CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,363 vulnerabilities with CWE-863
CVE-2026-49288 MEDIUM
Statamic CMS < 5.73.23 and 6.x < 6.20.0 - Control Panel Resource Disclosure
CVSS 4.3
CVE-2026-47339 HIGH
Apache APISIX: authz-casdoor incorrect session sharing
CVSS 8.1
CVE-2026-56075 HIGH
PraisonAI - Arbitrary Shell Command Execution via Hardcoded Approval Mode Override
CVSS 8.8
CVE-2026-56074 MEDIUM
PraisonAI - Tool Approval Cache Bypass via Coarse-Grained Caching
CVSS 5.5
CVE-2026-10741 MEDIUM
Sonatype Nexus Repository Manager < 3.93.0 - Proxy Credential Disclosure
CVSS 4.9
CVE-2026-54803 CRITICAL
WordPress SMS Alert Order Notifications plugin <= 3.9.4 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-48781 CRITICAL
Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
CVSS 9.9
CVE-2026-42357 MEDIUM
Apache DolphinScheduler < 3.4.2 - Unauthorized Workflow Instance Access
CVSS 6.5
CVE-2026-41280 MEDIUM
Apache DolphinScheduler < 3.4.2 - Unauthorized Task Definition Deletion
CVSS 4.9
CVE-2026-32967 CRITICAL
Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
CVSS 9.1
CVE-2026-32966 CRITICAL
Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
CVSS 9.8
CVE-2026-12446 MEDIUM
Google Chrome < 149.0.7827.155 - Cross-Origin Data Leak via Passwords Implementation
CVSS 4.3
CVE-2026-48776 MEDIUM
langchain-ai - LangGraph SDK Has Unsafe URL Path Construction
CVSS 4.2
CVE-2026-53860 MEDIUM
OpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifiers in BlueBubbles
CVSS 4.2
CVE-2026-53855 HIGH
OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks
CVSS 8.1
CVE-2026-53854 MEDIUM
OpenClaw < 2026.4.25 - Privilege Escalation via ownerAllowFrom Wildcard Inheritance in Internal/Webchat Commands
CVSS 6.5
CVE-2026-53853 HIGH
OpenClaw < 2026.5.12 - Argument Pattern Bypass in Exec Allowlist via Linux and macOS
CVSS 8.3
CVE-2026-5149 MEDIUM
RTMKit <= 2.0.7 - Authenticated (Contributor+) Missing Authorization to Arbitrary Form Submission Access via 'entries_id' Parameter
CVSS 6.5
CVE-2026-47777 HIGH
Mastodon has a consent-check bypass in its remote Collections
CVSS 7.5
CVE-2026-34023 HIGH
Wertheim SafeController 6.15.8328.28014 - WebSocket Authorization Bypass
CVE-2026-2470 MEDIUM
Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts'
CVSS 4.3
CVE-2026-54398 MEDIUM
MISP object edit authorization bypass allows unauthorized sharing group assignment
CVE-2026-53835 MEDIUM
OpenClaw < 2026.5.6 - Config-Write Enforcement Bypass in Feishu Dynamic-Agent Bindings
CVSS 4.3
CVE-2026-53834 HIGH
OpenClaw < 2026.4.27 - Authorization Bypass in QQBot Pre-dispatch Slash Commands
CVSS 7.5
CVE-2026-53828 HIGH
OpenClaw < 2026.5.6 - Native Command Authorization Bypass via Owner-Command Enforcement
CVSS 8.8
Details
Vulnerabilities 3,363
Exploit Likelihood High