← Back
CWE-863

3,796 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

JSON object

Loading...

CVEs (3,796)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Combodo
1Itop
Jun 17, 2026
Aug 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A security misconfiguration exists in Combodo iTop, which can expose sensitive information.
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jul 31, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privileged account to bypass authorization on the API of an affected device. T...Show more
A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privileged account to bypass authorization on the API of an affected device. The vulnerability is due to insufficient authorization of certain API functions. An attacker could exploit this vulnerability by sending a crafted request to the API using low-privileged credentials. A successful exploit could allow the attacker to perform arbitrary actions through the REST API with administrative privileges.Show less
1Cisco
1Sd Wan
Jun 17, 2026
Jul 31, 2020
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization, enabling them to access sensitive information, modify the syst...Show more
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization, enabling them to access sensitive information, modify the system configuration, or impact the availability of the affected system. The vulnerability is due to insufficient authorization checking on the affected system. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to gain privileges beyond what would normally be authorized for their configured user authorization level. The attacker may be able to access sensitive information, modify the system configuration, or impact the availability of the affected system.Show less
1Openclinic Ga Project
1Openclinic Ga
Jun 17, 2026
Jul 29, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which may allow unauthorized execution of commands.
1Ihatemoney
1I Hate Money
Jun 17, 2026
Jul 27, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In "I hate money" before version 4.1.5, an authenticated member of one project can modify and delete members of another project, without knowledge of this other project's private code. This can be further exploited to ac...Show more
In "I hate money" before version 4.1.5, an authenticated member of one project can modify and delete members of another project, without knowledge of this other project's private code. This can be further exploited to access all bills of another project without knowledge of this other project's private code. With the default configuration, anybody is allowed to create a new project. An attacker can create a new project and then use it to become authenticated and exploit this flaw. As such, the exposure is similar to an unauthenticated attack, because it is trivial to become authenticated. This is fixed in version 4.1.5.Show less
1Parseplatform
1Parse Server
Jun 17, 2026
Jul 22, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer...Show more
In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer on his User object.Show less
1Jupyterhub
1Kubespawner
Jun 17, 2026
Jul 17, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames. This has been fixed in...Show more
In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames. This has been fixed in 0.12.Show less
1Cisco
2Rv110w Firmware
Rv215w Firmware
Jun 17, 2026
Jul 16, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could allow an unauthenticated, remote attacker to download sensitive information from the device, which coul...Show more
A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could allow an unauthenticated, remote attacker to download sensitive information from the device, which could include the device configuration. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing a specific URI on the web-based management interface of the router, but only after any valid user has opened a specific file on the device since the last reboot. A successful exploit would allow the attacker to view sensitive information, which should be restricted.Show less
1Cisco
1Prime License Manager
Jun 17, 2026
Jul 16, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to...Show more
A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of user input on the web management interface. An attacker could exploit this vulnerability by submitting a malicious request to an affected system. An exploit could allow the attacker to gain administrative-level privileges on the system. The attacker needs a valid username to exploit this vulnerability.Show less
1Jenkins
1Gitlab Authentication
Jun 17, 2026
Jul 15, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnerability.
1Google
1Oauth Client Library For Java
Jun 17, 2026
Jul 9, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client tha...Show more
PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that will be authorized. An attacker is able to obtain the authorization code using a malicious app on the client-side and use it to gain authorization to the protected resource. This affects the package com.google.oauth-client:google-oauth-client before 1.31.0.Show less
1Mittwald
1Typo3 Forum
Jun 17, 2026
Jul 7, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control.
1Dell
5Emc Powerstore 1000 Firmware
Emc Powerstore 3000 FirmwareEmc Powerstore 5000 Firmware+2 more
Jun 17, 2026
Jul 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote unauthenticated attacker could potentially cause Denial of Service via test inte...Show more
Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote unauthenticated attacker could potentially cause Denial of Service via test interface ports which are not used during run time environment.Show less
1Powerdns
1Recursor
Jun 17, 2026
Jul 1, 2020
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced.
1Auth0
1Express Jwt
Jun 17, 2026
Jun 30, 2020
N/A· v4
9.1 CRITICAL· v3
4.3 MEDIUM· v2
In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in the configuration, with the combination of...Show more
In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in the configuration, with the combination of jwks-rsa, it may lead to authorization bypass. You are affected by this vulnerability if all of the following conditions apply: - You are using express-jwt - You do not have **algorithms** configured in your express-jwt configuration. - You are using libraries such as jwks-rsa as the **secret**. You can fix this by specifying **algorithms** in the express-jwt configuration. See linked GHSA for example. This is also fixed in version 6.0.0.Show less
1Unisys
1Stealth
Jun 17, 2026
Jun 22, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoint could be authorized without a private key.
1Gitlab
1Gitlab
Jun 17, 2026
Jun 19, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.
1Gitlab
1Gitlab
Jun 17, 2026
Jun 19, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5
1Cisco
1Ios Xr
Jun 17, 2026
Jun 18, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to reach the configured IP addre...Show more
A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the standby route processor management Gigabit Ethernet Management interface. The vulnerability is due to a logic error that was introduced in the Cisco IOS XR Software, which prevents the ACL from working when applied against the standby route processor management interface. An attacker could exploit this vulnerability by attempting to access the device through the standby route processor management interface.Show less
1Cisco
37Unified Ip Phone 6901 Firmware
Unified Ip Phone 6911 FirmwareUnified Ip Phone 6921 Firmware+34 more
Jun 17, 2026
Jun 18, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sensitive information on an affected device. The vulnerability is due to im...Show more
A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sensitive information on an affected device. The vulnerability is due to improper access controls on the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending malicious requests to the device, which could allow the attacker to bypass access restrictions. A successful attack could allow the attacker to view sensitive information, including device call logs that contain names, usernames, and phone numbers of users of the device.Show less