CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,047 vulnerabilities with CWE-863
CVE-2026-30863 CRITICAL
Parse Server <8.6.10/9.5.0-alpha.11 - Auth Bypass
CVSS 9.8
CVE-2026-30854 MEDIUM
Parse Server 9.3.1-alpha.3-9.5.0-alpha.10 - Info Disclosure
CVSS 5.3
CVE-2026-29196 MEDIUM
Netmaker < 1.5.0 - Incorrect Authorization via API Endpoints
CVSS 4.3
CVE-2026-29195 MEDIUM
Netmaker <1.5.0 - Privilege Escalation
CVSS 6.5
CVE-2026-29194 HIGH
Netmaker < 1.5.0 - Incorrect Authorization via Host JWT Token Bypass
CVSS 8.1
CVE-2026-30820 HIGH
Flowise <3.0.13 - Privilege Escalation
CVSS 8.8
CVE-2026-30241 HIGH
mercurius < 16.8.0 - Incorrect Authorization via WebSocket Subscription Query Depth Bypass
CVSS 8.2
CVE-2026-30229 HIGH
Parse Server <8.6.6/9.5.0-alpha.4 - Auth Bypass
CVSS 7.2
CVE-2026-30228 MEDIUM
Parse Server <8.6.5/9.5.0-alpha.3 - Auth Bypass
CVSS 4.9
CVE-2026-29182 HIGH
Parse Server <8.6.4/9.4.1-alpha.3 - Privilege Escalation
CVSS 7.2
CVE-2026-29087 HIGH
@hono/node-server <1.19.10 - Auth Bypass
CVSS 7.5
CVE-2026-23925 HIGH
Zabbix - Authenticated Incorrect Authorization via configuration.import API
CVSS 8.1
CVE-2026-28726 MEDIUM
Acronis Cyber Protect 17 - Info Disclosure
CVSS 4.3
CVE-2026-28724 MEDIUM
Acronis Cyber Protect 17 <41186 - Auth Bypass
CVSS 4.3
CVE-2026-28723 MEDIUM
Acronis Cyber Protect 17 <41186 - Auth Bypass
CVSS 4.3
CVE-2026-28720 MEDIUM
Acronis Cyber Protect 17 - Privilege Escalation
CVSS 4.3
CVE-2026-28719 MEDIUM
Acronis Cyber Protect 17 - Privilege Escalation
CVSS 4.3
CVE-2026-28716 MEDIUM
Acronis Cyber Protect 17 <41186 - Info Disclosure
CVSS 4.4
CVE-2026-28715 MEDIUM
Acronis Cyber Protect 17 - Info Disclosure
CVSS 6.5
CVE-2026-28709 MEDIUM
Acronis Cyber Protect 17 <41186 - Auth Bypass
CVSS 4.3
CVE-2026-28474 CRITICAL
OpenClaw Nextcloud Talk <2026.2.6 - Auth Bypass
CVSS 9.8
CVE-2026-28473 HIGH
OpenClaw < 2026.2.2 - Authorization Bypass via /approve Chat Command
CVSS 8.1
CVE-2026-28466 CRITICAL
OpenClaw <2026.2.14 - Command Injection
CVSS 9.9
CVE-2026-28392 HIGH
OpenClaw <2026.2.14 - Privilege Escalation
CVSS 7.5
CVE-2026-28790 HIGH
olivetin < 3000.11.0 - Unauthenticated Denial of Service via KillAction RPC
CVSS 7.5
Details
Vulnerabilities 3,047
Exploit Likelihood High