← Back
CWE-863

3,797 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

JSON object

Loading...

CVEs (3,797)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rest & Json Api Authentication Project
1Rest & Json Api Authentication
Jun 17, 2026
Jan 9, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13.
1Commerce View Receipt Project
1Commerce View Receipt
Jun 17, 2026
Jan 9, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commerce View Receipt: from 0.0.0 before 1.0.3.
1Advanced Pwa Inc Push Notifications Project
1Advanced Pwa Inc Push Notifications
Jun 17, 2026
Jan 9, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue affects Advanced PWA inc Push Notifications: from 0.0.0 before 1.5.0.
1Mattermost
1Mattermost Server
Jun 17, 2026
Jan 9, 2025
N/A· v4
3.8 LOW· v3
N/A· v2
Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making th...Show more
Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.Show less
-
-
Jun 17, 2026
Jan 8, 2025
N/A· v4
3.4 LOW· v3
N/A· v2
A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP prot...Show more
A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuration that allows packets routing (at layer 3). Configurations that do not allow network traffic routing are not impacted. Successful exploitation could allow an attacker to bypass security policies, potentially leading to unauthorized data exposure.Show less
1Mozilla
2Firefox
Thunderbird
Jun 17, 2026
Jan 7, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks....Show more
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.Show less
-
-
Jun 17, 2026
Dec 27, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data.
1Huawei
7Mate 20 Firmware
P30 FirmwareP30 Pro Firmware+4 more
Jun 17, 2026
Dec 27, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to...Show more
There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9081.Show less
1Honor
1Magicos
Jun 17, 2026
Dec 26, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
1Honor
1Magicos
Jun 17, 2026
Dec 26, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
1Xiph
1Theora
Jun 17, 2026
Dec 25, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an applicat...Show more
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.Show less
1Ibm
2Aix
Vios
Jun 17, 2026
Dec 25, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.
1Jetbrains
1Teamcity
Jun 17, 2026
Dec 20, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
1Jetbrains
1Teamcity
Jun 17, 2026
Dec 20, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents
1Arista
1Ng Firewall
Jun 17, 2026
Dec 20, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Arista NG Firewall. An attacker must...Show more
Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Arista NG Firewall. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the uvm_login module. The issue results from incorrect authorization. An attacker can leverage this to escalate privileges to resources normally protected from the user. Was ZDI-CAN-24324.Show less
-
-
Jun 17, 2026
Dec 19, 2024
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values...Show more
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions before 5.9.Show less
1Elastic
1Elasticsearch
Jun 17, 2026
Dec 17, 2024
6.0 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their role...Show more
An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.Show less
1Vercel
1Next.js
Jun 17, 2026
Dec 17, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to...Show more
Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly under the application's root directory. For example: * [Not affected] `https://example.com/` * [Affected] `https://example.com/foo` * [Not affected] `https://example.com/foo/bar`. This issue is patched in Next.js `14.2.15` and later. If your Next.js application is hosted on Vercel, this vulnerability has been automatically mitigated, regardless of Next.js version. There are no official workarounds for this vulnerability.Show less
-
-
Jun 17, 2026
Dec 17, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving socksmethod.
1Awesomemotive
1Easy Digital Downloads
Jun 17, 2026
Dec 17, 2024
N/A· v4
3.7 LOW· v3
N/A· v2
The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient validation checks within the 'verify_guest_email' function to ens...Show more
The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient validation checks within the 'verify_guest_email' function to ensure the requesting user is the intended recipient of the purchase receipt. This makes it possible for unauthenticated attackers to bypass intended security restrictions and view the receipts of other users, which contains a link to download paid content. Successful exploitation requires knowledge of another customers email address as well as the file ID of the content they purchased.Show less