CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,107 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 50 of 83
- CVE-2024-28394CRITICALCVSS 9.8EG 9.82024-03-19
An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & Export module.
- CVE-2024-28627HIGHCVSS 7.5EG 7.52024-04-23
An issue in Flipsnack v.18/03/2024 allows a local attacker to obtain sensitive information via the reader.gz.js file.
- CVE-2024-2915HIGHCVSS 8.8EG 8.82024-03-26
Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to elevate themselves to unauthorized groups via a specially crafted request.
- CVE-2024-29213HIGHCVSS 7.8EG 7.82024-10-18
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
- CVE-2024-29821HIGHCVSS 7.8EG 7.82024-10-18
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
- CVE-2024-29834MEDIUMCVSS 6.4EG 6.42024-04-02
This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering compaction. These management operations should be restricte…
- CVE-2024-29892MEDIUMCVSS 6.1EG 6.12024-03-27
ZITADEL, open source authentication management software, uses Go templates to render the login UI. Under certain circumstances an action could set reserved claims managed by ZITADEL. For example it would be possible to set the claim `urn:z…
- CVE-2024-30260LOWCVSS 3.9EG 3.92024-04-04
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 …
- CVE-2024-3033CRITICALCVSS 9.4EG 9.42024-06-06
An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-routes. This flaw allows unauthenticated users to perform destructive actions on the Vecto…
- CVE-2024-30616HIGHCVSS 8.8EG 8.82024-11-04
Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, posing a significant risk to data integrity.
- CVE-2024-31134MEDIUMCVSS 6.5EG 6.52024-03-28
In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled
- CVE-2024-3127MEDIUMCVSS 4.3EG 4.32024-08-22
An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to…
- CVE-2024-31402MEDIUMCVSS 4.3EG 4.32024-06-11
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete the data of Shared To-Dos.
- CVE-2024-31403MEDIUMCVSS 5.4EG 5.42024-06-11
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter and/or obtain the data of Memo.
- CVE-2024-31409MEDIUMCVSS 6.5EG 6.52024-05-15
Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the system after gaining access to any device.
- CVE-2024-31441HIGHCVSS 7.5EG 7.52024-05-14
DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data source, it is possible to exploit certain malicious parameters to achieve arbitrary file read…
- CVE-2024-31452HIGHCVSS 8.1EG 8.12024-04-16
OpenFGA is a high-performance and flexible authorization/permission engine. Some end users of OpenFGA v1.5.0 or later are vulnerable to authorization bypass when calling Check or ListObjects APIs. You are very likely affected if your model…
- CVE-2024-31682CRITICALCVSS 9.8EG 9.82024-06-03
Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint authentication due to the use of a deprecated API.
- CVE-2024-31695CRITICALCVSS 9.8EG 9.82024-11-14
A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attackers to bypass authentication when adding a new fingerprint.
- CVE-2024-31842HIGHCVSS 8.8EG 8.82024-08-20
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string for the URL could be saved in the browser's history, passed through Referers to o…
- CVE-2024-31970HIGHCVSS 8.8EG 8.82024-07-24
AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default, accessible both over the LAN and the Internet. During a window of time when the device is being set up, it uses a def…
- CVE-2024-31990MEDIUMCVSS 4.8EG 4.82024-04-15
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attackers to use the UI to edit resources which should only be mutable via gitops. This vulenra…
- CVE-2024-32470MEDIUMCVSS 6.5EG 6.52024-04-18
Tolgee is an open-source localization platform. When API key created by admin user is used it bypasses the permission check at all. This error was introduced in v3.57.2 and immediately fixed in v3.57.4.
- CVE-2024-32643HIGHCVSS 7.5EG 7.52025-12-03
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the page is modified to include a /tag/ declaration, the CMS will render the page regardless of group restrictions. This vu…
- CVE-2024-32983HIGHCVSS 8.2EG 8.22024-06-03
Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming signed ActivityPub activity objects before processing them, allowing threat actors to spoof th…
- CVE-2024-3331MEDIUMCVSS 6.8EG 6.82024-06-27
Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server allows The impact of this vulnerability dep…
- CVE-2024-3379CRITICALCVSS 8.1EG 9.62024-11-14
In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key for projects they do not have access to. Specifically, a user with a 'Member' role can issu…
- CVE-2024-3388MEDIUMCVSS 4.1EG 4.12024-04-10
A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the at…
- CVE-2024-3404MEDIUMCVSS 6.5EG 6.52024-06-06
In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. This flaw allows an authenticated attacker to bypass intended access restrictions and read …
- CVE-2024-34106MEDIUMCVSS 5.3EG 5.32024-06-13
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to gain unauthori…
- CVE-2024-34130MEDIUMCVSS 5.5EG 5.52024-06-13
Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could exploit this vulnerability to access confidential info…
- CVE-2024-34146MEDIUMCVSS 6.5EG 6.52024-05-02
Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing attackers with a previously configured SSH public key but lacking Overall/Read permission t…
- CVE-2024-34346HIGHCVSS 8.4EG 8.42024-05-07
Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may be unexpectedly weakened by allowing file read/write access to privileged files in various locations on Unix and Windows platforms. For ex…
- CVE-2024-34434MEDIUMCVSS 6.5EG 6.52024-05-17
Incorrect Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Inclusion, Functionality Misuse.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.2.
- CVE-2024-34642MEDIUMCVSS 4.6EG 4.62024-09-04
Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.
- CVE-2024-34650MEDIUMCVSS 4.0EG 4.02024-09-04
Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.
- CVE-2024-34651MEDIUMCVSS 6.2EG 6.22024-09-04
Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.
- CVE-2024-34652MEDIUMCVSS 4.0EG 4.02024-09-04
Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.
- CVE-2024-34701MEDIUMCVSS 5.9EG 5.92024-05-14
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users to be considered as the requester of a specific wiki request if their local user ID on any wiki in a wiki farm matches the local ID of t…
- CVE-2024-3504HIGHCVSS 6.5EG 8.12024-06-06
An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization user to the organization owner. This vulnerability allows the elevated user to delete projec…
- CVE-2024-3511MEDIUMCVSS 4.3EG 4.32025-06-23
An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console…
- CVE-2024-35187CRITICALCVSS 9.1EG 9.12024-05-16
Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execution as the stalwart-mail user (including web interface admins) can gain complete root access to the system. Usually, sy…
- CVE-2024-35353CRITICALCVSS 9.8EG 9.82024-05-30
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Users.php?f=save. Manipulating the argument id can result in improper authorization.
- CVE-2024-36037MEDIUMCVSS 5.5EG 5.52024-05-27
Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings.
- CVE-2024-36055MEDIUMCVSS 5.5EG 5.52024-05-26
Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory with read/write access via the MmMapIoSpace API (IOCTL 0x9c40a4f8, 0x9c40a4e8, 0x9c40a4c0, 0x9c40a4c4, 0x9c40a4ec, and…
- CVE-2024-36265CRITICALCVSS 9.8EG 9.82024-06-12
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. An attacker can bypass authentication by sending specially crafted REST r…
- CVE-2024-36364MEDIUMCVSS 6.5EG 6.52024-05-29
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible
- CVE-2024-36365MEDIUMCVSS 6.8EG 6.82024-05-29
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent
- CVE-2024-36376MEDIUMCVSS 6.5EG 6.52024-05-29
In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions
- CVE-2024-36377MEDIUMCVSS 6.5EG 6.52024-05-29
In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →