The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,363 vulnerabilities with CWE-863
CVE-2026-26289
HIGH
Subnet Solutions PowerSYSTEM Center Incorrect Authorization
CVSS 8.2
CVE-2026-44221
CRITICAL
ArcadeDB: Cross-database authorization bypass and unsecured newly-created databases
CVSS 9.0
CVE-2026-42889
CRITICAL
Relay Server WebSocket authentication bypass when token is omitted
CVSS 9.1
CVE-2026-34646
HIGH
Adobe Commerce | Incorrect Authorization (CWE-863)
CVSS 7.5
CVE-2026-34645
HIGH
Adobe Commerce | Incorrect Authorization (CWE-863)
CVSS 7.5
CVE-2026-34660
CRITICAL
Adobe Connect | Incorrect Authorization (CWE-863)
CVSS 9.3
CVE-2026-2465
HIGH
Improper Authorization in E-Kalite's Turboard FOR-S
CVSS 8.8
CVE-2026-43913
HIGH
Vaultwarden: Unconfirmed Owner Can Purge Entire Organization Vault
CVSS 8.1
CVE-2026-43889
MEDIUM
Outline: Unauthorized Document Publication via Mixed collectionId+documentId Share
CVSS 6.5
CVE-2026-28951
HIGH
iOS and iPadOS < 18.7.9 and < 26.5, macOS < 14.8.7, < 15.7.7, and < 26.5 - Authorization Bypass to Root Privileges
CVSS 7.8
CVE-2026-28873
HIGH
iOS and iPadOS < 18.7.9 and < 26.4 - Incorrect Authorization
CVSS 7.5
CVE-2026-42884
MEDIUM
Audiobookshelf: Collection endpoints bypass library access controls exposing restricted library data
CVSS 4.3
CVE-2026-42883
MEDIUM
Audiobookshelf: Cross-library file exfiltration via unscoped bulk download endpoint
CVSS 6.5
CVE-2026-42882
CRITICAL
oxyno-zeta/s3-proxy: Security Issues in Resource Path Matching
CVSS 9.4
CVE-2026-45002
MEDIUM
OpenClaw < 2026.4.20 - Hook Session-Key Bypass via Template Mapping
CVSS 5.3
CVE-2026-44998
MEDIUM
OpenClaw < 2026.4.20 - Tool Policy Bypass via Bundled MCP/LSP Tools
CVSS 5.4
CVE-2026-44991
MEDIUM
OpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel Senders
CVSS 4.2
CVE-2026-42313
HIGH
pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy
CVSS 8.3
CVE-2026-42312
MEDIUM
pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification
CVSS 6.8
CVE-2026-42843
HIGH
grav-plugin-api: Grav API Privilege Escalation to Super Admin
CVSS 8.8
CVE-2026-42349
HIGH
Clerk: Authorization bypass when combining organization, billing, or reverification checks
CVSS 8.1
CVE-2026-42610
MEDIUM
Grav: Sensitive Information Disclosure via Accounts Service Bypass
CVSS 6.5
CVE-2026-42571
CRITICAL
Privilege Escalation Attack affecting Pelican Web UI
CVE-2026-42296
HIGH
Argo Workflows < 3.7.14/4.0.5 templateReferencing - Strict Mode Bypass
CVSS 8.1
CVE-2026-42137
MEDIUM
Kirby: `pages.access/list` and `files.access/list` permissions are not consistently checked in the REST API and changes dialog
CVSS 6.5
Details
Vulnerabilities
3,363
Exploit Likelihood
High