CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,359 vulnerabilities with CWE-863
CVE-2026-7868 MEDIUM
This Power System update is being released to address incorrect authorization
CVSS 6.5
CVE-2026-14167 HIGH
ads-tec Industrial IT: Privilege escalation during configuration import
CVSS 8.8
CVE-2026-43672 HIGH
macOS < 14.8.8, < 15.7.8, < 26.6 - Privacy Preferences Bypass
CVSS 7.1
CVE-2026-42016 HIGH
Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation
CVSS 8.1
CVE-2026-17568 HIGH
Devolutions Server - Incorrect Authorization
CVSS 8.8
CVE-2026-17530 MEDIUM
AstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset authorization
CVSS 6.3
CVE-2026-17529 MEDIUM
AstrBotDevs AstrBot astr_main_agent.py authorization
CVSS 6.3
CVE-2026-59689 HIGH
Progress LoadMaster Family - Authenticated Root Privilege Escalation
CVSS 8.0
CVE-2026-17039 LOW
Pki-core: dogtag-pki: redhat-pki: pki-core: ca renewal request processing omits realm authorization check performed by enrollment path
CVSS 3.1
CVE-2026-8789 HIGH
Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Arbitrary Connection Deletion
CVSS 8.1
CVE-2026-15704 CRITICAL
CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components
CVSS 9.8
CVE-2026-15630 CRITICAL
Casdoor < v3.115.0 - Authenticated Cross-Tenant Resource Manipulation via ID Parameter Mismatch
CVSS 9.9
CVE-2026-59678 HIGH
Linux-Gaming PortProtonQt - Unauthorized Mount and Network Changes
CVE-2026-13068 MEDIUM
MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database Privilege Misuse
CVSS 4.2
CVE-2026-13067 MEDIUM
tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket
CVSS 6.3
CVE-2026-13061 MEDIUM
Improper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation Stage
CVSS 4.3
CVE-2026-13060 MEDIUM
$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access
CVSS 6.5
CVE-2026-65602 MEDIUM
Traefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass
CVE-2026-65601 MEDIUM
Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef
CVE-2026-65596 HIGH
n8n before 1.123.64 Credential Exfiltration via GraphQL Node
CVSS 8.1
CVE-2026-65594 MEDIUM
n8n before 2.30.1 Missing OAuth Authorization Check
CVSS 6.5
CVE-2026-65015 HIGH
n8n before 2.30.1 Privilege Escalation via run_node_tool
CVSS 8.8
CVE-2026-63145 MEDIUM
Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity Compromise
CVSS 4.3
CVE-2026-63142 MEDIUM
Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery
CVSS 5.0
CVE-2026-61325 HIGH
Oracle Advanced Benefits 12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 7.6
Details
Vulnerabilities 3,359
Exploit Likelihood High