CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,362 vulnerabilities with CWE-863
CVE-2026-54555 HIGH
rtk: Permission-gate bypass in rtk rewrite auto-allow via unsplit shell separators
CVSS 7.8
CVE-2026-54321 HIGH
Daytona: Public sandbox previews remain accessible for up to one hour after being made private
CVSS 7.0
CVE-2026-54320 HIGH
Daytona: Cross-tenant organization takeover via invitation acceptance with an unverified email
CVSS 8.4
CVE-2026-54324 MEDIUM
Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
CVSS 6.5
CVE-2026-54022 MEDIUM
Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
CVSS 5.3
CVE-2026-54021 MEDIUM
Open WebUI < 0.9.6 - Authenticated Ollama Backend Access Control Bypass
CVSS 6.3
CVE-2026-49983 MEDIUM
Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access
CVSS 5.2
CVE-2026-45692 MEDIUM
Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
CVSS 5.4
CVE-2026-54307 CRITICAL
n8n: Credential Exfiltration via Permission Bypass
CVSS 9.6
CVE-2026-56694 MEDIUM
NanoClaw < 2.1.0 - Privilege Escalation via Forged Channel Approval Callback
CVSS 5.4
CVE-2026-27604 CRITICAL
FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin Functions
CVE-2026-56268 HIGH
Flowise - Cross-Workspace Information Disclosure via chatflows/apikey Endpoint
CVSS 7.7
CVE-2026-54281 HIGH
Nest: Middleware Bypass on Fastify via Trailing Slash
CVE-2026-8823 LOW
User Manager can demote bot accounts to guest without bot-management permission
CVSS 3.8
CVE-2026-41049 HIGH
Caching of Authentication allows Authentication Bypass between users in qSnapper
CVSS 7.1
CVE-2026-41048 HIGH
Caching of Authentication allows Authentication Bypass in qSnapper
CVSS 7.1
CVE-2026-8074 LOW
Improper Permission Check Allows User Manager to Deactivate Bot Accounts
CVSS 3.8
CVE-2026-56424 HIGH
MISP Core - Cross-Organization Data Modification and Deletion
CVSS 8.8
CVE-2026-44911 MEDIUM
Apache NiFi: Incorrect Authorization for Configuration Verification Requests
CVSS 6.3
CVE-2026-12797 MEDIUM
BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization
CVSS 6.3
CVE-2026-50559 HIGH
Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
CVSS 7.5
CVE-2026-48794 LOW
Authelia has an Edge Case Access Control Rule Mismatch
CVE-2026-48772 CRITICAL
ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rules.client_addr ACL
CVSS 10.0
CVE-2026-48089 HIGH
DevGuard has improper authorization on public assets
CVE-2026-49288 MEDIUM
Statamic CMS < 5.73.23 and 6.x < 6.20.0 - Control Panel Resource Disclosure
CVSS 4.3
Details
Vulnerabilities 3,362
Exploit Likelihood High