CWE-863
3,308 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,308)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Google Redhat4Chrome Enterprise Linux DesktopEnterprise Linux Server+1 moreMay 13, 2026 Oct 27, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to perform domain spoofing via IDN homographs in a cr...Show more |
5Debian MariadbNetapp+2 more17Active Iq Unified Manager Debian LinuxEnterprise Linux Desktop+14 moreMay 13, 2026 Oct 19, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable vuln...Show more |
1Osisoft 3Pi Integrator For Business Analystics Pi Integrator For Microsoft AzurePi Integrator For Sap HanaMay 13, 2026 Aug 14, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An Improper Authorization issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft Azure before 2016 R2 SP1, and PI Integrator for SAP HANA before 2017. An attacker...Show more |
6Apache CanonicalDebian+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 13, 2026 Aug 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to thos...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Aug 8, 2017 N/A· v4 7.5 HIGH· v3 8.5 HIGH· v2 Windows Error Reporting (WER) in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an eleva...Show more |
1Sma 39Sunny Boy 1.5 Firmware Sunny Boy 2.5 FirmwareSunny Boy 3.0 Firmware+36 moreMay 13, 2026 Aug 5, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in SMA Solar Technology products. A secondary authentication system is available for Installers called the Grid Guard system. This system uses predictable codes, and a single Grid Guard code can b...Show more |
1Cisco 1Asr 5000 Series Software May 13, 2026 Jul 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in certain filtering mechanisms of access control lists (ACLs) for Cisco ASR 5000 Series Aggregation Services Routers through 21.x could allow an unauthenticated, remote attacker to bypass ACL rules that...Show more |
1Redhat 13scale Api Management Platform May 13, 2026 Jul 7, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attacker could use this flaw to circumvent authentication controls and gain a...Show more |
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the OAuth module allows remote authenticated users to hijack OAuth sessions of other...Show more |
Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a...Show more |
BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed to be an admin-only action, and the admin may have other tasks (such as...Show more |
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device. |
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allowing privilege escalat...Show more |
Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions o...Show more |
1Vmware 2Workstation Player Workstation ProMay 13, 2026 May 22, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privil...Show more |
Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the...Show more |
1Cisco 1Unified Computing System Director May 13, 2026 Apr 7, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the role-based resource checking functionality of Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in...Show more |
An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that shou...Show more |
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions. |
When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass. |