CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,108 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 53 of 83
- CVE-2024-46918CRITICALCVSS 4.9EG 9.82024-09-15
app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.
- CVE-2024-47025MEDIUMCVSS 5.5EG 5.52024-10-25
In ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo…
- CVE-2024-47060MEDIUMCVSS 4.3EG 4.32024-09-20
Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associated projects, respectively their applications remain active. Users across other organizations can still log in and access…
- CVE-2024-47077MEDIUMCVSS 6.5EG 6.52024-09-27
authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to impersonate the user against any other proxy provider. Also, a us…
- CVE-2024-47078HIGHCVSS 8.1EG 8.12024-09-25
Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. Nodes can communicate directly via an internet connection or proxied t…
- CVE-2024-47102MEDIUMCVSS 5.5EG 5.52024-12-25
IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.
- CVE-2024-47148MEDIUMCVSS 4.0EG 4.02024-12-26
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
- CVE-2024-47157LOWCVSS 2.9EG 2.92024-12-26
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
- CVE-2024-47159MEDIUMCVSS 4.3EG 4.32024-09-19
In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project
- CVE-2024-47160MEDIUMCVSS 4.3EG 4.32024-09-19
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
- CVE-2024-47172MEDIUMCVSS 5.4EG 5.42024-09-30
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account may retrieve certain information about any project, task, job or membership resource on the CVAT …
- CVE-2024-47183HIGHCVSS 8.1EG 8.12024-10-04
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId: true is set, an attacker that is allowed to create a new user can set a custom object I…
- CVE-2024-47272LOWCVSS 2.7EG 2.72026-05-27
Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vecto…
- CVE-2024-47560HIGHCVSS 7.8EG 7.82024-10-01
RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is exploited, unintended processes may be executed in the sandbox environment. Even if malware is executed in the sandbox en…
- CVE-2024-47616MEDIUMCVSS 6.8EG 6.82024-10-02
Pomerium is an identity and context-aware access proxy. The Pomerium databroker service is responsible for managing all persistent Pomerium application state. Requests to the databroker service API are authorized by the presence of a JSON …
- CVE-2024-47780LOWCVSS 3.1EG 3.12024-10-08
TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/group, or if no mounts were configured but …
- CVE-2024-47876HIGHCVSS 8.8EG 8.82024-10-15
Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in as a normal user. This can result in illegal access being granted to the system. Vers…
- CVE-2024-4811LOWCVSS 2.2EG 2.22024-07-25
In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts.
- CVE-2024-48176CRITICALCVSS 9.8EG 9.82024-11-05
Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and passwor…
- CVE-2024-48237CRITICALCVSS 9.8EG 9.82024-10-25
WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.
- CVE-2024-48540MEDIUMCVSS 6.2EG 6.22024-10-24
Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code and data within the APK file.
- CVE-2024-48541HIGHCVSS 8.4EG 8.42024-10-24
Incorrect access control in the firmware update and download processes of Ruochan Smart v4.4.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.
- CVE-2024-48542HIGHCVSS 8.4EG 8.42024-10-24
Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.
- CVE-2024-48544HIGHCVSS 8.4EG 8.42024-10-24
Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to access sensitive information by analyzing the code and data within the APK file.
- CVE-2024-48545HIGHCVSS 8.4EG 8.42024-10-24
Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.
- CVE-2024-48546HIGHCVSS 8.4EG 8.42024-10-24
Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.
- CVE-2024-48547HIGHCVSS 8.4EG 8.42024-10-24
Incorrect access control in the firmware update and download processes of DreamCatcher Life v1.8.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.
- CVE-2024-48548CRITICALCVSS 9.3EG 9.32024-10-24
The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulnerability allows attackers to arbitrarily construct a request to use the app to bind to unknown devices by finding a val…
- CVE-2024-48651HIGHCVSS 7.5EG 7.52024-11-29
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.
- CVE-2024-48769CRITICALCVSS 9.1EG 9.12024-10-11
An issue in BURG-WCHTER KG de.burgwachter.keyapp.app 4.5.0 allows a remote attacker to obtain sensitve information via the firmware update process.
- CVE-2024-48772CRITICALCVSS 9.1EG 9.12024-10-11
An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firmware update process.
- CVE-2024-48778CRITICALCVSS 9.1EG 9.12024-10-11
An issue in GIANT MANUFACTURING CO., LTD RideLink (tw.giant.ridelink) 2.0.7 allows a remote attacker to obtain sensitive information via the firmware update process.
- CVE-2024-48784CRITICALCVSS 9.8EG 9.82024-10-11
An Incorrect Access Control issue in SAMPMAX com.sampmax.homemax 2.1.2.7 allows a remote attacker to obtain sensitive information via the firmware update process.
- CVE-2024-48786CRITICALCVSS 9.1EG 9.12024-10-11
An issue in SWITCHBOT INC SwitchBot (com.theswitchbot.switchbot) 5.0.4 allows a remote attacker to obtain sensitive information via the firmware update process.
- CVE-2024-48787CRITICALCVSS 9.1EG 9.12024-10-11
An issue in Revic Optics Revic Ops (us.revic.revicops) 1.12.5 allows a remote attacker to obtain sensitive information via the firmware update process.
- CVE-2024-48792HIGHCVSS 7.5EG 7.52024-10-14
An issue in Hideez com.hideez 2.7.8.3 allows a remote attacker to obtain sensitive information via the firmware update process.
- CVE-2024-48897MEDIUMCVSS 4.3EG 4.32024-11-18
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.
- CVE-2024-48901MEDIUMCVSS 4.3EG 4.32024-11-18
A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.
- CVE-2024-48911HIGHCVSS 7.8EG 7.82024-10-14
OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0.9.4, where the config file is stored in an unprivileged user directory but the daemon is executed by root, it’s poss…
- CVE-2024-48921LOWCVSS 2.7EG 2.72024-10-29
Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can be overridden by the creation of a PolicyException in a random namespace. By design, PolicyExceptions are consumed from …
- CVE-2024-48925UnratedEG 0.02024-10-22
Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version 14.3.0. The issue allows low-privilege users to access the webhook API and retrieve inform…
- CVE-2024-48936MEDIUMCVSS 5.0EG 5.02024-10-28
SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or …
- CVE-2024-49208MEDIUMCVSS 5.9EG 5.92024-10-22
Archer Platform 2024.03 before version 2024.08 is affected by an authorization bypass vulnerability related to supporting application files. A remote unprivileged attacker could potentially exploit this vulnerability to elevate their privi…
- CVE-2024-49209MEDIUMCVSS 6.5EG 6.52024-10-22
Archer Platform 2024.03 before version 2024.09 is affected by an API authorization bypass vulnerability related to supporting application files. A remote unprivileged attacker could potentially exploit this vulnerability to elevate their p…
- CVE-2024-49256MEDIUMCVSS 5.4EG 5.42024-11-01
Incorrect Authorization vulnerability in WP Chill Htaccess File Editor htaccess-file-editor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Htaccess File Editor: from n/a through <= 1.0.18.
- CVE-2024-49376HIGHCVSS 8.8EG 8.82024-10-25
Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0. For email-based accounts, users with insufficient privileges could reset and theoreticall…
- CVE-2024-49501MEDIUMCVSS 5.7EG 5.72024-11-01
Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may access the program which is protected by Data Protection function.
- CVE-2024-49808MEDIUMCVSS 6.3EG 6.32025-04-18
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions.
- CVE-2024-50310HIGHCVSS 7.5EG 7.52024-11-12
A vulnerability has been identified in SIMATIC CP 1543-1 V4.0 (6GK7543-1AX10-0XE0) (All versions >= V4.0.44 < V4.0.50). Affected devices do not properly handle authorization. This could allow an unauthenticated remote attacker to gain acce…
- CVE-2024-50419MEDIUMCVSS 5.4EG 5.42024-10-30
Incorrect Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Greenshift: from n/a through <= 9.7.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →