← Back
CWE-863

3,038 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

JSON object

Loading...

CVEs (3,038)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitlab
1Gitlab
Nov 21, 2024
Jun 6, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possessio...Show more
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any location even when IP address restrictions were configuredShow less
1Wpexperts
1All In One Login
Jan 14, 2026
May 30, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings....Show more
The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vectorShow less
1Apple
1Macos
May 30, 2025
May 26, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The issue was addressed with additional permissions checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to bypass Privacy preferences.
1Rescue Dispatch Management System Project
1Rescue Dispatch Management System
Nov 21, 2024
May 23, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=system_info.
3Netapp
OracleVmware
3Active Iq Unified Manager
Financial Services Crime And Compliance Management StudioSpring Security
Nov 21, 2024
May 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatc...Show more
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.Show less
1Lenovo
1Xclarity Controller
Nov 21, 2024
May 18, 2022
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an L...Show more
A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an LDAP server that supports “unauthenticated bind”, such as Microsoft Active Directory. An unauthenticated user can gain read-only access to XCC in such a configuration, thereby allowing the XCC device configuration to be viewed but not changed. XCC devices configured to use local authentication, LDAP Authentication + Authorization Mode, or LDAP servers that support only “authenticated bind” and/or “anonymous bind” are not affected.Show less
2Fedoraproject
Redhat
4Enterprise Linux
FedoraIgnition+1 more
Nov 21, 2024
May 17, 2022
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config conta...Show more
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.Show less
1Wowonder
1Wowonder
Nov 21, 2024
May 17, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting message...Show more
A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. It is possible to launch the attack remotely but it might require authentication. A video explaining the attack has been disclosed to the public.Show less
1Publify Project
1Publify
Nov 21, 2024
May 16, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected art...Show more
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users.Show less
1Publify Project
1Publify
Nov 21, 2024
May 16, 2022
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Improper Access Control in GitHub repository publify/publify prior to 9.2.8.
1Mitel
1Minet Firmware
Nov 21, 2024
May 13, 2022
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient...Show more
A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.Show less
1Rubygems
1Rubygems.org
Nov 21, 2024
May 13, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allowed some gems (with platforms ending in numbers, like `arm64-darwin-21`...Show more
RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allowed some gems (with platforms ending in numbers, like `arm64-darwin-21`) to be temporarily replaced in the CDN cache by a malicious package. The bug has been patched, and is believed to have never been exploited, based on an extensive review of logs and existing gems by rubygems. The easiest way to ensure that an application has not been exploited by this vulnerability is to verify all downloaded .gems checksums match the checksum recorded in the RubyGems.org database. RubyGems.org has been patched and is no longer vulnerable to this issue.Show less
1B1
1Eosio Batdappboomx
Nov 21, 2024
May 13, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
EOSIO batdappboomx v327c04cf has an Access-control vulnerability in the `transfer` function of the smart contract which allows remote attackers to win the cryptocurrency without paying ticket fee via the `std::string mem...Show more
EOSIO batdappboomx v327c04cf has an Access-control vulnerability in the `transfer` function of the smart contract which allows remote attackers to win the cryptocurrency without paying ticket fee via the `std::string memo` parameter.Show less
1Zte
1Zxmp M721 Firmware
Nov 21, 2024
May 12, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modificati...Show more
ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modification?of?the file permission configuration, so that low-authority accounts could actually obtain higher operating permissions on key files.Show less
1Yubico
1Otp
Nov 21, 2024
May 11, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Incorrect access control in Yubico OTP functionality of the YubiKey hardware tokens along with the Yubico OTP validation server. The Yubico OTP supposedly creates hardware bound second factor credentials. When a user rep...Show more
Incorrect access control in Yubico OTP functionality of the YubiKey hardware tokens along with the Yubico OTP validation server. The Yubico OTP supposedly creates hardware bound second factor credentials. When a user reprograms the OTP functionality by "writing" it on a token using the Yubico Personalization Tool, they can then upload the new configuration to Yubicos OTP validation servers. NOTE: the vendor disputes this because there is no way for a YubiKey device to prevent a user from deciding that a secret value, which is imported into the device, should also be stored elsewhereShow less
1Sap
1Host Agent
Nov 21, 2024
May 11, 2022
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted.
1Gitlab
1Gitlab
Nov 21, 2024
May 11, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing cor...Show more
An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations on scheduled pipelines allowing a malicious user to run a pipeline in the context of another user.Show less
1Gitlab
1Gitlab
Nov 21, 2024
May 11, 2022
N/A· v4
4.3 MEDIUM· v3
3.5 LOW· v2
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of job...Show more
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabledShow less
1Lmsdoctor
12 Factor Authentication
Nov 21, 2024
May 10, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allo...Show more
A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.Show less
1Gitlab
1Gitlab
Nov 21, 2024
May 10, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project membe...Show more
Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to access contents of Project Members-only Wikis via malicious CI jobsShow less