CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,363 vulnerabilities with CWE-863
CVE-2026-10860 MEDIUM
MISP CRUDComponent delete validation bypass via operator precedence error
CVSS 6.5
CVE-2026-41283 CRITICAL
Openstack Mistral - Incorrect Authorization
CVSS 9.9
CVE-2026-44654 HIGH
LibreChat: Shared-agent editor can globally delete owner's file records — breaks owner's other private agents
CVSS 8.1
CVE-2026-35482 HIGH
alf.io <2.0-M5-2606 Extension Scripts - Sandbox Escape
CVSS 8.0
CVE-2026-10616 MEDIUM
nextlevelbuilder GoClaw Team Task Completion team_tasks_lifecycle.go TeamTasksTool.executeComplete authorization
CVSS 4.3
CVE-2026-3514 HIGH
Authentication Bypass in prefecthq/prefect
CVSS 7.5
CVE-2026-9048 MEDIUM
Slider Revolution 7.0.0-7.0.14 - Authenticated Sensitive Information Exposure via slider.get.full AJAX Action
CVSS 4.3
CVE-2026-22872 CRITICAL
Capsule < 0.13.0 - Authenticated Privilege Escalation via TenantResource RawItems Processing
CVSS 9.1
CVE-2026-45426 LOW
Apache Airflow Log Server - JWT Authorization Bypass
CVSS 3.1
CVE-2026-10211 MEDIUM
AstrBotDevs AstrBot fs.py _normalize_rw_path authorization
CVSS 6.3
CVE-2026-49376 MEDIUM
Jetbrains TeamCity < 2026.1 - Incorrect Authorization
CVSS 6.5
CVE-2026-49369 MEDIUM
Jetbrains YouTrack < 2026.1.13162 - Incorrect Authorization
CVSS 4.3
CVE-2026-48501 HIGH
GitHub CLI tokens leak via `gh attestation` commands
CVSS 7.4
CVE-2026-35674 HIGH
OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route
CVSS 8.8
CVE-2026-35673 MEDIUM
OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes
CVSS 6.5
CVE-2026-34507 MEDIUM
OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks
CVSS 5.4
CVE-2026-32906 MEDIUM
OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Gate
CVSS 4.3
CVE-2026-9808 HIGH
Mautic 7 - Authenticated Authorization Bypass in API v2 Endpoints
CVSS 7.1
CVE-2026-49299 MEDIUM
Openstack Neutron - Incorrect Authorization
CVE-2026-44882 HIGH
Portainer: Kubernetes middleware continues after token validation failure, bypassing endpoint authorization
CVSS 8.1
CVE-2026-44850 HIGH
Portainer: Bind-mount restriction bypass via HostConfig.Mounts
CVSS 8.5
CVE-2026-46823 HIGH
Oracle Public Sector Financials (International) 12.2.6-12.2.15 - Unauthorized Data Access via Authorization Component
CVSS 7.7
CVE-2026-42070 MEDIUM
MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API
CVE-2026-45042 HIGH
RustFS: UploadPartCopy Does Not Enforce Destination Bucket Policy on Copy Source
CVE-2026-44394 MEDIUM
Openstack Keystone - Incorrect Authorization
CVSS 6.0
Details
Vulnerabilities 3,363
Exploit Likelihood High