CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (3,736)
page 75 of 187| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-71518 | Hig | 0.42 | 7.5 | 0.00 | Aug 17, 2026 | Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash… | ||
| CVE-2026-19726 | Med | 0.42 | 6.5 | 0.00 | Aug 16, 2026 | The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above to read the full configuration of any chart on the site, including charts the Visualizer WordPress plugin… | ||
| CVE-2026-58427 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 | ||
| CVE-2026-58417 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | REST API exposes organization membership of private organizations to public | ||
| CVE-2026-73285 | Hig | 0.42 | 7.5 | 0.00 | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_tag incorrectly for PreparedIamMode::Opa,… | ||
| CVE-2026-64952 | Med | 0.42 | 6.5 | 0.00 | Aug 12, 2026 | The hunt_delete() VQL function allows deleting hunts. Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned to the "investigator" role) instead of the "DELETE_RESULTS" permission (usually only assigned to "administrators"). | ||
| CVE-2026-18696 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is… | ||
| CVE-2026-48411 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue… | ||
| CVE-2026-63512 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network. | ||
| CVE-2026-48375 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue… | ||
| CVE-2026-19345 | Med | 0.42 | 6.5 | 0.01 | Aug 9, 2026 | A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in missing authorization. It is possible to launch the attack remotely. The exploit… | ||
| CVE-2026-48076 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1.0.1 and prior consists of three calls: `bootstrap-challenge` (returns a 16-bit PoW challenge with `difficulty=4` leading hex… | ||
| CVE-2026-64640 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog's… | ||
| CVE-2026-50749 | Med | 0.42 | 6.5 | 0.00 | Aug 5, 2026 | Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. Users are… | ||
| CVE-2026-71247 | Med | 0.42 | 6.5 | 0.00 | Aug 5, 2026 | Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields belonging to any later-or-equal-order, not-yet-signed recipient in the same envelope, with no restriction on field type. A newer V2… | ||
| CVE-2026-62927 | Hig | 0.42 | 7.5 | 0.00 | Aug 4, 2026 | In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method. | ||
| CVE-2026-18572 | Med | 0.42 | 6.5 | 0.00 | Aug 2, 2026 | Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request… | ||
| CVE-2026-18203 | Med | 0.42 | 6.5 | 0.00 | Jul 31, 2026 | A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a… | ||
| CVE-2026-54719 | Hig | 0.42 | 7.5 | 0.00 | Jul 28, 2026 | goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticated reads of files protected only… | ||
| CVE-2026-13060 | Med | 0.42 | 6.5 | 0.00 | Jul 22, 2026 | An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and during execution. Affected scenarios… |
- risk 0.42cvss 7.5epss 0.00
Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash…
- risk 0.42cvss 6.5epss 0.00
The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above to read the full configuration of any chart on the site, including charts the Visualizer WordPress plugin…
- risk 0.42cvss 7.5epss 0.00
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
- risk 0.42cvss 7.5epss 0.00
REST API exposes organization membership of private organizations to public
- risk 0.42cvss 7.5epss 0.00
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_tag incorrectly for PreparedIamMode::Opa,…
- risk 0.42cvss 6.5epss 0.00
The hunt_delete() VQL function allows deleting hunts. Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned to the "investigator" role) instead of the "DELETE_RESULTS" permission (usually only assigned to "administrators").
- risk 0.42cvss 6.5epss 0.00
An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is…
- risk 0.42cvss 6.5epss 0.00
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue…
- risk 0.42cvss 6.5epss 0.01
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
- risk 0.42cvss 6.5epss 0.01
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue…
- risk 0.42cvss 6.5epss 0.01
A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in missing authorization. It is possible to launch the attack remotely. The exploit…
- risk 0.42cvss 6.5epss 0.00
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1.0.1 and prior consists of three calls: `bootstrap-challenge` (returns a 16-bit PoW challenge with `difficulty=4` leading hex…
- risk 0.42cvss 6.5epss 0.00
Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog's…
- risk 0.42cvss 6.5epss 0.00
Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. Users are…
- risk 0.42cvss 6.5epss 0.00
Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields belonging to any later-or-equal-order, not-yet-signed recipient in the same envelope, with no restriction on field type. A newer V2…
- risk 0.42cvss 7.5epss 0.00
In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.
- risk 0.42cvss 6.5epss 0.00
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request…
- risk 0.42cvss 6.5epss 0.00
A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a…
- risk 0.42cvss 7.5epss 0.00
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticated reads of files protected only…
- risk 0.42cvss 6.5epss 0.00
An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and during execution. Affected scenarios…