CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (3,735)
page 15 of 187| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-26040 | Cri | 0.59 | 9.1 | 0.01 | Aug 24, 2021 | An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command. | ||
| CVE-2021-20538 | Cri | 0.59 | 9.1 | 0.01 | May 10, 2021 | IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have access to due to incorrect authorization mechanisms. IBM X-Force ID: 198919. | ||
| CVE-2020-29020 | Cri | 0.59 | 9.1 | 0.02 | Mar 5, 2021 | Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All versions prior to 9.4.620527004 on Hardware. | ||
| CVE-2013-1350 | Cri | 0.59 | 9.1 | 0.02 | Jan 30, 2020 | Verax NMS prior to 2.1.0 has multiple security bypass vulnerabilities | ||
| CVE-2019-19597 | Hig | 0.59 | 8.8 | 0.21 | Dec 5, 2019 | D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header. | ||
| CVE-2010-2548 | Cri | 0.59 | 9.1 | 0.02 | Oct 31, 2019 | IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files. | ||
| CVE-2019-7258 | Hig | 0.59 | 8.8 | 0.20 | Jul 2, 2019 | Linear eMerge E3-Series devices allow Privilege Escalation. | ||
| CVE-2018-1245 | Cri | 0.59 | 9.0 | 0.03 | Jul 13, 2018 | RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect component (ACM). A remote authenticated malicious user with non-admin privileges could potentially bypass the Java Security… | ||
| CVE-2018-7245 | Cri | 0.59 | 9.1 | 0.01 | Apr 18, 2018 | An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and… | ||
| CVE-2026-27604 | Cri | 0.58 | — | 0.00 | Jun 23, 2026 | FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypass in the API role handling allows unauthenticated access to privileged `/api/system/*` endpoints. Because `system` resolves to the… | ||
| CVE-2026-46595 | Cri | 0.58 | 10.0 | 0.01 | May 22, 2026 | Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped. | ||
| CVE-2025-20701 | Hig | 0.58 | 8.8 | 0.07 | Aug 4, 2025 | In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-23924 | Cri | 0.58 | 10.0 | 0.04 | Feb 1, 2023 | Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP < 8, through the `phar` URL wrapper. An attacker can exploit the… | ||
| CVE-2022-24783 | Cri | 0.58 | 10.0 | 0.01 | Mar 25, 2022 | Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where a malicious actor controlling the code executed in a Deno runtime could bypass all permission checks and execute arbitrary shell… | ||
| CVE-2021-37705 | Cri | 0.58 | 10.0 | 0.02 | Aug 13, 2021 | OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allows an authenticated user from any Azure Active Directory tenant to make authorized API calls to a vulnerable OneFuzz instance. To… | ||
| CVE-2020-35682 | Hig | 0.58 | 8.8 | 0.07 | Mar 13, 2021 | Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login). | ||
| CVE-2020-3229 | Hig | 0.58 | 8.8 | 0.05 | Jun 3, 2020 | A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remote attacker to execute commands or configuration changes as an Admin user. The vulnerability is due to incorrect handling of RBAC… | ||
| CVE-2020-10786 | Hig | 0.58 | 8.8 | 0.05 | Apr 21, 2020 | A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs. | ||
| CVE-2019-19681 | Hig | 0.58 | 8.8 | 0.05 | Dec 26, 2019 | Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to define and execute commands as root/Administrator. NOTE: The product vendor states that the vulnerability as it is described is not in… | ||
| CVE-2019-5602 | Hig | 0.58 | 8.8 | 0.04 | Jul 3, 2019 | In FreeBSD 12.0-STABLE before r349628, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349629, 11.3-RC3 before 11.3-RC3-p1, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the cdrom driver allows users with read access to the cdrom device to arbitrarily overwrite… |
- risk 0.59cvss 9.1epss 0.01
An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.
- risk 0.59cvss 9.1epss 0.01
IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have access to due to incorrect authorization mechanisms. IBM X-Force ID: 198919.
- risk 0.59cvss 9.1epss 0.02
Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All versions prior to 9.4.620527004 on Hardware.
- risk 0.59cvss 9.1epss 0.02
Verax NMS prior to 2.1.0 has multiple security bypass vulnerabilities
- risk 0.59cvss 8.8epss 0.21
D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header.
- risk 0.59cvss 9.1epss 0.02
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
- risk 0.59cvss 8.8epss 0.20
Linear eMerge E3-Series devices allow Privilege Escalation.
- risk 0.59cvss 9.0epss 0.03
RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect component (ACM). A remote authenticated malicious user with non-admin privileges could potentially bypass the Java Security…
- risk 0.59cvss 9.1epss 0.01
An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and…
- risk 0.58cvss —epss 0.00
FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypass in the API role handling allows unauthenticated access to privileged `/api/system/*` endpoints. Because `system` resolves to the…
- risk 0.58cvss 10.0epss 0.01
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
- risk 0.58cvss 8.8epss 0.07
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.58cvss 10.0epss 0.04
Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP < 8, through the `phar` URL wrapper. An attacker can exploit the…
- risk 0.58cvss 10.0epss 0.01
Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where a malicious actor controlling the code executed in a Deno runtime could bypass all permission checks and execute arbitrary shell…
- risk 0.58cvss 10.0epss 0.02
OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allows an authenticated user from any Azure Active Directory tenant to make authorized API calls to a vulnerable OneFuzz instance. To…
- risk 0.58cvss 8.8epss 0.07
Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).
- risk 0.58cvss 8.8epss 0.05
A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remote attacker to execute commands or configuration changes as an Admin user. The vulnerability is due to incorrect handling of RBAC…
- risk 0.58cvss 8.8epss 0.05
A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs.
- risk 0.58cvss 8.8epss 0.05
Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to define and execute commands as root/Administrator. NOTE: The product vendor states that the vulnerability as it is described is not in…
- risk 0.58cvss 8.8epss 0.04
In FreeBSD 12.0-STABLE before r349628, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349629, 11.3-RC3 before 11.3-RC3-p1, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the cdrom driver allows users with read access to the cdrom device to arbitrarily overwrite…