07-06
Nexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable TELNET.
- CVE-2022-4613MEDIUMCVSS 5.0EG 6.52022-12-19
A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as critical. This issue affects some unknown processing of the component Browser Extension Provisioning. The manipulation le…
- CVE-2022-46160MEDIUMCVSS 4.3EG 4.32022-12-13
Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14.2.99.104, project level authorizations are not properly verified when accessing the project "homepage"/dashboards. Use…
- CVE-2022-46167HIGHCVSS 8.8EG 8.82022-12-02
Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to version 0.1.3, a ServiceAccount deployed in a Tenant Namespace, when granted with `PATCH` capabilities on its own Namespace, is able to edit it and remove the O…
- CVE-2022-46169CRITICALCVSS 9.8EG 9.8⚠ KEV2022-12-05
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbit…
- CVE-2022-46258MEDIUMCVSS 6.5EG 6.52023-01-09
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository-scoped token with read/write access to modify Action Workflow files without a Workflow scope. The Create or Update file contents …
- CVE-2022-46307HIGHCVSS 8.8EG 8.82023-06-02
SGUDA U-Lock central lock control service’s lock management function has incorrect authorization. A remote attacker with general privilege can exploit this vulnerability to call privileged APIs to acquire information, manipulate or disru…
- CVE-2022-46308HIGHCVSS 8.8EG 8.82023-06-02
SGUDA U-Lock central lock control service’s user management function has incorrect authorization. A remote attacker with general user privilege can exploit this vulnerability to call privileged APIs to access, modify and delete user info…
- CVE-2022-46399HIGHCVSS 7.5EG 7.52022-12-19
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero.
- CVE-2022-46400MEDIUMCVSS 5.4EG 5.42022-12-19
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing.
- CVE-2022-46704MEDIUMCVSS 5.5EG 5.52023-02-27
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.1, macOS Big Sur 11.7.2, macOS Monterey 12.6.2. An app may be able to modify protected parts of the file system.
- CVE-2022-46792HIGHCVSS 8.8EG 8.82022-12-08
Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, and 2.15.2. (Versions before 2.10.0 are unaffected.)
- CVE-2022-47002CRITICALCVSS 9.8EG 9.82023-02-01
A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.
- CVE-2022-47003CRITICALCVSS 9.8EG 9.82023-02-01
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.
- CVE-2022-47553HIGHCVSS 8.6EG 8.62023-09-19
Incorrect authorisation in ekorCCP and ekorRCI, which could allow a remote attacker to obtain resources with sensitive information for the organisation, without being authenticated within the web server.
- CVE-2022-47648HIGHCVSS 7.6EG 8.82023-02-08
An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or authentication due to the IP based authorization. If an authorized user has accessed a publi…
- CVE-2022-47714CRITICALCVSS 9.8EG 9.82023-02-01
Last Yard 22.09.8-1 does not enforce HSTS headers
- CVE-2022-47874MEDIUMCVSS 6.5EG 6.52023-05-02
Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' and method 'getGlobalConnection'.
- CVE-2022-48066CRITICALCVSS 9.8EG 9.82023-01-27
An issue in the component global.so of Totolink A830R V4.1.2cu.5182 allows attackers to bypass authentication via a crafted cookie.
- CVE-2022-48283CRITICALCVSS 9.8EG 9.82023-02-27
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.
- CVE-2022-48284CRITICALCVSS 9.8EG 9.82023-02-27
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.
- CVE-2022-48286HIGHCVSS 7.5EG 7.52023-02-09
The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-48302HIGHCVSS 7.5EG 7.52023-02-09
The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-48488MEDIUMCVSS 5.3EG 5.32023-06-19
Vulnerability of bypassing the default desktop security controls.Successful exploitation of this vulnerability may cause unauthorized modifications to the desktop.
- CVE-2022-48495MEDIUMCVSS 5.3EG 5.32023-06-19
Vulnerability of unauthorized access to foreground app information.Successful exploitation of this vulnerability may cause foreground app information to be obtained.
- CVE-2022-48508HIGHCVSS 7.5EG 7.52023-07-06
Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulnerability may affect service integrity.
- CVE-2022-48538MEDIUMCVSS 5.3EG 5.32023-08-22
In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password.
- CVE-2023-0091LOWCVSS 3.8EG 3.82023-01-13
A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.
- CVE-2023-0120LOWCVSS 3.5EG 3.52023-09-01
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was poss…
- CVE-2023-0133MEDIUMCVSS 6.5EG 6.52023-01-10
Inappropriate implementation in in Permission prompts in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to bypass main origin permission delegation via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-0298MEDIUMCVSS 6.5EG 6.52023-01-14
Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0.
- CVE-2023-0319MEDIUMCVSS 5.8EG 5.82023-04-05
An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to …
- CVE-2023-0328MEDIUMCVSS 4.3EG 4.32023-03-06
The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for several AJAX actions, only checking the nonce. This may lead to allowing any authenticated user who can edit posts to call the endpoints related …
- CVE-2023-0814MEDIUMCVSS 6.5EG 6.52023-02-14
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_meta] shortcode in versions up to, and including 3.9.0. This is due to insufficient restric…
- CVE-2023-0940HIGHCVSS 8.8EG 8.82023-03-20
The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. This allows a user with low privileges, such as subscriber, to change the password of any ac…
- CVE-2023-0952MEDIUMCVSS 6.5EG 6.52023-03-01
Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization.
- CVE-2023-0971CRITICALCVSS 9.6EG 9.62023-06-21
A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.
- CVE-2023-1071MEDIUMCVSS 3.1EG 4.32023-04-05
An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for a…
- CVE-2023-1136CRITICALCVSS 9.8EG 9.82023-03-27
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass.
- CVE-2023-1144HIGHCVSS 8.8EG 8.82023-03-27
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in which an attacker can use the Device-Gateway service and bypass authorization, which could result in privilege escalati…
- CVE-2023-1158MEDIUMCVSS 4.3EG 4.32023-05-24
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard prompts to users who are not part of the authorization list.
- CVE-2023-1164HIGHCVSS 8.4EG 8.42023-03-03
A vulnerability was found in KylinSoft kylin-activation on KylinOS and classified as critical. Affected by this issue is some unknown functionality of the component File Import. The manipulation leads to improper authorization. The attack …
- CVE-2023-1202MEDIUMCVSS 6.5EG 6.52023-04-02
Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9 and prior versions allows users with restricted rights to bypass entry permission via id collision.
- CVE-2023-1417MEDIUMCVSS 4.3EG 4.32023-04-05
An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unre…
- CVE-2023-1603MEDIUMCVSS 6.5EG 6.52023-04-02
Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restricted rights to bypass entry permission via id collision.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →