← Back
CWE-863

3,773 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

JSON object

Loading...

CVEs (3,773)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chrome
Aug 31, 2026
Aug 25, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Incorrect authorization in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium s...Show more
Incorrect authorization in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)Show less
1Google
1Chrome
Aug 31, 2026
Aug 25, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
1Google
1Chrome
Aug 31, 2026
Aug 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium securi...Show more
Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)Show less
1Google
1Chrome
Aug 31, 2026
Aug 25, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Incorrect authorization in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
1Google
1Chrome
Aug 31, 2026
Aug 25, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
1Google
1Chrome
Aug 27, 2026
Aug 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
1Google
1Chrome
Aug 27, 2026
Aug 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Incorrect authorization in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
1Google
1Chrome
Aug 27, 2026
Aug 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium securi...Show more
Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)Show less
1Google
1Chrome
Aug 31, 2026
Aug 25, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity:...Show more
Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)Show less
1Google
1Chrome
Aug 28, 2026
Aug 25, 2026
N/A· v4
3.1 LOW· v3
N/A· v2
Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security sev...Show more
Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)Show less
1Google
1Chrome
Aug 27, 2026
Aug 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
1Google
1Chrome
Aug 28, 2026
Aug 25, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML p...Show more
Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)Show less
1Google
1Chrome
Aug 28, 2026
Aug 25, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security sev...Show more
Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)Show less
1Google
1Chrome
Aug 27, 2026
Aug 25, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
1Google
1Chrome
Aug 27, 2026
Aug 25, 2026
N/A· v4
8.3 HIGH· v3
N/A· v2
Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the...Show more
Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)Show less
1Google
1Chrome
Aug 27, 2026
Aug 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
1Google
1Chrome
Aug 31, 2026
Aug 25, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severi...Show more
Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)Show less
1Google
1Chrome
Aug 31, 2026
Aug 25, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system access restrictions via a local program. (Chromium security severity: Medium)
-
-
Aug 26, 2026
Aug 25, 2026
6.3 MEDIUM· v4
3.7 LOW· v3
2.6 LOW· v2
A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of the component Journey Photo Proxy. Executing a manipulation can lead to incorrect authorization. The a...Show more
A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of the component Journey Photo Proxy. Executing a manipulation can lead to incorrect authorization. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is said to be difficult. Upgrading to version 3.1.0 will fix this issue. You should upgrade the affected component.Show less
-
-
Aug 31, 2026
Aug 25, 2026
8.5 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, but allows write operations including password changes. An attacker with an admin's profile:read access token can change t...Show more
Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, but allows write operations including password changes. An attacker with an admin's profile:read access token can change the admin's password and login to obtain an unrestricted session token that bypasses all scope enforcement.Show less