← Back
CWE-863

3,046 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

JSON object

Loading...

CVEs (3,046)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Honor
1Magicos
Jun 5, 2025
Dec 26, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
1Xiph
1Theora
Apr 25, 2025
Dec 25, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an applicat...Show more
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.Show less
1Ibm
2Aix
Vios
Sep 29, 2025
Dec 25, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.
1Jetbrains
1Teamcity
Jan 2, 2025
Dec 20, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
1Jetbrains
1Teamcity
Jan 2, 2025
Dec 20, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents
1Arista
1Ng Firewall
Jan 3, 2025
Dec 20, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Arista NG Firewall. An attacker must...Show more
Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Arista NG Firewall. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the uvm_login module. The issue results from incorrect authorization. An attacker can leverage this to escalate privileges to resources normally protected from the user. Was ZDI-CAN-24324.Show less
-
-
Dec 19, 2024
Dec 19, 2024
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values...Show more
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions before 5.9.Show less
1Elastic
1Elasticsearch
Feb 4, 2025
Dec 17, 2024
6.0 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their role...Show more
An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.Show less
1Vercel
1Next.js
Sep 10, 2025
Dec 17, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to...Show more
Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly under the application's root directory. For example: * [Not affected] `https://example.com/` * [Affected] `https://example.com/foo` * [Not affected] `https://example.com/foo/bar`. This issue is patched in Next.js `14.2.15` and later. If your Next.js application is hosted on Vercel, this vulnerability has been automatically mitigated, regardless of Next.js version. There are no official workarounds for this vulnerability.Show less
-
-
Dec 18, 2024
Dec 17, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving socksmethod.
1Awesomemotive
1Easy Digital Downloads
Feb 7, 2025
Dec 17, 2024
N/A· v4
3.7 LOW· v3
N/A· v2
The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient validation checks within the 'verify_guest_email' function to ens...Show more
The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient validation checks within the 'verify_guest_email' function to ensure the requesting user is the intended recipient of the purchase receipt. This makes it possible for unauthenticated attackers to bypass intended security restrictions and view the receipts of other users, which contains a link to download paid content. Successful exploitation requires knowledge of another customers email address as well as the file ID of the content they purchased.Show less
1Sunbirddcim
1Dctrack
Jun 20, 2025
Dec 16, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location which bypasses an RBAC check.
1Gitlab
1Gitlab
Jul 11, 2025
Dec 16, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes i...Show more
An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.Show less
1Gitlab
1Gitlab
Jul 11, 2025
Dec 16, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user c...Show more
An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.Show less
1Xwiki
1Xwiki
Apr 30, 2025
Dec 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code r...Show more
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights on the server. This vulnerability has been fixed in XWiki 15.10.9 and 16.3.0. Since `Extension Repository Application` is not mandatory, it can be safely disabled on instances that do not use it as a workaround. It is also possible to manually apply the patches from commit 8659f17d500522bf33595e402391592a35a162e8 to the page `ExtensionCode.ExtensionSheet` and to the page `ExtensionCode.ExtensionAuthorsDisplayer`.Show less
1Apache
1Superset
Feb 12, 2025
Dec 12, 2024
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Incorrectly identified as a read-only query,...Show more
Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Incorrectly identified as a read-only query, enabling its execution. Non postgres analytics database connections and postgres analytics database connections set with a readonly user (advised) are not vulnerable.  This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.Show less
1Gitlab
1Gitlab
Jul 11, 2025
Dec 12, 2024
N/A· v4
3.1 LOW· v3
N/A· v2
An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to v...Show more
An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure.Show less
1Apple
1Macos
Nov 3, 2025
Dec 12, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The issue was addressed with improved permissions logic. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to modify protected parts of the file system.
1Apache
1Superset
Feb 12, 2025
Dec 9, 2024
7.6 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API.  issue affects Apache Superset: from 2.0.0 before 4.1...Show more
Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API.  issue affects Apache Superset: from 2.0.0 before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.Show less
-
-
Dec 10, 2024
Dec 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create connection objects that trigger execution of arbitrary EXE files. This...Show more
An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create connection objects that trigger execution of arbitrary EXE files. This is fixed in November 2024 IR, May 2024 Patch 10, February 2024 Patch 14, November 2023 Patch 16, August 2023 Patch 16, May 2023 Patch 18, and February 2023 Patch 15.Show less