CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (4,257)
page 111 of 213| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-41189 | Hig | 0.40 | 7.2 | 0.02 | Oct 29, 2021 | DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can escalate their permission up to become system administrator. This vulnerability only exists in 7.0 and does not impact 6.x or below. This issue is patched in… | ||
| CVE-2021-3457 | Med | 0.40 | 6.1 | 0.00 | May 12, 2021 | An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources… | ||
| CVE-2021-21367 | Med | 0.40 | 6.1 | 0.01 | Mar 12, 2021 | Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When the Bluetooth plug is running (in discoverable mode), Bluetooth service requests and pairing requests are automatically accepted,… | ||
| CVE-2019-11724 | Med | 0.40 | 6.1 | 0.01 | Jul 23, 2019 | Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. This additional permission is unnecessary and is a potential vector for malicious attacks. This vulnerability… | ||
| CVE-2026-43976 | Hig | 0.39 | 7.1 | — | Oct 7, 2026 | wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym_a != gym_b`) that silently passes when both operands are `None`. A trainer with `gym.gym_trainer` and `gym.add_adminusernote`… | ||
| CVE-2026-102335 | Hig | 0.39 | 7.1 | 0.00 | Sep 28, 2026 | Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary… | ||
| CVE-2026-100392 | Hig | 0.39 | — | 0.00 | Sep 28, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Secondary Administrator (user_type = 1, user_id != 1) can rewrite the Primary… | ||
| CVE-2026-57449 | Hig | 0.39 | — | 0.00 | Sep 25, 2026 | Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authenticated users fetch resources only from repositories listed in the official plugin allowlist. When `ACTUAL_GITHUB_TOKEN` is configured, the proxy… | ||
| CVE-2026-61672 | Hig | 0.39 | 7.1 | 0.00 | Sep 18, 2026 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which assumes byte-order sorting. When an… | ||
| CVE-2026-59965 | Hig | 0.39 | 7.1 | 0.00 | Sep 15, 2026 | Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard that accepts any authenticated user, while… | ||
| CVE-2026-19816 | Hig | 0.39 | 7.1 | 0.00 | Sep 14, 2026 | A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role… | ||
| CVE-2026-78134 | Hig | 0.39 | 7.1 | 0.00 | Sep 11, 2026 | strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity. | ||
| CVE-2026-87803 | Hig | 0.39 | 7.1 | 0.00 | Sep 10, 2026 | An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed sub-pipeline detection in the aggregation stage sanitizer. The /o/db aggregation endpoint parses user-controlled aggregation JSON and passes it through a stage sanitizer that determines… | ||
| CVE-2026-87998 | Hig | 0.39 | 7.1 | 0.00 | Sep 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/knowledge/{id}/delete in backend/open_webui/routers/knowledge.py authorized deletion against the knowledge base but then removed its administrator-owned… | ||
| CVE-2026-80223 | Hig | 0.39 | — | 0.00 | Aug 30, 2026 | Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive another tenant's records over GraphQL subscriptions. The subscription resolver in AshGraphql.Graphql.Resolver authorizes each notification payload in… | ||
| CVE-2026-77611 | Hig | 0.39 | 7.1 | 0.00 | Aug 26, 2026 | SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal with permissions scoped to a nested object key can overwrite a different object outside that scope by calling PutObjectAcl on the key it is allowed to access.… | ||
| CVE-2026-66003 | Hig | 0.39 | — | 0.00 | Aug 26, 2026 | Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access control bypass in the REST API allows a user to read data from Linked DocTypes that they are not authorized to access. When a document references another… | ||
| CVE-2026-17183 | Hig | 0.39 | 7.1 | 0.00 | Aug 19, 2026 | An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through… | ||
| CVE-2026-18674 | Hig | 0.39 | — | 0.01 | Aug 17, 2026 | On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone identity derived from the connection. Authenticated zones can have the global… | ||
| CVE-2026-49989 | Hig | 0.39 | — | 0.00 | Aug 14, 2026 | CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they know, and can plant new blobs unconditionally, in any blob table, regardless of `GRANT`s. CrateDB has two ways to access blob… |
- risk 0.40cvss 7.2epss 0.02
DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can escalate their permission up to become system administrator. This vulnerability only exists in 7.0 and does not impact 6.x or below. This issue is patched in…
- risk 0.40cvss 6.1epss 0.00
An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources…
- risk 0.40cvss 6.1epss 0.01
Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When the Bluetooth plug is running (in discoverable mode), Bluetooth service requests and pairing requests are automatically accepted,…
- risk 0.40cvss 6.1epss 0.01
Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. This additional permission is unnecessary and is a potential vector for malicious attacks. This vulnerability…
- risk 0.39cvss 7.1epss —
wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym_a != gym_b`) that silently passes when both operands are `None`. A trainer with `gym.gym_trainer` and `gym.add_adminusernote`…
- risk 0.39cvss 7.1epss 0.00
Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary…
- risk 0.39cvss —epss 0.00
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Secondary Administrator (user_type = 1, user_id != 1) can rewrite the Primary…
- risk 0.39cvss —epss 0.00
Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authenticated users fetch resources only from repositories listed in the official plugin allowlist. When `ACTUAL_GITHUB_TOKEN` is configured, the proxy…
- risk 0.39cvss 7.1epss 0.00
Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which assumes byte-order sorting. When an…
- risk 0.39cvss 7.1epss 0.00
Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard that accepts any authenticated user, while…
- risk 0.39cvss 7.1epss 0.00
A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role…
- risk 0.39cvss 7.1epss 0.00
strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.
- risk 0.39cvss 7.1epss 0.00
An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed sub-pipeline detection in the aggregation stage sanitizer. The /o/db aggregation endpoint parses user-controlled aggregation JSON and passes it through a stage sanitizer that determines…
- risk 0.39cvss 7.1epss 0.00
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/knowledge/{id}/delete in backend/open_webui/routers/knowledge.py authorized deletion against the knowledge base but then removed its administrator-owned…
- risk 0.39cvss —epss 0.00
Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive another tenant's records over GraphQL subscriptions. The subscription resolver in AshGraphql.Graphql.Resolver authorizes each notification payload in…
- risk 0.39cvss 7.1epss 0.00
SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal with permissions scoped to a nested object key can overwrite a different object outside that scope by calling PutObjectAcl on the key it is allowed to access.…
- risk 0.39cvss —epss 0.00
Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access control bypass in the REST API allows a user to read data from Linked DocTypes that they are not authorized to access. When a document references another…
- risk 0.39cvss 7.1epss 0.00
An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through…
- risk 0.39cvss —epss 0.01
On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone identity derived from the connection. Authenticated zones can have the global…
- risk 0.39cvss —epss 0.00
CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they know, and can plant new blobs unconditionally, in any blob table, regardless of `GRANT`s. CrateDB has two ways to access blob…