CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

2,832 vulnerabilities with CWE-863
CVE-2026-41348 MEDIUM
OpenClaw < 2026.3.31 - Group DM Channel Allowlist Bypass via Discord Slash Commands
CVSS 5.4
CVE-2026-41344 MEDIUM
OpenClaw < 2026.3.28 - Privilege Escalation via chat.send /verbose Parameter
CVSS 5.4
CVE-2026-41909 MEDIUM
OpenClaw < 2026.4.20 - Improper Authorization in Paired-Device Pairing Actions
CVSS 5.4
CVE-2026-41908 MEDIUM
OpenClaw < 2026.4.20 - Scope Enforcement Bypass in Assistant-Media Route
CVSS 4.3
CVE-2026-41233 MEDIUM
Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add()
CVSS 5.4
CVE-2026-41232 MEDIUM
Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index that Allows Cross-Customer Email Spoofing
CVSS 5.0
CVE-2026-5377 MEDIUM
Incorrect Authorization in GitLab
CVSS 4.3
CVE-2026-35370 MEDIUM
uutils coreutils id Incorrect Access-Control Decisions via Misrepresented Group Membership
CVSS 4.4
CVE-2026-41131 MEDIUM
OpenFGA has Improper Policy Enforcement
CVSS 5.0
CVE-2026-40599 HIGH
ClearanceKit: Ad-hoc signed binaries can spoof Apple process identities in the global allowlist
CVSS 7.1
CVE-2026-41191 HIGH
FreeScout's signature only mailbox permission allows unauthorized mailbox chat setting changes
CVSS 7.1
CVE-2026-41190 HIGH
FreeScout has assigned-only visibility bypass via save_draft that allows hidden conversation draft injection
CVSS 7.1
CVE-2026-41189 HIGH
FreeScout has assigned-only visibility bypass that allows editing hidden customer-authored threads
CVSS 7.1
CVE-2026-40574 MEDIUM
OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims
CVSS 6.8
CVE-2026-29179 LOW
October: Editor Sub-Permission Bypass for Asset and Blueprint File Operations
CVSS 3.3
CVE-2026-26274 MEDIUM
October: Safe Mode Bypass via Twig Database Write Operations
CVSS 6.6
CVE-2026-26067 MEDIUM
October: Safe Mode Bypass via CSS Preprocessor Compilers
CVSS 4.9
CVE-2026-24176 MEDIUM
NVIDIA KAI Scheduler <0.13.0 - Auth Bypass
CVSS 4.3
CVE-2026-41303 HIGH
OpenClaw < 2026.3.28 - Authorization Bypass in Discord Text Approval Commands
CVSS 8.8
CVE-2026-34082 MEDIUM
Dify has IDOR in deleting someone else's chat conversation
CVSS 4.3
CVE-2026-33031 HIGH
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens
CVSS 8.1
CVE-2026-32228 HIGH
Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to
CVSS 7.5
CVE-2026-40350 HIGH
Movary User Management (/settings/users) has Authorization Bypass that Allows Low-Privileged Users to Enumerate All Users and Create Administrator Accounts
CVSS 8.8
CVE-2026-40304 MEDIUM
zrok's broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records
CVSS 5.3
CVE-2026-40155 MEDIUM
Auth0 Next.js SDK has Improper Proxy Cache Lookup
CVSS 5.4
Details
Vulnerabilities 2,832
Exploit Likelihood High