← Back
CWE-863

3,796 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

JSON object

Loading...

CVEs (3,796)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Aug 28, 2026
Aug 11, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation...Show more
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.Show less
1Adobe
1Lightroom
Aug 28, 2026
Aug 11, 2026
N/A· v4
7.7 HIGH· v3
N/A· v2
Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrar...Show more
Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.Show less
-
-
Aug 28, 2026
Aug 11, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read...Show more
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.Show less
-
-
Aug 28, 2026
Aug 11, 2026
N/A· v4
7.6 HIGH· v3
N/A· v2
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unau...Show more
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.Show less
-
-
Aug 28, 2026
Aug 11, 2026
N/A· v4
2.7 LOW· v3
N/A· v2
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to restricted re...Show more
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction.Show less
-
-
Aug 28, 2026
Aug 11, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and ga...Show more
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.Show less
1Adobe
1Campaign
Aug 28, 2026
Aug 11, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execu...Show more
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.Show less
1Adobe
1Coldfusion
Aug 28, 2026
Aug 11, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code....Show more
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction.Show less
1Adobe
1Coldfusion
Aug 28, 2026
Aug 11, 2026
N/A· v4
9.6 CRITICAL· v3
N/A· v2
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write acces...Show more
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.Show less
1Adobe
1Coldfusion
Aug 28, 2026
Aug 11, 2026
N/A· v4
7.3 HIGH· v3
N/A· v2
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized read and wri...Show more
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized read and write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.Show less
1Microsoft
1Visual Studio Code
Sep 2, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
1Microsoft
1Sharepoint Server
Aug 12, 2026
Aug 11, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
1Microsoft
1.net Framework
Aug 14, 2026
Aug 11, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
1Microsoft
1Windows 11 26h1
Aug 13, 2026
Aug 11, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Aug 17, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
1Adobe
1Coldfusion
Aug 28, 2026
Aug 11, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker could exploit this vulnerability to crash the application, leading to a...Show more
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.Show less
1Adobe
1Coldfusion
Aug 28, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of th...Show more
is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction.Show less
-
-
Aug 13, 2026
Aug 11, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also a...Show more
SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths such as /tenant1234, /tenant1-old, and /tenant1backup, enabling cross-tenant reads and writes with a valid scoped token. This issue is fixed in version 4.24.Show less
-
-
Aug 28, 2026
Aug 11, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only...Show more
Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to 0.77.2 evaluate this permission against the caller's org instead of against the target org. This allows an administrator in one org to impersonate another user in another org, in which they may not have the IMPERSONATE permission.Show less
-
-
Aug 28, 2026
Aug 11, 2026
9.3 CRITICAL· v4
4.3 MEDIUM· v3
N/A· v2
Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can permanently modify t...Show more
Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can permanently modify that group's category structure — reordering and re-parenting categories — via the structures/move-element action. The structureEditable flag is computed from the view permission rather than the save permission, and the StructuresController authorizes the mutating action on that read-time session grant without a save re-check. Because a category's URI is derived from its position in the structure, moving a category changes its URL and those of its descendants and can corrupt navigation menus built from the category taxonomy. The issue is fixed in 5.10.6.Show less