CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (4,238)
page 16 of 212| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0670 | Cri | 0.59 | 9.1 | 0.01 | Jul 25, 2022 | A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise… | ||
| CVE-2022-26629 | Cri | 0.59 | 9.1 | 0.03 | Mar 24, 2022 | An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function. | ||
| CVE-2022-0482 | Cri | 0.59 | 9.1 | 0.44 | Mar 9, 2022 | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3. | ||
| CVE-2021-39233 | Cri | 0.59 | 9.1 | 0.02 | Nov 19, 2021 | In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client. | ||
| CVE-2021-41244 | Cri | 0.59 | 9.1 | 0.03 | Nov 15, 2021 | Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enabled and there is more than one organization in the Grafana instance admins are able to access users from other organizations.… | ||
| CVE-2021-30925 | Cri | 0.59 | 9.1 | 0.01 | Aug 24, 2021 | The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 and iPadOS 15. A malicious application may be able to bypass Privacy preferences. | ||
| CVE-2021-30856 | Cri | 0.59 | 9.1 | 0.01 | Aug 24, 2021 | This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions. This issue is fixed in macOS Big Sur 11.3. A malicious unsandboxed app on a system with Remote Login enabled may bypass Privacy preferences. | ||
| CVE-2021-26040 | Cri | 0.59 | 9.1 | 0.01 | Aug 24, 2021 | An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command. | ||
| CVE-2021-20538 | Cri | 0.59 | 9.1 | 0.01 | May 10, 2021 | IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have access to due to incorrect authorization mechanisms. IBM X-Force ID: 198919. | ||
| CVE-2020-29020 | Cri | 0.59 | 9.1 | 0.02 | Mar 5, 2021 | Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All versions prior to 9.4.620527004 on Hardware. | ||
| CVE-2013-1350 | Cri | 0.59 | 9.1 | 0.02 | Jan 30, 2020 | Verax NMS prior to 2.1.0 has multiple security bypass vulnerabilities | ||
| CVE-2019-19597 | Hig | 0.59 | 8.8 | 0.21 | Dec 5, 2019 | D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header. | ||
| CVE-2010-2548 | Cri | 0.59 | 9.1 | 0.02 | Oct 31, 2019 | IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files. | ||
| CVE-2019-7258 | Hig | 0.59 | 8.8 | 0.20 | Jul 2, 2019 | Linear eMerge E3-Series devices allow Privilege Escalation. | ||
| CVE-2018-1245 | Cri | 0.59 | 9.0 | 0.02 | Jul 13, 2018 | RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect component (ACM). A remote authenticated malicious user with non-admin privileges could potentially bypass the Java Security… | ||
| CVE-2018-7245 | Cri | 0.59 | 9.1 | 0.01 | Apr 18, 2018 | An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and… | ||
| CVE-2026-80515 | Hig | 0.58 | — | 0.00 | Sep 3, 2026 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestURL() un-decoded,… | ||
| CVE-2026-27604 | Cri | 0.58 | — | 0.01 | Jun 23, 2026 | FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypass in the API role handling allows unauthenticated access to privileged `/api/system/*` endpoints. Because `system` resolves to the… | ||
| CVE-2026-46595 | Cri | 0.58 | 10.0 | 0.01 | May 22, 2026 | Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped. | ||
| CVE-2025-20701 | Hig | 0.58 | 8.8 | 0.09 | Aug 4, 2025 | In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
- risk 0.59cvss 9.1epss 0.01
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise…
- risk 0.59cvss 9.1epss 0.03
An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.
- risk 0.59cvss 9.1epss 0.44
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
- risk 0.59cvss 9.1epss 0.02
In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client.
- risk 0.59cvss 9.1epss 0.03
Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enabled and there is more than one organization in the Grafana instance admins are able to access users from other organizations.…
- risk 0.59cvss 9.1epss 0.01
The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 and iPadOS 15. A malicious application may be able to bypass Privacy preferences.
- risk 0.59cvss 9.1epss 0.01
This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions. This issue is fixed in macOS Big Sur 11.3. A malicious unsandboxed app on a system with Remote Login enabled may bypass Privacy preferences.
- risk 0.59cvss 9.1epss 0.01
An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.
- risk 0.59cvss 9.1epss 0.01
IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have access to due to incorrect authorization mechanisms. IBM X-Force ID: 198919.
- risk 0.59cvss 9.1epss 0.02
Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All versions prior to 9.4.620527004 on Hardware.
- risk 0.59cvss 9.1epss 0.02
Verax NMS prior to 2.1.0 has multiple security bypass vulnerabilities
- risk 0.59cvss 8.8epss 0.21
D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header.
- risk 0.59cvss 9.1epss 0.02
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
- risk 0.59cvss 8.8epss 0.20
Linear eMerge E3-Series devices allow Privilege Escalation.
- risk 0.59cvss 9.0epss 0.02
RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect component (ACM). A remote authenticated malicious user with non-admin privileges could potentially bypass the Java Security…
- risk 0.59cvss 9.1epss 0.01
An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and…
- risk 0.58cvss —epss 0.00
In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestURL() un-decoded,…
- risk 0.58cvss —epss 0.01
FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypass in the API role handling allows unauthenticated access to privileged `/api/system/*` endpoints. Because `system` resolves to the…
- risk 0.58cvss 10.0epss 0.01
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
- risk 0.58cvss 8.8epss 0.09
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.