CWE-863
3,796 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,796)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Broadcom 1Fabric Operating System Jun 17, 2026 Aug 12, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after v8.2.0 could cause a...Show more |
In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user by directly accessing RemoteMgmtTaskSave (Automation Tasks) feature. |
1Siemens 56Cpu1510sp F 1 Firmware Cpu 1211c FirmwareCpu 1212c Firmware+53 moreJun 17, 2026 Aug 10, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7 PLCSIM Advanced (...Show more |
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has ri...Show more |
1Corero 1Securewatch Managed Services Jun 17, 2026 Aug 6, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor user’s privileges, allowing a user to perform actions not belonging to his role. |
Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 Aug 3, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows remote authenticated users with permission to update/edit users to take o...Show more |
A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a crafted payload in the condition parameter. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Aug 3, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML pag...Show more |
1Huawei 4Hulk Al00c Firmware Jennifer An00c FirmwareJenny Al10b Firmware+1 moreJun 17, 2026 Aug 2, 2021 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 There is a logic error vulnerability in several smartphones. The software does not properly restrict certain operation when the Digital Balance function is on. Successful exploit could allow the attacker to bypass the Di...Show more |
There is a Permission Control Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed. |
1Microfocus 2Zenworks Configuration Management Zenworks Endpoint Security ManagementJun 17, 2026 Jul 30, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all prior versions. The vulnerability could be exploited to gain unauthorize...Show more |
The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's perimeter) via an account with write permissions. This occurs because nod...Show more |
Agents are able to list appointments in the calendars without required permissions. This issue affects: OTRS AG ((OTRS)) Community Edition: 6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x versions prior to 7....Show more |
HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed i...Show more |
1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to perform privilege escalation. Malicious users authorized to create Secrets...Show more |
1Depstech 1Wifi Digital Microscope 3 Firmware Jun 17, 2026 Jul 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Certain Shenzhen PENGLIXIN components on DEPSTECH WiFi Digital Microscope 3, as used by Shekar Endoscope, allow a TELNET connection with the molinkadmin password for the molink account. |
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.22), Mendix Applications using Mendix 8 (All versions < V8.18.7), Mendix Applications using Mendix 9 (All versions < V9.3.0)...Show more |
1Microfocus 1Netiq Advanced Authentication Jun 17, 2026 Jul 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in NetIQ Advanced Authentication versions prior to 6.3 SP4 Patch 1. |
The Agent in NinjaRMM 5.0.909 has Incorrect Access Control. |