CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,359 vulnerabilities with CWE-863
CVE-2026-62323 MEDIUM
Cloudreve: Unauthorized file write via WOPI view sessions whose access token secret is ignored
CVSS 6.3
CVE-2026-55502 HIGH
Cloudreve: OAuth Admin.Read scope can update OneDrive storage policy credentials
CVSS 7.1
CVE-2026-55499 MEDIUM
Cloudreve: Broken access control in file event stream leaks activity events for unshared siblings to single-file share recipients
CVSS 4.3
CVE-2026-14538 MEDIUM
BigQuery Dataset Allowlist Bypass via Metadata Dry-Run in MCP Toolbox
CVE-2026-14537 HIGH
Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints
CVE-2026-10031 MEDIUM
SFTPGo 2.7.4 Permission Bypass via Symbolic Link Creation
CVSS 4.2
CVE-2026-67528 MEDIUM
OpenProject: Improper Access Control through /api/v3/custom_options/:id via Path "id" leads to Sensitive Data Exposure
CVSS 4.3
CVE-2026-65835 MEDIUM
Capsule >= 0.13.0, < 0.13.8 - Cross-Tenant Cluster-Scoped Resource Creation
CVSS 6.6
CVE-2026-67347 MEDIUM
Vendure 3.7.1 Cross-Channel Authorization Bypass via StockLocation and Asset Update
CVSS 6.8
CVE-2026-41187 MEDIUM
Calico Tier Authorization Bypass via DeleteCollection
CVE-2026-14923 MEDIUM
Sync Post With Other Site < 1.9.3 - Contributor+ Arbitrary Page Creation/Modification
CVSS 6.5
CVE-2026-48449 CRITICAL
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
CVSS 10.0
CVE-2026-67439 MEDIUM
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
CVSS 4.3
CVE-2026-65975 MEDIUM
Pydantic AI UI Adapters - Client-Submitted Tool Call Execution
CVSS 6.5
CVE-2026-6336 MEDIUM
Incorrect Authorization in GitLab
CVSS 5.3
CVE-2026-18236 CRITICAL
Google-ADK Continuation Forgery
CVE-2026-54693 HIGH
ZITADEL Users Can Self-Verify Email/Phone via API
CVE-2026-18255 HIGH
Quay: quay: global read-only superuser can view robot account tokens
CVSS 7.2
CVE-2026-44944 HIGH
iscsiuio control-socket authentication bypass in open-iscsi
CVE-2026-58159 HIGH
Apache Traffic Server: Listener and ACL handling allow access-control bypass
CVSS 8.2
CVE-2026-58156 MEDIUM
Apache Traffic Server: URL and port parsing errors allow access-control bypass
CVSS 4.9
CVE-2026-66064 MEDIUM
goshs has ACL Bypass & Path Traversal
CVSS 5.3
CVE-2026-54719 HIGH
goshs < 2.1.1 - Unauthenticated Bulk Download ACL Bypass
CVSS 7.5
CVE-2026-48396 HIGH
Adobe Bridge - Bridge | Incorrect Authorization (CWE-863)
CVSS 8.6
CVE-2026-48390 HIGH
Adobe Bridge - Bridge | Incorrect Authorization (CWE-863)
CVSS 8.2
Details
Vulnerabilities 3,359
Exploit Likelihood High