CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,041 vulnerabilities with CWE-863
CVE-2026-5149 MEDIUM
RTMKit <= 2.0.7 - Authenticated (Contributor+) Missing Authorization to Arbitrary Form Submission Access via 'entries_id' Parameter
CVSS 6.5
CVE-2026-47777 HIGH
Mastodon has a consent-check bypass in its remote Collections
CVSS 7.5
CVE-2026-34023 HIGH
Wertheim SafeController 6.15.8328.28014 - WebSocket Authorization Bypass
CVE-2026-2470 MEDIUM
Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts'
CVSS 4.3
CVE-2026-54398 MEDIUM
MISP object edit authorization bypass allows unauthorized sharing group assignment
CVE-2026-53835 MEDIUM
OpenClaw < 2026.5.6 - Config-Write Enforcement Bypass in Feishu Dynamic-Agent Bindings
CVSS 4.3
CVE-2026-53834 HIGH
OpenClaw < 2026.4.27 - Authorization Bypass in QQBot Pre-dispatch Slash Commands
CVSS 7.5
CVE-2026-53828 HIGH
OpenClaw < 2026.5.6 - Native Command Authorization Bypass via Owner-Command Enforcement
CVSS 8.8
CVE-2026-53521 MEDIUM
Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context
CVSS 6.4
CVE-2026-49397 MEDIUM
Nezha Monitoring: Private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
CVSS 5.3
CVE-2026-47120 HIGH
Nezha Monitoring - AlertRule Cron Task Ownership Bypass
CVSS 7.1
CVE-2026-46717 HIGH
Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification
CVSS 7.7
CVE-2026-54397 MEDIUM
MISP event editing allows unauthorized assignment to undisclosed sharing groups
CVE-2026-54362 MEDIUM
MISP template builder exposes non-visible custom galaxies across organisations
CVE-2026-54358 HIGH
MISP organization administrators can target site administrator accounts for password reset
CVE-2026-54357 MEDIUM
MISP improper authorization allows organization administrators to modify site administrator user settings
CVE-2026-42604 MEDIUM
Actual has an OpenID `client_secret` Disclosure via Broken Authorization Guard in `/openid/config`
CVE-2026-50008 MEDIUM
Parse Server: Server option routeAllowList is bypassable through batch sub-requests
CVE-2026-47236 MEDIUM
Solidtime team page exposes pending invitation and member emails to employees who lack invitations:view/members:view permission
CVSS 4.3
CVE-2026-44173 MEDIUM
MariaDB: FILE privilege was not checked for subqueries in the FROM clause
CVSS 5.0
CVE-2026-44169 MEDIUM
MariaDB: Authorization bypass in role-based routine-level privilege check exposes stored routine definitions
CVSS 4.3
CVE-2026-7387 HIGH
Mattermost group syncable endpoints allow privilege escalation via scheme_admin
CVSS 8.8
CVE-2026-6739 MEDIUM
Mattermost: Delegated admins could patch protected default system roles
CVSS 6.7
CVE-2026-45831 HIGH
ChromaDB - Incorrect Authorization
CVE-2026-53721 HIGH
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
CVSS 8.2
Details
Vulnerabilities 3,041
Exploit Likelihood High