CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (4,171)
page 70 of 209| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-73723 | Hig | 0.46 | 7.1 | 0.00 | Sep 1, 2026 | A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current… | ||
| CVE-2026-82730 | Hig | 0.46 | — | 0.00 | Sep 1, 2026 | Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied. When a field policy denies an attribute, Ash substitutes %Ash.ForbiddenField{}, which retains the real value in… | ||
| CVE-2026-81892 | Hig | 0.46 | 8.1 | 0.00 | Aug 31, 2026 | EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed… | ||
| CVE-2026-79746 | Hig | 0.46 | 8.1 | 0.00 | Aug 31, 2026 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.31, when a bearer key with accessType: 'servers' (or 'custom') is used against a group route,… | ||
| CVE-2026-82463 | — | Hig | 0.46 | 8.1 | 0.00 | Aug 29, 2026 | pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic… | |
| CVE-2026-77317 | Hig | 0.46 | 8.1 | 0.00 | Aug 26, 2026 | SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same access to any sibling path whose… | ||
| CVE-2026-43621 | Hig | 0.46 | 8.1 | 0.00 | Aug 26, 2026 | Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gain administrator access by supplying multiple values for the user parameter.… | ||
| CVE-2026-18985 | Hig | 0.46 | 8.1 | 0.00 | Aug 25, 2026 | Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1. | ||
| CVE-2026-78892 | Hig | 0.46 | 7.1 | 0.00 | Aug 25, 2026 | Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system access restrictions via a local program. (Chromium security severity: Medium) | ||
| CVE-2026-71506 | Hig | 0.46 | 8.1 | 0.00 | Aug 24, 2026 | Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check.… | ||
| CVE-2026-19685 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA… | ||
| CVE-2026-41424 | Hig | 0.46 | 8.2 | 0.00 | Aug 19, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.9.0 until 4.10.4 and 4.14.6, PUT /security/users/{user_id} in api/api/controllers/security_controller.py passes request.get("user") instead of… | ||
| CVE-2026-72643 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentication realms, so two distinct… | ||
| CVE-2026-72630 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was updated, that restriction was… | ||
| CVE-2026-73652 | Hig | 0.46 | — | 0.00 | Aug 13, 2026 | vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorithm while it is pending or under review. The… | ||
| CVE-2026-58439 | Hig | 0.46 | 8.1 | 0.00 | Aug 13, 2026 | Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag | ||
| CVE-2026-24791 | Hig | 0.46 | 8.1 | 0.00 | Aug 13, 2026 | Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes | ||
| CVE-2026-70463 | Hig | 0.46 | 8.1 | 0.00 | Aug 13, 2026 | rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The… | ||
| CVE-2026-73289 | Hig | 0.46 | 8.1 | 0.00 | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated string operators StringNotEquals, StringNotEqualsIgnoreCase, StringNotLike, ArnNotEquals, and ArnNotLike using… | ||
| CVE-2026-73286 | Hig | 0.46 | 8.1 | 0.00 | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap:… |
- risk 0.46cvss 7.1epss 0.00
A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current…
- risk 0.46cvss —epss 0.00
Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied. When a field policy denies an attribute, Ash substitutes %Ash.ForbiddenField{}, which retains the real value in…
- risk 0.46cvss 8.1epss 0.00
EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed…
- risk 0.46cvss 8.1epss 0.00
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.31, when a bearer key with accessType: 'servers' (or 'custom') is used against a group route,…
- risk 0.46cvss 8.1epss 0.00
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic…
- risk 0.46cvss 8.1epss 0.00
SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same access to any sibling path whose…
- risk 0.46cvss 8.1epss 0.00
Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gain administrator access by supplying multiple values for the user parameter.…
- risk 0.46cvss 8.1epss 0.00
Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1.
- risk 0.46cvss 7.1epss 0.00
Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system access restrictions via a local program. (Chromium security severity: Medium)
- risk 0.46cvss 8.1epss 0.00
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check.…
- risk 0.46cvss 7.1epss 0.00
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA…
- risk 0.46cvss 8.2epss 0.00
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.9.0 until 4.10.4 and 4.14.6, PUT /security/users/{user_id} in api/api/controllers/security_controller.py passes request.get("user") instead of…
- risk 0.46cvss 7.1epss 0.00
Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentication realms, so two distinct…
- risk 0.46cvss 7.1epss 0.00
Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was updated, that restriction was…
- risk 0.46cvss —epss 0.00
vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorithm while it is pending or under review. The…
- risk 0.46cvss 8.1epss 0.00
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
- risk 0.46cvss 8.1epss 0.00
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
- risk 0.46cvss 8.1epss 0.00
rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The…
- risk 0.46cvss 8.1epss 0.00
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated string operators StringNotEquals, StringNotEqualsIgnoreCase, StringNotLike, ArnNotEquals, and ArnNotLike using…
- risk 0.46cvss 8.1epss 0.00
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap:…