CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,104 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 40 of 83
- CVE-2023-23192HIGHCVSS 7.2EG 7.22023-03-23
IS Decisions UserLock MFA 11.01 is vulnerable to authentication bypass using scheduled task.
- CVE-2023-23299HIGHCVSS 7.5EG 7.52023-05-23
The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirely. A malicious application with specially crafted code and data sections could access restricted CIQ…
- CVE-2023-23304CRITICALCVSS 9.1EG 9.12023-05-23
The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybox.SensorHistory` module without permission. A malicious application could call any functions from …
- CVE-2023-23445HIGHCVSS 7.5EG 7.52023-05-15
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpr…
- CVE-2023-23446HIGHCVSS 7.5EG 7.52023-05-15
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the…
- CVE-2023-23476LOWCVSS 3.1EG 3.12023-08-02
IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insufficient authorization validation on some API routes. IBM X-Force ID: 245425.
- CVE-2023-23506MEDIUMCVSS 5.5EG 5.52023-02-27
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be able to access user-sensitive data.
- CVE-2023-23510MEDIUMCVSS 5.5EG 5.52023-02-27
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be able to access a user’s Safari history.
- CVE-2023-23538MEDIUMCVSS 5.5EG 5.52023-05-08
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4. An app may be able to modify protected parts of the file system.
- CVE-2023-23594CRITICALCVSS 9.8EG 9.82023-03-31
An authentication bypass vulnerability in the web client interface for the CL4NX printer before firmware version 1.13.3-u724_r2 provides remote unauthenticated attackers with access to execute commands intended only for valid/authenticated…
- CVE-2023-23604MEDIUMCVSS 6.5EG 6.52023-06-02
A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromSafeString`. This could have lead to bypassing web security checks. This vulnerability affects Firefox < 109.
- CVE-2023-23696HIGHCVSS 7.0EG 7.82023-02-07
Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locally authenticated malicious users could potentially exploit this vulnerability in order to write arbitrary files to the s…
- CVE-2023-23751MEDIUMCVSS 4.3EG 4.32023-02-01
An issue was discovered in Joomla! 4.0.0 through 4.2.4. A missing ACL check allows non super-admin users to access com_actionlogs.
- CVE-2023-23918HIGHCVSS 7.5EG 7.52023-02-23
A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non author…
- CVE-2023-23924CRITICALCVSS 10.0EG 10.02023-02-01
Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP < 8, through the `phar` URL wrappe…
- CVE-2023-23947CRITICALCVSS 9.1EG 9.12023-02-16
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23 2.5.11, and 2.6.2 are vulnerable to an improper authorization bug which allows users who ha…
- CVE-2023-24029HIGHCVSS 7.2EG 7.22023-02-03
In Progress WS_FTP Server before 8.8, it is possible for a host administrator to elevate their privileges via the administrative interface due to insufficient authorization controls applied on user modification workflows.
- CVE-2023-24047MEDIUMCVSS 6.8EG 6.82023-12-04
An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via use of weak hashing algorithm.
- CVE-2023-24051CRITICALCVSS 9.8EG 9.82023-12-04
A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style attacks.
- CVE-2023-24052CRITICALCVSS 9.8EG 9.82023-12-04
An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as it does not prompt for the current password.
- CVE-2023-24471MEDIUMCVSS 6.5EG 6.52023-08-09
An access control vulnerability was found, due to the restrictions that are applied on actual assertions not being enforced in their debug functionality. An authenticated user with reduced visibility can obtain unauthorized information vi…
- CVE-2023-24485HIGHCVSS 7.8EG 7.82023-02-16
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.
- CVE-2023-24505MEDIUMCVSS 5.3EG 5.32023-05-08
Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request.
- CVE-2023-24512HIGHCVSS 8.8EG 8.82023-04-25
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Te…
- CVE-2023-24546HIGHCVSS 8.1EG 8.12023-06-13
On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration da…
- CVE-2023-24600MEDIUMCVSS 4.3EG 4.32023-05-29
OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via a move to their own address book.
- CVE-2023-24829HIGHCVSS 8.8EG 8.82023-01-31
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component from 0.13.0 before 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console…
- CVE-2023-24880CRITICALCVSS 4.4EG 9.0⚠ KEV2023-03-14
Windows SmartScreen Security Feature Bypass Vulnerability
- CVE-2023-24932MEDIUMCVSS 6.7EG 6.72023-05-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2023-24999MEDIUMCVSS 4.4EG 4.42023-03-11
HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fi…
- CVE-2023-25017HIGHCVSS 8.1EG 8.12023-03-27
RIFARTEK IOT Wall has a vulnerability of incorrect authorization. An authenticated remote attacker with general user privilege is allowed to perform specific privileged function to access and modify all sensitive data.
- CVE-2023-25043MEDIUMCVSS 4.3EG 5.02024-04-17
Incorrect Authorization vulnerability in Supsystic Data Tables Generator.This issue affects Data Tables Generator: from n/a through 1.10.25.
- CVE-2023-2515MEDIUMCVSS 4.7EG 4.72023-05-12
Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin
- CVE-2023-25173MEDIUMCVSS 5.3EG 5.32023-02-16
containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and ma…
- CVE-2023-25185LOWCVSS 3.8EG 3.82023-06-16
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN software releases. Certain software processes in the BTS internal software design have un…
- CVE-2023-25189LOWCVSS 3.3EG 3.32024-09-25
BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a possibility to read BTS service operation details perform…
- CVE-2023-2534HIGHCVSS 7.6EG 7.62023-05-08
Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into overall system usage. User IDs can easily be correlated with re…
- CVE-2023-25415MEDIUMCVSS 5.3EG 5.32023-04-11
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Event Notification configuration.
- CVE-2023-25547HIGHCVSS 8.8EG 8.82023-04-18
A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution on upload and install packages when a hacker is using a low privileged user account. Affected products: StruxureWare Data Center Expert (V7.9.2…
- CVE-2023-25548HIGHCVSS 8.8EG 8.82023-04-18
A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE endpoints not being properly secured when a hacker is using a low privileged user. Affected products: StruxureWare Da…
- CVE-2023-25559HIGHCVSS 8.2EG 8.22023-02-11
DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the default configuration, the Metadata service (GMS) will use the X-DataHub-Actor HTTP header to infer the user the frontend is …
- CVE-2023-25575HIGHCVSS 7.7EG 7.72023-02-28
API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs. Resource properties secured with the `security` option of the `ApiPlatform\Metadata\ApiProperty` attribute can be disclosed to unauthorized users. The …
- CVE-2023-25594HIGHCVSS 6.3EG 8.82023-03-22
A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of…
- CVE-2023-25647MEDIUMCVSS 4.7EG 4.72023-08-17
There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.
- CVE-2023-25729HIGHCVSS 8.8EG 8.82023-06-02
Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them without user interaction via <code>ExpandedPrincipals</code>. This could lead to further mal…
- CVE-2023-25749MEDIUMCVSS 4.3EG 4.32023-06-02
Android applications with unpatched vulnerabilities can be launched from a browser using Intents, exposing users to these vulnerabilities. Firefox will now confirm with users that they want to launch an external application before doing so…
- CVE-2023-2576MEDIUMCVSS 4.3EG 4.32023-07-13
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. This allowed a developer to remove the CO…
- CVE-2023-25923HIGHCVSS 2.7EG 7.52023-03-21
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization. IBM X-Force ID: 247629.
- CVE-2023-25924HIGHCVSS 5.4EG 8.82023-03-22
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper authorization. IBM X-Force ID: 247630.
- CVE-2023-25946HIGHCVSS 8.8EG 8.82023-05-23
Authentication bypass vulnerability in Qrio Lock (Q-SL2) firmware version 2.0.9 and earlier allows a network-adjacent attacker to analyze the product's communication data and conduct an arbitrary operation under certain conditions.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →