CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,363 vulnerabilities with CWE-863
CVE-2026-26289 HIGH
Subnet Solutions PowerSYSTEM Center Incorrect Authorization
CVSS 8.2
CVE-2026-44221 CRITICAL
ArcadeDB: Cross-database authorization bypass and unsecured newly-created databases
CVSS 9.0
CVE-2026-42889 CRITICAL
Relay Server WebSocket authentication bypass when token is omitted
CVSS 9.1
CVE-2026-34646 HIGH
Adobe Commerce | Incorrect Authorization (CWE-863)
CVSS 7.5
CVE-2026-34645 HIGH
Adobe Commerce | Incorrect Authorization (CWE-863)
CVSS 7.5
CVE-2026-34660 CRITICAL
Adobe Connect | Incorrect Authorization (CWE-863)
CVSS 9.3
CVE-2026-2465 HIGH
Improper Authorization in E-Kalite's Turboard FOR-S
CVSS 8.8
CVE-2026-43913 HIGH
Vaultwarden: Unconfirmed Owner Can Purge Entire Organization Vault
CVSS 8.1
CVE-2026-43889 MEDIUM
Outline: Unauthorized Document Publication via Mixed collectionId+documentId Share
CVSS 6.5
CVE-2026-28951 HIGH
iOS and iPadOS < 18.7.9 and < 26.5, macOS < 14.8.7, < 15.7.7, and < 26.5 - Authorization Bypass to Root Privileges
CVSS 7.8
CVE-2026-28873 HIGH
iOS and iPadOS < 18.7.9 and < 26.4 - Incorrect Authorization
CVSS 7.5
CVE-2026-42884 MEDIUM
Audiobookshelf: Collection endpoints bypass library access controls exposing restricted library data
CVSS 4.3
CVE-2026-42883 MEDIUM
Audiobookshelf: Cross-library file exfiltration via unscoped bulk download endpoint
CVSS 6.5
CVE-2026-42882 CRITICAL
oxyno-zeta/s3-proxy: Security Issues in Resource Path Matching
CVSS 9.4
CVE-2026-45002 MEDIUM
OpenClaw < 2026.4.20 - Hook Session-Key Bypass via Template Mapping
CVSS 5.3
CVE-2026-44998 MEDIUM
OpenClaw < 2026.4.20 - Tool Policy Bypass via Bundled MCP/LSP Tools
CVSS 5.4
CVE-2026-44991 MEDIUM
OpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel Senders
CVSS 4.2
CVE-2026-42313 HIGH
pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy
CVSS 8.3
CVE-2026-42312 MEDIUM
pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification
CVSS 6.8
CVE-2026-42843 HIGH
grav-plugin-api: Grav API Privilege Escalation to Super Admin
CVSS 8.8
CVE-2026-42349 HIGH
Clerk: Authorization bypass when combining organization, billing, or reverification checks
CVSS 8.1
CVE-2026-42610 MEDIUM
Grav: Sensitive Information Disclosure via Accounts Service Bypass
CVSS 6.5
CVE-2026-42571 CRITICAL
Privilege Escalation Attack affecting Pelican Web UI
CVE-2026-42296 HIGH
Argo Workflows < 3.7.14/4.0.5 templateReferencing - Strict Mode Bypass
CVSS 8.1
CVE-2026-42137 MEDIUM
Kirby: `pages.access/list` and `files.access/list` permissions are not consistently checked in the REST API and changes dialog
CVSS 6.5
Details
Vulnerabilities 3,363
Exploit Likelihood High