CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,107 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 45 of 83
- CVE-2023-42541MEDIUMCVSS 5.3EG 5.32023-11-07
Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id.
- CVE-2023-42553MEDIUMCVSS 5.3EG 5.32023-11-07
Improper authorization verification vulnerability in Samsung Email prior to version 6.1.90.4 allows attackers to read sandbox data of email.
- CVE-2023-42569MEDIUMCVSS 3.3EG 4.02023-12-05
Improper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows attackers to read sandbox data of AR Emoji.
- CVE-2023-42575MEDIUMCVSS 6.8EG 6.82023-12-05
Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid flag setting.
- CVE-2023-4269MEDIUMCVSS 4.3EG 4.32023-09-04
The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowing any authenticated users, such as subscriber to perform such action and retrieve PII such as email addresses.
- CVE-2023-42860HIGHCVSS 5.5EG 7.72024-02-21
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to modify protected parts of the file system.
- CVE-2023-43119CRITICALCVSS 9.8EG 9.82023-10-16
An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain escalated privileges using crafted telnet commands via Redis server.
- CVE-2023-4317MEDIUMCVSS 4.3EG 4.32023-12-01
An issue has been discovered in GitLab affecting all versions starting from 9.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a user with the Developer role…
- CVE-2023-43508MEDIUMCVSS 6.5EG 6.52023-10-25
Vulnerabilities in the web-based management interface of ClearPass Policy Manager allow an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of…
- CVE-2023-43609MEDIUMCVSS 6.9EG 6.92024-02-09
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive information or cause a denial-of-service condition.
- CVE-2023-4379HIGHCVSS 7.5EG 8.12023-11-09
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.
- CVE-2023-43961HIGHCVSS 8.8EG 8.82023-10-25
An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
- CVE-2023-44154HIGHCVSS 8.1EG 8.12023-09-27
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
- CVE-2023-44401MEDIUMCVSS 5.3EG 5.32024-01-23
The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks are bypassed for ORM data in paginated GraphQL query results wh…
- CVE-2023-44860HIGHCVSS 7.5EG 7.52023-10-06
An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization component in the HTTP request.
- CVE-2023-45185HIGHCVSS 8.8EG 8.82023-12-14
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper authority checks the attacker could perform operations on the PC under the user's authority. IB…
- CVE-2023-4532MEDIUMCVSS 4.3EG 4.32023-09-29
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. Users were capable of linking CI/CD jobs of priva…
- CVE-2023-45626HIGHCVSS 7.2EG 7.22023-11-14
An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code execution across boot cycles.
- CVE-2023-45793MEDIUMCVSS 5.5EG 5.52024-03-12
A vulnerability has been identified in Siveillance Control (All versions >= V2.8 < V3.1.1). The affected product does not properly check the list of access groups that are assigned to an individual user. This could enable a locally logged …
- CVE-2023-45899HIGHCVSS 7.5EG 7.52023-10-31
An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attackers to bypass authentication via a crafted HTTP call.
- CVE-2023-46125MEDIUMCVSS 6.5EG 6.52023-10-25
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in code. The Fides webserver API allows users to retrieve its c…
- CVE-2023-46139MEDIUMCVSS 5.7EG 5.72023-10-31
KernelSU is a Kernel based root solution for Android. Starting in version 0.6.1 and prior to version 0.7.0, if a KernelSU installed device is infected with a malware whose app signing block specially constructed, it can take over root priv…
- CVE-2023-4617CRITICALCVSS 10.0EG 10.02024-12-19
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values. This issue affe…
- CVE-2023-46241CRITICALCVSS 9.0EG 9.02024-02-21
`discourse-microsoft-auth` is a plugin that enables authentication via Microsoft. On sites with the `discourse-microsoft-auth` plugin enabled, an attack can potentially take control of a victim's Discourse account. Sites that have configur…
- CVE-2023-46244HIGHCVSS 8.8EG 8.82023-11-07
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to write a script in which any velocity content is executed with the right of any other …
- CVE-2023-4658LOWCVSS 3.1EG 3.12023-12-01
An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `…
- CVE-2023-46753HIGHCVSS 5.9EG 7.52023-10-26
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
- CVE-2023-46754MEDIUMCVSS 5.3EG 5.32023-10-26
The admin panel for Obl.ong before 1.1.2 allows authorization bypass because the email OTP feature accepts arbitrary numerical values.
- CVE-2023-46906MEDIUMCVSS 4.9EG 4.92024-01-09
juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status code. The payload in the timezone field was not correctly validated.
- CVE-2023-46992HIGHCVSS 7.5EG 7.52023-10-31
TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without authentication by visiting specific pages.
- CVE-2023-47037MEDIUMCVSS 4.3EG 4.32023-11-12
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then. Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DA…
- CVE-2023-47090MEDIUMCVSS 6.5EG 6.52023-10-30
NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each…
- CVE-2023-47142HIGHCVSS 7.5EG 7.52024-02-02
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate their privileges due to unauthorized API access. IBM X-Force ID: 270267.
- CVE-2023-47320HIGHCVSS 8.1EG 8.12023-12-13
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes t…
- CVE-2023-47716MEDIUMCVSS 6.3EG 6.32024-03-01
IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges of another user under unusual circumstances. IBM X-Force ID: 271656.
- CVE-2023-47827HIGHCVSS 7.5EG 7.52023-11-30
Incorrect Authorization vulnerability in NicheAddons Events Addon for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Events Addon for Elementor: from n/a through 2.1.3.
- CVE-2023-4812HIGHCVSS 7.6EG 7.62024-01-12
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypa…
- CVE-2023-4814HIGHCVSS 7.1EG 7.12023-09-14
A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for which the user does not have permission to.
- CVE-2023-48218MEDIUMCVSS 5.3EG 5.32023-11-20
The Strapi Protected Populate Plugin protects `get` endpoints from revealing too much information. Prior to version 1.3.4, users were able to bypass the field level security. Users who tried to populate something that they didn't have acce…
- CVE-2023-48227MEDIUMCVSS 4.3EG 4.32023-12-12
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.3.0, Backoffice users with send for approval permission but not publish permission are able to publish in some s…
- CVE-2023-48309MEDIUMCVSS 5.3EG 5.32023-11-20
NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the default Middleware authorization are affected by a vulnerability. A bad actor could create an empty/mock user, by getting ho…
- CVE-2023-4853HIGHCVSS 8.1EG 8.12023-09-20
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass th…
- CVE-2023-48712HIGHCVSS 8.8EG 8.82023-11-24
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. In affected versions there is a privilege escalation vulnerability through a non-admin user's account. Limited users can impersonate another user's account if only sin…
- CVE-2023-48859HIGHCVSS 8.8EG 8.82023-12-06
TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end security restrictions and execute arbitrary code.
- CVE-2023-49239HIGHCVSS 7.5EG 7.52023-12-06
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-49240HIGHCVSS 7.5EG 7.52023-12-06
Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-49246HIGHCVSS 7.5EG 7.52023-12-06
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-49273MEDIUMCVSS 5.4EG 5.42023-12-12
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, users with low privileges (Editor, etc.) are able to access some unintended endpoints. Versions 8.18.10, 10…
- CVE-2023-49734MEDIUMCVSS 6.5EG 6.52023-12-19
An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the charts allowing him to incorrectly have write permissions to these charts.This issue affe…
- CVE-2023-49783MEDIUMCVSS 4.3EG 4.32024-01-23
Silverstripe Admin provides a basic management interface for the Silverstripe Framework. In versions on the 1.x branch prior to 1.13.19 and on the 2.x branch prior to 2.1.8, users who don't have edit or delete permissions for records expos…
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →