CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,107 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 41 of 83
- CVE-2023-26056MEDIUMCVSS 5.4EG 5.42023-03-02
XWiki Platform is a generic wiki platform. Starting in version 3.0-milestone-1, it's possible to execute a script with the right of another user, provided the target user does not have programming right. The problem has been patched in XWi…
- CVE-2023-26097HIGHCVSS 8.4EG 8.42023-04-24
An issue was discovered in Telindus Apsal 3.14.2022.235 b. Unauthorized actions that could modify the application behaviour may not be blocked.
- CVE-2023-26244HIGHCVSS 7.8EG 7.82023-04-27
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDMClient binary file, which is used during the firmware installation process, can be modified by an attacker to bypass th…
- CVE-2023-26245HIGHCVSS 7.8EG 7.82023-04-27
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is used during the firmware installation process, can be modified by an attacker to bypass the…
- CVE-2023-26246HIGHCVSS 7.8EG 7.82023-04-27
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is used during the firmware installation process, can be modified by an attacker to bypass the…
- CVE-2023-26258CRITICALCVSS 9.8EG 9.82023-07-03
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obt…
- CVE-2023-2640HIGHCVSS 7.8EG 7.82023-07-26
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set …
- CVE-2023-26484HIGHCVSS 8.2EG 8.22023-03-15
KubeVirt is a virtual machine management add-on for Kubernetes. In versions 0.59.0 and prior, if a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account c…
- CVE-2023-26818MEDIUMCVSS 5.5EG 5.52023-05-19
Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT_LIBRARIES flag.
- CVE-2023-26829CRITICALCVSS 9.8EG 9.82023-03-31
An authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows remote attackers to set a new password for any valid user account, without needing the previous known password, resultin…
- CVE-2023-27107HIGHCVSS 8.8EG 8.82023-04-26
Incorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server before 8.2 Patch 22 allows users who do not have appropriate access rights to generate internal reports using a direct U…
- CVE-2023-27384MEDIUMCVSS 4.3EG 4.32023-05-23
Operation restriction bypass vulnerability in MultiReport of Cybozu Garoon 5.15.0 allows a remote authenticated attacker to alter the data of MultiReport.
- CVE-2023-27388CRITICALCVSS 9.8EG 9.82023-05-23
Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user. Affected products and versions are as follows: T&D Cor…
- CVE-2023-27485MEDIUMCVSS 4.3EG 4.32023-03-07
thmmniii/fbs-core is an open source feedback system for students. In versions prior to 1.5.3 when querying `subresults`, it is possible to query `subresults` from other users due to insufficient authorisation. This is only possible for log…
- CVE-2023-27486HIGHCVSS 8.1EG 8.12023-03-08
xCAT is a toolkit for deployment and administration of computer clusters. In versions prior to 2.16.5 if zones are configured as a mechanism to secure clusters in XCAT, it is possible for a local root user from one node to obtain credentia…
- CVE-2023-27523MEDIUMCVSS 5.0EG 5.02023-09-06
Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to.
- CVE-2023-27525MEDIUMCVSS 3.1EG 4.32023-04-17
An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1
- CVE-2023-27526MEDIUMCVSS 4.3EG 4.32023-09-06
A non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset up to and including 2.1.0.
- CVE-2023-27578CRITICALCVSS 9.1EG 9.12023-03-20
Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an insufficient permission check. Unsupported versions are likely affected as far back as th…
- CVE-2023-2759HIGHCVSS 8.8EG 8.82023-07-17
A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user to change passwords of other users without any prior knowledge. The attacker may gain full access to the device by using…
- CVE-2023-27594MEDIUMCVSS 4.2EG 4.22023-03-17
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.11.15, 1.12.8, and 1.13.1, under specific conditions, Cilium may misattribute the source IP address of traffic to a cluster, ide…
- CVE-2023-27716CRITICALCVSS 9.8EG 9.82023-06-12
An issue was discovered in freakchicken kafkaUI-lite 1.2.11 allows attackers on the same network to gain escalated privileges for the nodes running on it.
- CVE-2023-2782MEDIUMCVSS 5.5EG 5.52023-05-18
Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.3.1-38.
- CVE-2023-27899HIGHCVSS 7.0EG 7.02023-03-10
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers wi…
- CVE-2023-27903MEDIUMCVSS 4.4EG 4.42023-03-10
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a file parameter through the CLI, potentially allowing attac…
- CVE-2023-27920MEDIUMCVSS 4.3EG 4.32023-05-23
Improper access control vulnerability in the system date/time setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to alter system dat…
- CVE-2023-27951MEDIUMCVSS 5.5EG 5.52023-05-08
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An archive may be able to bypass Gatekeeper.
- CVE-2023-27954MEDIUMCVSS 6.5EG 6.52023-05-08
The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4, watchOS 9.4. A website may be able to track sensitive user i…
- CVE-2023-28175HIGHCVSS 7.1EG 7.12023-06-15
Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted internal network via a port forwarding request.
- CVE-2023-28249MEDIUMCVSS 6.2EG 6.22023-04-11
Windows Boot Manager Security Feature Bypass Vulnerability
- CVE-2023-28270MEDIUMCVSS 6.8EG 6.82023-04-11
Windows Lock Screen Security Feature Bypass Vulnerability
- CVE-2023-28325MEDIUMCVSS 6.5EG 6.52023-05-11
An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit message in the target roo…
- CVE-2023-28352HIGHCVSS 7.4EG 7.42023-05-31
An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system, an attacker-controlled artificial Student Console can connect to and attack a Teacher Console even after Enhanced Sec…
- CVE-2023-28357MEDIUMCVSS 4.3EG 4.32023-05-11
A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking whether a user is a member of a given channel, leaking private channel members to unauthorized users. This allows auth…
- CVE-2023-28468MEDIUMCVSS 6.5EG 6.52023-08-03
An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntimeDxe SMM module exposes an SMI handler that allows an attacker to interact with the SPI flash at run-time from the OS.
- CVE-2023-28611CRITICALCVSS 9.8EG 9.82023-03-23
Incorrect authorization in OMICRON StationGuard 1.10 through 2.20 and StationScout 1.30 through 2.20 allows an attacker to bypass intended access restrictions.
- CVE-2023-28634HIGHCVSS 8.8EG 8.82023-04-05
GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, a user who has the Technician profile could see and generate a Personal token for a Super-Admin. Using such token it…
- CVE-2023-28635MEDIUMCVSS 5.4EG 5.42023-10-11
vantage6 is privacy preserving federated learning infrastructure. Prior to version 4.0.0, malicious users may try to get access to resources they are not allowed to see, by creating resources with integers as names. One example where this …
- CVE-2023-28698CRITICALCVSS 9.8EG 9.82023-06-02
Wade Graphic Design FANTSY has a vulnerability of insufficient authorization check. An unauthenticated remote user can exploit this vulnerability by modifying URL parameters to gain administrator privileges to perform arbitrary system oper…
- CVE-2023-28714HIGHCVSS 8.2EG 8.22023-08-11
Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2023-2877HIGHCVSS 8.8EG 8.82023-06-27
The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate a…
- CVE-2023-29240MEDIUMCVSS 5.4EG 5.42023-05-03
An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2023-29288MEDIUMCVSS 4.3EG 4.32023-06-15
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A privileged attacker could leverage th…
- CVE-2023-29295MEDIUMCVSS 4.3EG 4.32023-06-15
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverag…
- CVE-2023-29296MEDIUMCVSS 4.3EG 4.32023-06-15
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverag…
- CVE-2023-29381CRITICALCVSS 9.8EG 9.82023-07-06
An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information via the password and 2FA parameters.
- CVE-2023-29484MEDIUMCVSS 6.5EG 6.52023-10-16
In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password.
- CVE-2023-29656MEDIUMCVSS 6.1EG 6.12023-07-06
An improper authorization vulnerability in Darktrace mobile app (Android) prior to version 6.0.15 allows disabled and low-privilege users to control "antigena" actions(block/unblock traffic) from the mobile application. This vulnerability …
- CVE-2023-29708HIGHCVSS 7.5EG 7.52023-06-22
An issue was discovered in /cgi-bin/adm.cgi in WavLink WavRouter version RPT70HA1.x, allows attackers to force a factory reset via crafted payload.
- CVE-2023-29752HIGHCVSS 7.8EG 7.82023-06-09
An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →