← Back
CWE-863

3,796 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

JSON object

Loading...

CVEs (3,796)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Polrproject
1Polr
Jun 17, 2026
Feb 1, 2021
N/A· v4
9.3 CRITICAL· v3
6.4 MEDIUM· v2
Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attackers to gain admin access to site instances, even if they do not possess an existing account. This vuln...Show more
Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attackers to gain admin access to site instances, even if they do not possess an existing account. This vulnerability exists regardless of users' settings. If an attacker crafts a request with specific cookie headers to the /setup/finish endpoint, they may be able to obtain admin privileges on the instance. This is caused by a loose comparison (==) in SetupController that is susceptible to attack. The project has been patched to ensure that a strict comparison (===) is used to verify the setup key, and that /setup/finish verifies that no users table exists before performing any migrations or provisioning any new accounts. This is fixed in version 2.3.0. Users can patch this vulnerability without upgrading by adding abort(404) to the very first line of finishSetup in SetupController.php.Show less
1Mantisbt
1Mantisbt
Jun 17, 2026
Jan 29, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary fields of private Issues via bug_arr[]= in a c...Show more
An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary fields of private Issues via bug_arr[]= in a crafted bug_actiongroup_page.php URL. (The target Issues can have Private view status, or belong to a private Project.)Show less
1Hide Thread Content Project
1Hide Thread Content
Jun 17, 2026
Jan 28, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit.
1Redhat
1Keycloak
Jun 17, 2026
Jan 28, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token.
1Acdsee
1Photo Studio 2021
Jun 17, 2026
Jan 26, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!JPEGTransW+0x000000000000c7f4 via a crafted BMP image.
1Acdsee
1Photo Studio 2021
Jun 17, 2026
Jan 26, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!zlibVersion+0x0000000000004e5e via a crafted BMP image.
2Apache
Oracle
3Financial Services Crime And Compliance Management Studio
HadoopSolr
Jun 17, 2026
Jan 26, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.
1Cisco
4Ios Xe Sd Wan
Sd Wan FirmwareSd Wan Vbond Orchestrator+1 more
Jun 17, 2026
Jan 20, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, ga...Show more
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not authorized to access. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jan 20, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jan 20, 2021
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Ibm
1Planning Analytics
Jun 17, 2026
Jan 19, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 190836.
1Adobe
1Magento
Jun 17, 2026
Jan 13, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the customer API module. Successful exploitation could lead to sens...Show more
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the customer API module. Successful exploitation could lead to sensitive information disclosure and update arbitrary information on another user's account.Show less
1Cisco
1Connected Mobile Experiences
Jun 17, 2026
Jan 13, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter the password of any user on an affected system. The vulnerability is due...Show more
A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter the password of any user on an affected system. The vulnerability is due to incorrect handling of authorization checks for changing a password. An authenticated attacker without administrative privileges could exploit this vulnerability by sending a modified HTTP request to an affected device. A successful exploit could allow the attacker to alter the passwords of any user on the system, including an administrative user, and then impersonate that user.Show less
1Cisco
1Connected Mobile Experiences
Jun 17, 2026
Jan 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote attacker to enumerate what users exist on the system. The vulnerability is due to a lack of authorizatio...Show more
A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote attacker to enumerate what users exist on the system. The vulnerability is due to a lack of authorization checks for certain API GET requests. An attacker could exploit this vulnerability by sending specific API GET requests to an affected device. A successful exploit could allow the attacker to enumerate users of the CMX system.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Jan 13, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers without Overall/Read permission to access some URLs as if they did hav...Show more
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers without Overall/Read permission to access some URLs as if they did have Overall/Read permission.Show less
1Google
1Android
Jun 17, 2026
Jan 11, 2021
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without appropriate permissions due to a permissions bypass. This could lead to local...Show more
In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without appropriate permissions due to a permissions bypass. This could lead to local escalation of privilege that grants access to nearby MAC addresses, with User execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.0, Android-8.1, Android-9, Android-10, Android-11; Android ID: A-167244818.Show less
1Google
1Android
Jun 17, 2026
Jan 11, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User i...Show more
In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-10, Android-11, Android-8.0, Android-8.1, Android-9; Android ID: A-168319670.Show less
1K7computing
4Antivrius
Enterprise SecurityTotal Security+1 more
Jul 9, 2026
Jan 11, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local). The component is: K7TSMngr.exe.
1K7computing
4Antivrius
Enterprise SecurityTotal Security+1 more
Jul 9, 2026
Jan 11, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: Local Process Execution (local). The component is: K7Sentry.sys.
1Nvidia
1Gpu Driver
Jun 17, 2026
Jan 8, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not perform or incorrectly performs an authorizat...Show more
NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action, which may lead to denial of service.Show less