← Back
CWE-863

3,780 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

JSON object

Loading...

CVEs (3,780)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Avas!t
1Secure Browser
Jun 17, 2026
Jan 27, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the AvastBrowserUpdate.exe (which is running as NT AUTHORITY\SYSTEM) when AvastS...Show more
A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the AvastBrowserUpdate.exe (which is running as NT AUTHORITY\SYSTEM) when AvastSecureBrowser.exe checks for new updates. When the update check is triggered, the elevated process cleans the ACL of the Update.ini file in %PROGRAMDATA%\Avast Software\Browser\Update\ and sets all privileges to group Everyone. Because any low-privileged user can create, delete, or modify the Update.ini file stored in this location, an attacker with low privileges can create a hard link named Update.ini in this folder, and make it point to a file writable by NT AUTHORITY\SYSTEM. Once AvastBrowserUpdate.exe is triggered by the update check functionality, the DACL is set to a misconfigured value on the crafted Update.ini and, consequently, to the target file that was previously not writable by the low-privileged attacker.Show less
1Jenkins
1Sounds
Jun 17, 2026
Jan 15, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing attackers with Overall/Read access to execute arbitrary OS commands as the OS user account running Jen...Show more
Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing attackers with Overall/Read access to execute arbitrary OS commands as the OS user account running Jenkins.Show less
1Sap
1Basis
Jun 17, 2026
Jan 14, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitive information.
1Arialsoftware
1Campaign Enterprise
Nov 21, 2024
Jan 10, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malicious user modify the SerialNumber field.
1Arialsoftware
1Campaign Enterprise
Nov 21, 2024
Jan 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate users' credentials.
1Mozilla
1Firefox
Jun 17, 2026
Jan 8, 2020
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-origin information leak. This vulnerability affects Firefox < 71.
1Symantec
1Norton App Lock
Nov 21, 2024
Jan 8, 2020
N/A· v4
7.1 HIGH· v3
3.3 LOW· v2
A security bypass vulnerability exists in Symantec Norton App Lock 1.0.3.186 and earlier if application pinning is enabled, which could let a local malicious user bypass security restrictions.
1Redhat
2Jboss Enterprise Application Platform
Single Sign On
Jun 17, 2026
Jan 7, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized informatio...Show more
A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7 are vulnerable to this issue.Show less
1Schneider Electric
23Ecostruxure Control Expert
Modicon M340 Bmxp341000 FirmwareModicon M340 Bmxp342000 Firmware+20 more
Jun 17, 2026
Jan 6, 2020
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior...Show more
Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control Expert and the M340 and M580 controllers.Show less
1Redhat
1Jboss Enterprise Application Platform
Nov 21, 2024
Jan 2, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resourc...Show more
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality, it was not clearly documented which can mislead users into thinking that a security domain cache is isolated to a single application.Show less
2Obs Server
Suse
2Linux Enterprise Server
Obs Server
Nov 21, 2024
Jan 2, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation.
1Dlink
14Dir 818lx Firmware
Dir 822 FirmwareDir 823 Firmware+11 more
Jun 17, 2026
Jan 2, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.
1Gencat
1Portal D'acces A La Universitat
Jun 17, 2026
Dec 31, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Java API in accesuniversitat.gencat.cat 1.7.5 allows remote attackers to get personal information of all registered students via several API endpoints.
1Gitlab
1Gitlab
Nov 21, 2024
Dec 30, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
1Gitlab
1Gitlab
Nov 21, 2024
Dec 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
1Gitlab
1Gitlab
Nov 21, 2024
Dec 30, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Jun 17, 2026
Dec 30, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private information. An attacker could exploit this vulnerability to access content that...Show more
IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private information. An attacker could exploit this vulnerability to access content that should be restricted. IBM X-Force ID: 161422.Show less
1Vivotek
3Ip7160 Firmware
Ip7361 FirmwareIp8332 Firmware
Nov 21, 2024
Dec 27, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
1Gitlab
1Gitlab
Nov 21, 2024
Dec 26, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control (issue 2 of 6).
1Artica
1Pandora Fms
Jun 17, 2026
Dec 26, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to define and execute commands as root/Administrator. NOTE: The product vendor...Show more
Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to define and execute commands as root/Administrator. NOTE: The product vendor states that the vulnerability as it is described is not in fact an actual vulnerability. They state that to be able to create alert commands, you need to have admin rights. They also state that the extended ACL system can disable access to specific sections of the configuration, such as defining new alert commandsShow less