CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,362 vulnerabilities with CWE-863
CVE-2026-13484 MEDIUM
MLflow Experiment-scoped Label Schema CRUD API authorization
CVSS 5.0
CVE-2026-58056 HIGH
RustDesk - FileTransfer Session Authorization Scope Bypass
CVSS 7.6
CVE-2026-53577 MEDIUM
Kestra: Cross-Execution File Read via Preview Endpoint (IDOR)
CVSS 6.5
CVE-2026-55189 HIGH
RustFS: FTP frontend skips IAM authorization on object reads
CVSS 7.7
CVE-2026-55188 HIGH
RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials
CVSS 8.2
CVE-2026-52779 MEDIUM
OpenProject Calendar and Team Planner - Cross-Project Authorization Bypass
CVSS 5.4
CVE-2026-44735 MEDIUM
OpenProject: Shares API Information Disclosure
CVSS 6.5
CVE-2026-9640 HIGH
Canonical - LXD Snapshot Import Privilege Escalation Vulnerability
CVSS 7.2
CVE-2026-54096 HIGH
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
CVSS 8.4
CVE-2026-54091 HIGH
File Browser: Incorrect access control in public directory shares via rule path rebasing
CVSS 7.5
CVE-2026-55411 MEDIUM
ToolJet < 3.20.1780-lts - Cross-Tenant Credential Decryption
CVSS 6.8
CVE-2026-54573 MEDIUM
Authorization Bypass in API Key/OAuth Scopes via Path Parsing Discrepancy
CVE-2026-5952 MEDIUM
Incorrect Authorization in GitLab
CVSS 4.3
CVE-2026-5796 MEDIUM
Incorrect Authorization in GitLab
CVSS 4.3
CVE-2026-11379 MEDIUM
Incorrect Authorization in GitLab
CVSS 5.3
CVE-2026-0934 LOW
Incorrect Authorization in GitLab
CVSS 3.8
CVE-2026-52808 HIGH
Gogs: Write-level collaborators can mutate admin-only repository settings via API
CVSS 7.1
CVE-2026-52795 MEDIUM
Gogs: Authorization Bypass in Watch API allows any user to monitor private repository activity
CVSS 4.3
CVE-2026-56232 HIGH
Capgo - Subkey Scope Bypass in middlewareKey via x-limited-key-id Header
CVSS 8.8
CVE-2026-48493 MEDIUM
Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
CVSS 5.5
CVE-2026-54518 MEDIUM
jackson-databind: @JsonView bypass for unwrapped creator parameters in jackson-databind
CVSS 6.5
CVE-2026-54517 MEDIUM
jackson-databind: @JsonView bypass for setterless creator properties
CVSS 5.3
CVE-2026-46549 LOW
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
CVSS 2.0
CVE-2026-23513 HIGH
FOSSBilling: Broken Authorization in Client Transaction and Order Listings
CVE-2026-54761 HIGH
Traefik < 3.6.21 and 3.7.0-ea.1-3.7.4 - Gateway Namespace Bypass
CVSS 7.1
Details
Vulnerabilities 3,362
Exploit Likelihood High