CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,104 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 39 of 83
- CVE-2023-1779MEDIUMCVSS 4.3EG 4.32023-06-06
Exposure of Sensitive Information to an unauthorized actor vulnerability in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual in versions <=2.13.3 allow an authorized remote attacker with low privileges…
- CVE-2023-1832MEDIUMCVSS 6.8EG 6.82023-10-04
An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.
- CVE-2023-1979MEDIUMCVSS 4.9EG 4.92023-05-08
The Web Stories for WordPress plugin supports the WordPress built-in functionality of protecting content with a password. The content is then only accessible to website visitors after entering the password. In WordPress, users with the "Au…
- CVE-2023-20018HIGHCVSS 8.6EG 8.62023-01-20
A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device. This vulnerability is due to insufficien…
- CVE-2023-2002MEDIUMCVSS 6.8EG 6.82023-05-26
A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the …
- CVE-2023-20048CRITICALCVSS 9.9EG 9.92023-11-01
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) devi…
- CVE-2023-20190MEDIUMCVSS 5.8EG 5.82023-09-13
A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. Th…
- CVE-2023-20191MEDIUMCVSS 5.8EG 5.82023-09-13
A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to in…
- CVE-2023-2020MEDIUMCVSS 4.3EG 4.32023-04-18
Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host.
- CVE-2023-20269CRITICALCVSS 5.0EG 9.0⚠ KEV2023-09-06
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an at…
- CVE-2023-20800MEDIUMCVSS 6.5EG 6.52023-08-07
In imgsys, there is a possible system crash due to a mssing ptr check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07420968; Issue ID:…
- CVE-2023-20871HIGHCVSS 7.8EG 7.82023-04-25
VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system.
- CVE-2023-20877HIGHCVSS 8.8EG 8.82023-05-12
VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.
- CVE-2023-20880MEDIUMCVSS 6.7EG 6.72023-05-12
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
- CVE-2023-20950HIGHCVSS 7.8EG 7.82023-04-19
In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restrictions via a pendingIntent. This could lead to local escalation of privilege with no additional execution privileges n…
- CVE-2023-20971HIGHCVSS 7.8EG 7.82023-03-24
In removePermission of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permissions without user consent due to a logic error in the code. This could lead to local escalation of privilege with no additional ex…
- CVE-2023-20975HIGHCVSS 7.8EG 7.82023-03-24
In getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible way to bypass DISALLOW_CONTENT_CAPTURE due to a permissions bypass. This could lead to local escalation of privilege with no additional executio…
- CVE-2023-21034HIGHCVSS 7.8EG 7.82023-03-24
In multiple functions of SensorService.cpp, there is a possible access of accurate sensor data due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not nee…
- CVE-2023-21035HIGHCVSS 7.8EG 7.82023-03-24
In multiple functions of BackupHelper.java, there is a possible way for an app to get permissions previously granted to another app with the same package name due to a permissions bypass. This could lead to local escalation of privilege wi…
- CVE-2023-21116MEDIUMCVSS 6.7EG 6.72023-05-15
In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below system image version due to a logic error in the code. This could lead to local escalation of privilege with System executio…
- CVE-2023-21117HIGHCVSS 7.8EG 7.82023-05-15
In registerReceiverWithFeature of ActivityManagerService.java, there is a possible way for isolated processes to register a broadcast receiver due to a permissions bypass. This could lead to local escalation of privilege with no additional…
- CVE-2023-21225HIGHCVSS 7.8EG 7.82023-06-28
there is a possible way to bypass the protected confirmation screen due to Failure to lock display power. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for explo…
- CVE-2023-21245HIGHCVSS 7.8EG 7.82023-07-13
In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during device setup due to a logic error in the code. This could lead to local escalation of privilege with no…
- CVE-2023-21254HIGHCVSS 7.8EG 7.82023-07-13
In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the app is being killed due to a logic error in the code. This could lead to local escalation of privilege with no addition…
- CVE-2023-21256HIGHCVSS 7.8EG 7.82023-07-13
In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User i…
- CVE-2023-21270HIGHCVSS 7.8EG 7.82024-11-19
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to incorrect permission flags cleared during an update. This could lead to local escalation o…
- CVE-2023-21311MEDIUMCVSS 5.5EG 5.52023-10-30
In Settings, there is a possible way to control private DNS settings from a secondary user due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…
- CVE-2023-21390HIGHCVSS 7.8EG 7.82023-10-30
In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit…
- CVE-2023-21422MEDIUMCVSS 5.7EG 5.72023-02-09
Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.
- CVE-2023-21423MEDIUMCVSS 5.1EG 5.52023-02-09
Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission using unprotected action.
- CVE-2023-21424MEDIUMCVSS 5.1EG 5.12023-02-09
Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand.
- CVE-2023-21560MEDIUMCVSS 6.6EG 6.62023-01-10
Windows Boot Manager Security Feature Bypass Vulnerability
- CVE-2023-21670HIGHCVSS 7.8EG 7.82023-06-06
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
- CVE-2023-21715CRITICALCVSS 7.3EG 9.0⚠ KEV2023-02-14
Microsoft Publisher Security Feature Bypass Vulnerability
- CVE-2023-21719MEDIUMCVSS 6.5EG 6.52023-01-24
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- CVE-2023-22067MEDIUMCVSS 5.3EG 5.32023-10-17
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf; Oracle GraalVM Enterprise Edition: 20.3.11 an…
- CVE-2023-22248HIGHCVSS 7.5EG 7.52023-06-15
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnera…
- CVE-2023-22251MEDIUMCVSS 4.3EG 4.32023-03-27
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorrect Authorization vulnerability. A low-privileged authenticated attacker could leverage this vulnerability to achieve minor information disc…
- CVE-2023-22480HIGHCVSS 7.3EG 8.42023-01-14
KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak…
- CVE-2023-22482CRITICALCVSS 9.0EG 9.02023-01-26
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and prior to 2.3.13, 2.4.19, 2.5.6, and 2.6.0-rc-3 are vulnerable to an improper authorization bug causing the API to accep…
- CVE-2023-22500HIGHCVSS 7.5EG 7.52023-01-26
GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6 are vulnerable to Incorrect Authorization. This vulnerability allow unauthorized access to inventory files. Thus, if anonymous access to FA…
- CVE-2023-22518CRITICALCVSS 9.8EG 9.8⚠ KEV2023-10-31
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrat…
- CVE-2023-2257HIGHCVSS 7.8EG 7.82023-04-24
Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker with access to the user interface to unlock a Hub Business space without being prompted to e…
- CVE-2023-22593MEDIUMCVSS 4.0EG 4.02023-06-27
IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to security misconfiguration of the Redis container which may provide elevated privileges. IBM X-Force ID: 244074.
- CVE-2023-22610CRITICALCVSS 9.1EG 9.12023-01-31
A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server when specific messages are sent to the server over the database server TCP port.
- CVE-2023-22620HIGHCVSS 7.5EG 7.52023-04-12
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an invalid authentication attempt. This can afterwards be used to bypass the device's authenticat…
- CVE-2023-22833HIGHCVSS 7.6EG 7.62023-06-06
Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Foundry organization to bypass discretionary or mandatory access controls under certain circums…
- CVE-2023-22891HIGHCVSS 8.1EG 8.12023-03-08
There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset passwords for other accounts.
- CVE-2023-22945MEDIUMCVSS 4.3EG 4.32023-01-11
In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows blocked users (blocked in ApiManageMentorList) to enroll as mentors or edit any of their mentorship-related properties.
- CVE-2023-23064CRITICALCVSS 9.8EG 9.82023-02-17
TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →