← Back
CWE-863

3,796 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

JSON object

Loading...

CVEs (3,796)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Broadcom
1Fabric Operating System
Jun 17, 2026
Aug 12, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after v8.2.0 could cause a...Show more
ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after v8.2.0 could cause a user with a valid account to be unable to log into the switch.Show less
1Sapphireims
1Sapphireims
Jun 17, 2026
Aug 11, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user by directly accessing RemoteMgmtTaskSave (Automation Tasks) feature.
1Siemens
56Cpu1510sp F 1 Firmware
Cpu 1211c FirmwareCpu 1212c Firmware+53 more
Jun 17, 2026
Aug 10, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7 PLCSIM Advanced (...Show more
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7 PLCSIM Advanced (All versions > V2 < V4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (Version V4.4), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions > V2.5 < V2.9.2), SIMATIC S7-1500 Software Controller (All versions > V2.5 < V21.9), TIM 1531 IRC (incl. SIPLUS NET variants) (Version V2.1). Due to an incorrect authorization check in the affected component, an attacker could extract information about access protected PLC program variables over port 102/tcp from an affected device when reading multiple attributes at once.Show less
1Dolibarr
1Dolibarr
Jun 17, 2026
Aug 9, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has ri...Show more
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field is at “/adherents/note.php?id=1” endpoint.Show less
1Corero
1Securewatch Managed Services
Jun 17, 2026
Aug 6, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor user’s privileges, allowing a user to perform actions not belonging to his role.
1Gitlab
1Gitlab
Jun 17, 2026
Aug 5, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled
1Liferay
2Digital Experience Platform
Liferay Portal
Jun 17, 2026
Aug 3, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows remote authenticated users with permission to update/edit users to take o...Show more
Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows remote authenticated users with permission to update/edit users to take over a company administrator user account by editing the company administrator user.Show less
1Vaethink
1Vaethink
Jun 17, 2026
Aug 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a crafted payload in the condition parameter.
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Aug 3, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML pag...Show more
Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.Show less
1Huawei
4Hulk Al00c Firmware
Jennifer An00c FirmwareJenny Al10b Firmware+1 more
Jun 17, 2026
Aug 2, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
There is a logic error vulnerability in several smartphones. The software does not properly restrict certain operation when the Digital Balance function is on. Successful exploit could allow the attacker to bypass the Di...Show more
There is a logic error vulnerability in several smartphones. The software does not properly restrict certain operation when the Digital Balance function is on. Successful exploit could allow the attacker to bypass the Digital Balance limit after a series of operations. Affected product versions include: Hulk-AL00C 9.1.1.201(C00E201R8P1);Jennifer-AN00C 10.1.1.171(C00E170R6P3);Jenny-AL10B 10.1.0.228(C00E220R5P1) and OxfordPL-AN10B 10.1.0.116(C00E110R2P1).Show less
1Huawei
2Emui
Magic Ui
Jun 17, 2026
Aug 2, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is a Permission Control Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed.
1Microfocus
2Zenworks Configuration Management
Zenworks Endpoint Security Management
Jun 17, 2026
Jul 30, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all prior versions. The vulnerability could be exploited to gain unauthorize...Show more
A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all prior versions. The vulnerability could be exploited to gain unauthorized system privileges.Show less
1Solarwinds
1Orion Platform
Jun 17, 2026
Jul 30, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's perimeter) via an account with write permissions. This occurs because nod...Show more
The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's perimeter) via an account with write permissions. This occurs because node IDs are predictable (with incrementing numbers) and the access control on Services/NodeManagement.asmx/DeleteObjNow is incorrect. To exploit this, an attacker must be authenticated and must have node management rights associated with at least one valid group on the platform.Show less
1Otrs
1Otrs
Jun 17, 2026
Jul 26, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Agents are able to list appointments in the calendars without required permissions. This issue affects: OTRS AG ((OTRS)) Community Edition: 6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x versions prior to 7....Show more
Agents are able to list appointments in the calendars without required permissions. This issue affects: OTRS AG ((OTRS)) Community Edition: 6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x versions prior to 7.0.27.Show less
1Hashicorp
1Terraform
Jun 17, 2026
Jul 20, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed i...Show more
HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.Show less
11password
1Connect
Jun 17, 2026
Jul 16, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to perform privilege escalation. Malicious users authorized to create Secrets...Show more
1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to perform privilege escalation. Malicious users authorized to create Secrets Automation access tokens can create tokens that have access beyond what the user is authorized to access, but limited to the existing authorizations of the Secret Automation the token is created in.Show less
1Depstech
1Wifi Digital Microscope 3 Firmware
Jun 17, 2026
Jul 15, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Certain Shenzhen PENGLIXIN components on DEPSTECH WiFi Digital Microscope 3, as used by Shekar Endoscope, allow a TELNET connection with the molinkadmin password for the molink account.
1Siemens
1Mendix
Jun 17, 2026
Jul 13, 2021
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.22), Mendix Applications using Mendix 8 (All versions < V8.18.7), Mendix Applications using Mendix 9 (All versions < V9.3.0)...Show more
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.22), Mendix Applications using Mendix 8 (All versions < V8.18.7), Mendix Applications using Mendix 9 (All versions < V9.3.0). Write access checks of attributes of an object could be bypassed, if user has a write permissions to the first attribute of this object.Show less
1Microfocus
1Netiq Advanced Authentication
Jun 17, 2026
Jul 12, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in NetIQ Advanced Authentication versions prior to 6.3 SP4 Patch 1.
1Ninjarmm
1Ninjarmm
Jun 17, 2026
Jul 7, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The Agent in NinjaRMM 5.0.909 has Incorrect Access Control.