CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,107 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 49 of 83
- CVE-2024-23255CRITICALCVSS 2.4EG 9.12024-03-08
An authentication issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Photos in the Hidden Photos Album may be viewed without authentication.
- CVE-2024-23262LOWCVSS 3.3EG 3.32024-03-08
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, visionOS 1.1. An app may be able to spoof system notifications and UI.
- CVE-2024-23329LOWCVSS 3.7EG 3.72024-01-19
changedetection.io is an open source tool designed to monitor websites for content changes. In affected versions the API endpoint `/api/v1/watch/<uuid>/history` can be accessed by any unauthorized user. As a result any unauthorized user c…
- CVE-2024-23451MEDIUMCVSS 4.4EG 4.42024-03-27
Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.10.0 and before 8.13.0. This allows a malicious user with a valid API key for a remote cl…
- CVE-2024-23629CRITICALCVSS 9.6EG 9.62024-01-26
An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve sensitive information.
- CVE-2024-23653CRITICALCVSS 9.8EG 9.82024-01-31
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based o…
- CVE-2024-23669HIGHCVSS 8.8EG 8.82024-06-05
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands vi…
- CVE-2024-23675MEDIUMCVSS 6.5EG 6.52024-01-22
In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST application programming interface (API). This can potentially result in the deletion of K…
- CVE-2024-2378HIGHCVSS 8.0EG 8.02024-04-30
A vulnerability exists in the web-authentication component of the SDM600. If exploited an attacker could escalate privileges on af-fected installations.
- CVE-2024-23823MEDIUMCVSS 4.2EG 4.22024-03-14
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. The vantage6 server has no restrictions on CORS settings. It should be possible for…
- CVE-2024-23833HIGHCVSS 7.5EG 7.52024-02-12
OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=3.7.7) where an attacker may construct a JDBC query which may read files on the host files…
- CVE-2024-23921HIGHCVSS 8.8EG 8.82025-01-31
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists wi…
- CVE-2024-23928HIGHCVSS 6.5EG 8.12025-01-31
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability. The speci…
- CVE-2024-23929HIGHCVSS 7.3EG 8.02025-01-31
This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Pioneer DMH-WT7600NEX devices. Although authentication is required to exploit this vulnerability, the existing authentication mecha…
- CVE-2024-23937MEDIUMCVSS 4.3EG 6.52025-01-31
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the d…
- CVE-2024-23963HIGHCVSS 8.0EG 8.82025-01-31
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in orde…
- CVE-2024-24573HIGHCVSS 8.8EG 8.82024-01-31
facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, when a user updates their profile, a POST request containing user information is sent to the endpoint server/fm-modules/facileMana…
- CVE-2024-2473MEDIUMCVSS 5.3EG 5.32024-06-11
The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parameter is supplied. This makes it possible…
- CVE-2024-24751MEDIUMCVSS 4.3EG 4.32024-02-13
sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check for events in the backend module got broken during the update of the extens…
- CVE-2024-24761HIGHCVSS 7.5EG 7.52024-03-06
Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to version 1.0.2, public pages are per default restricted to only administrators and staff members. From configuration, it…
- CVE-2024-24773MEDIUMCVSS 4.9EG 4.92024-02-28
Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to …
- CVE-2024-24774LOWCVSS 3.4EG 3.42024-02-09
Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the subscription resulting in registered users on Jira being able to create webhooks that give …
- CVE-2024-24779MEDIUMCVSS 5.0EG 5.02024-02-28
Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets…
- CVE-2024-24824HIGHCVSS 8.8EG 8.82024-02-07
Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the `/api/system/cluster_config/` endpoint. …
- CVE-2024-24966MEDIUMCVSS 6.2EG 6.22024-02-14
When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2024-25108CRITICALCVSS 9.9EG 9.92024-02-12
Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative a…
- CVE-2024-25149MEDIUMCVSS 5.4EG 5.42024-02-20
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not properly restrict membership of a child site when the "Limit mem…
- CVE-2024-25170CRITICALCVSS 9.1EG 9.12024-02-28
An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.
- CVE-2024-2557MEDIUMCVSS 5.3EG 5.32024-03-17
A vulnerability was found in kishor-23 Food Waste Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/admin.php. The manipulation leads to improper authorization. The attack c…
- CVE-2024-25604MEDIUMCVSS 6.5EG 6.52024-02-20
Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions does not properly check user permissions, which allows remote a…
- CVE-2024-25652CRITICALCVSS 7.6EG 9.82024-03-14
In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access…
- CVE-2024-26016MEDIUMCVSS 4.3EG 4.32024-02-28
A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby gaining ownership of the object. However, it's important to note that access to the analyt…
- CVE-2024-26145MEDIUMCVSS 6.5EG 6.52024-02-21
Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited users are able to gain access to private events by crafting a request to update their attendance. This problem is resolve…
- CVE-2024-2698HIGHCVSS 8.8EG 8.82024-06-12
A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fixing this mistake required adding a special case for the ch…
- CVE-2024-27086LOWCVSS 3.9EG 3.92024-04-16
The MSAL library enabled acquisition of security tokens to call protected APIs. MSAL.NET applications targeting Xamarin Android and .NET Android (e.g., MAUI) using the library from versions 4.48.0 to 4.60.0 are impacted by a low severity v…
- CVE-2024-27105HIGHCVSS 8.1EG 8.12024-03-21
Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed using certain endpoints, granting less privileged users permission to delete or clone a file. Versions 14.66.3 and 15.…
- CVE-2024-27138HIGHCVSS 7.5EG 7.52024-03-01
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, however this restriction can be bypassed. As Apache Archiva has been retired, we do not ex…
- CVE-2024-27139HIGHCVSS 7.5EG 7.52024-03-01
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated attacker to modify account data, potentially leading to account takeover. This issue aff…
- CVE-2024-27288MEDIUMCVSS 6.3EG 6.32024-03-06
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can use Burp to obtain unauthorized access to the console page. The vulnerability has been fixed in v1.10.1-lts. There are…
- CVE-2024-27309HIGHCVSS 7.4EG 7.42024-04-12
While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditions are needed to trigger the bug: 1. The administrator decides to remove an ACL 2. The re…
- CVE-2024-27312HIGHCVSS 8.1EG 8.12024-05-20
Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. Note: This vulnerability affects only the PAM360 6600 version. No other versions are appli…
- CVE-2024-2743MEDIUMCVSS 5.3EG 5.32024-09-12
An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables.
- CVE-2024-27798HIGHCVSS 7.8EG 7.82024-05-14
An authorization issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An attacker may be able to elevate privileges.
- CVE-2024-27848HIGHCVSS 7.8EG 7.82024-06-10
This issue was addressed with improved permissions checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. A malicious app may be able to gain root privileges.
- CVE-2024-27915MEDIUMCVSS 6.8EG 6.82024-03-06
Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to pages is granted regardless of role permissions for webspaces which have a security system configured and permission check …
- CVE-2024-27933HIGHCVSS 8.2EG 8.22024-03-21
Deno is a JavaScript, TypeScript, and WebAssembly runtime. In version 1.39.0, use of raw file descriptors in `op_node_ipc_pipe()` leads to premature close of arbitrary file descriptors, allowing standard input to be re-opened as a differen…
- CVE-2024-28098MEDIUMCVSS 6.4EG 6.42024-03-12
The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings. These management operations should be restricted to users with the tenan…
- CVE-2024-28148MEDIUMCVSS 4.3EG 4.32024-05-07
An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to versi…
- CVE-2024-28174MEDIUMCVSS 5.8EG 5.82024-03-06
In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly
- CVE-2024-28229MEDIUMCVSS 6.5EG 6.52024-03-07
In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →