← Back
CWE-863

3,780 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

JSON object

Loading...

CVEs (3,780)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Icegram
1Email Subscribers & Newsletters
Jun 17, 2026
Dec 26, 2019
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.
1Fermax
1Outdoor Panel Firmware
Nov 21, 2024
Dec 24, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
An access control weakness in the DTMF tone receiver of Fermax Outdoor Panel allows physical attackers to inject a Dual-Tone-Multi-Frequency (DTMF) tone to invoke an access grant that would allow physical access to a res...Show more
An access control weakness in the DTMF tone receiver of Fermax Outdoor Panel allows physical attackers to inject a Dual-Tone-Multi-Frequency (DTMF) tone to invoke an access grant that would allow physical access to a restricted floor/level. By design, only a residential unit owner may allow such an access grant. However, due to incorrect access control, an attacker could inject it via the speaker unit to perform an access grant to gain unauthorized access, as demonstrated by a loud DTMF tone representing '1' and a long '#' (697 Hz and 1209 Hz, followed by 941 Hz and 1477 Hz).Show less
2Apple
Debian
2Cups
Debian Linux
Nov 21, 2024
Dec 20, 2019
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system
1Cloudfoundry
2Capi Release
Cf Deployment
Jun 17, 2026
Dec 19, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.
1Apple
1Iphone Os
Jun 17, 2026
Dec 18, 2019
N/A· v4
5.7 MEDIUM· v3
7.9 HIGH· v2
This issue was addressed with improved transparency. This issue is fixed in iOS 12.2. A user may authorize an enterprise administrator to remotely wipe their device without appropriate disclosure.
1Sap
2Enterprise Extension Financial Services
Treasury And Risk Management (s4core)
Jun 17, 2026
Dec 17, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary autho...Show more
Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for functionalities that require user identity.Show less
1Sap
2Enterprise Extension Financial Services
Treasury And Risk Management (s4core)
Jun 17, 2026
Dec 17, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary autho...Show more
Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.Show less
1Qnap
1Photo Station
Jun 17, 2026
Dec 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
1Dlink
1Dap 1860 Firmware
Jun 17, 2026
Dec 5, 2019
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header.
1Openbsd
1Openbsd
Jun 17, 2026
Dec 5, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlopen.
2Fedoraproject
Reviewboard
2Fedora
Reviewboard
Nov 21, 2024
Dec 3, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Review Board: URL processing gives unauthorized users access to review lists
2Fedoraproject
Reviewboard
2Fedora
Reviewboard
Nov 21, 2024
Dec 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ReviewBoard: has an access-control problem in REST API
1Cloudera
1Cdh
Nov 21, 2024
Nov 26, 2019
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler.
1Cloudera
1Cdh
Nov 21, 2024
Nov 26, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
1Cloudera
1Cdh
Nov 21, 2024
Nov 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
2Debian
Tahoe Lafs
2Debian Linux
Tahoe Lafs
Nov 21, 2024
Nov 26, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.
1Google
1Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.
1Google
1Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
1Redhat
2Ovirt Engine
Virtualization
Nov 21, 2024
Nov 22, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center