← Back
CWE-863

3,780 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

JSON object

Loading...

CVEs (3,780)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Parseplatform
1Parse Server
Jun 17, 2026
Mar 4, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the NoSQL, you can use a regex on sessionToken and find valid accounts this way.
1Totaljs
1Total.js Cms
Jun 17, 2026
Feb 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI. This can be exploited in conjunction with CVE-2019-15954.
1Ibm
7Maximo Asset Management
Maximo For AviationMaximo For Life Sciences+4 more
Jun 17, 2026
Feb 24, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated user due to disclosing path information in the URL. IBM X-Force ID: 172883.
1Google
1Android
Nov 21, 2024
Feb 21, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth pac...Show more
btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.Show less
1Openhab
1Openhab
Jun 17, 2026
Feb 20, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation service and execute arbitrary commands on the system with the privileges of the user running openHAB. Star...Show more
openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation service and execute arbitrary commands on the system with the privileges of the user running openHAB. Starting with version 2.5.2 all commands need to be whitelisted in a local file which cannot be changed via REST calls.Show less
1Organic Groups Project
1Organic Groups
Nov 21, 2024
Feb 18, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to private groups, which allows remote authenticated users to gues...Show more
The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to private groups, which allows remote authenticated users to guess node IDs, subscribe to, and read the content of arbitrary private groups via unspecified vectors.Show less
1Mcafee
1Endpoint Security
Jun 17, 2026
Feb 14, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthorised use of the config...Show more
Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthorised use of the configuration tool from older versions of ENS.Show less
1Mailu
1Mailu
Jun 17, 2026
Feb 13, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Mailu before version 1.7, an authenticated user can exploit a vulnerability in Mailu fetchmail script and gain full access to a Mailu instance. Mailu servers that have open registration or untrusted users are most imp...Show more
In Mailu before version 1.7, an authenticated user can exploit a vulnerability in Mailu fetchmail script and gain full access to a Mailu instance. Mailu servers that have open registration or untrusted users are most impacted. The master and 1.7 branches are patched on our git repository. All Docker images published on docker.io/mailu for tags 1.5, 1.6, 1.7 and master are patched. For detailed instructions about patching and securing the server afterwards, see https://github.com/Mailu/Mailu/issues/1354Show less
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Feb 11, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.130 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted Chrome Extension.
1Dell
1Emc Isilon Onefs
Jun 17, 2026
Feb 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations. An attacker may exploit this vulnerability to gain access to restricted files. The non-RAN HTTP and WebD...Show more
Dell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations. An attacker may exploit this vulnerability to gain access to restricted files. The non-RAN HTTP and WebDAV file-serving components have a vulnerability wherein when either are enabled, and Basic Authentication is enabled for either or both components, files are accessible without authentication.Show less
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.
1Brother
1Mfc 9970cdw Firmware
Nov 21, 2024
Feb 3, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Brother MFC-9970CDW 1.10 firmware L devices contain a security bypass vulnerability which allows physically proximate attackers to gain unauthorized access.
1Hashicorp
1Consul
Jun 17, 2026
Jan 31, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.
1Login Security Project
1Login Security
Nov 21, 2024
Jan 30, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows attackers to bypass intended restrictions via a crafted username.
1Veraxsystems
1Network Management System
Nov 21, 2024
Jan 30, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Verax NMS prior to 2.1.0 has multiple security bypass vulnerabilities
1Foscam
1Fi8620 Firmware
Nov 21, 2024
Jan 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /log/ directories, which could let a malicious user obtain sensitive information.
1Jenkins
1Jenkins
Jun 17, 2026
Jan 29, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart.
2Debian
Prosody
3Debian Linux
Mod Auth LdapMod Auth Ldap2
Jun 17, 2026
Jan 28, 2020
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their...Show more
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username of a local admin.Show less
1Micasaverde
1Veralite Firmware
Nov 21, 2024
Jan 28, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via the squashfs parameter to upgrade_step2.sh or (2) obtain hashed passwor...Show more
MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via the squashfs parameter to upgrade_step2.sh or (2) obtain hashed passwords via the cgi-bin/cmh/backup.sh page.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 28, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.