CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,363 vulnerabilities with CWE-863
CVE-2026-42426 HIGH
OpenClaw < 2026.4.8 - Improper Authorization in node.pair.approve via operator.write Scope
CVSS 8.8
CVE-2026-42422 HIGH
OpenClaw < 2026.4.8 - Role Bypass in device.token.rotate Function
CVSS 8.8
CVE-2026-41910 MEDIUM
OpenClaw < 2026.4.8 - Missing Owner-Only Enforcement in /allowlist Cross-Channel Writes
CVSS 4.3
CVE-2026-41404 HIGH
OpenClaw < 2026.3.31 - Operator Admin Privilege Escalation via Trusted-Proxy Authentication
CVSS 8.8
CVE-2026-41381 MEDIUM
OpenClaw < 2026.3.31 - Access Control Bypass in Discord Voice Manager via Channel Allowlist
CVSS 5.4
CVE-2026-41379 HIGH
OpenClaw < 2026.3.28 - Privilege Escalation via chat.send to Admin-Class Talk Voice Config
CVSS 7.1
CVE-2026-41375 MEDIUM
OpenClaw < 2026.3.28 - Authorization Bypass in /phone arm and /phone disarm Endpoints
CVSS 6.5
CVE-2026-41371 HIGH
OpenClaw < 2026.3.28 - Privilege Escalation via chat.send Reset Command
CVSS 8.5
CVE-2026-41367 MEDIUM
OpenClaw 2026.2.14 < 2026.3.28 - Policy Enforcement Bypass in Discord Component Interactions
CVSS 5.0
CVE-2026-41248 CRITICAL
Official Clerk JavaScript SDKs: Middleware-based route protection bypass
CVSS 9.1
CVE-2026-41427 MEDIUM
Better Auth OAuth 2.1 Provider: Unprivileged users can register OAuth clients
CVSS 6.5
CVE-2026-30368 MEDIUM
Lightspeed Classroom 5.1.2.1763770643 - Auth Bypass
CVSS 5.4
CVE-2026-25660 CRITICAL
Authentication bypass for certain API calls
CVSS 9.8
CVE-2026-23902 HIGH
Apache DolphinScheduler: Users are able to use tenants that are not defined on the platform during workflow execution.
CVSS 8.1
CVE-2026-41068 HIGH
Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)
CVSS 7.7
CVE-2026-41325 HIGH
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
CVSS 8.8
CVE-2026-40099 MEDIUM
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
CVSS 6.5
CVE-2026-41350 MEDIUM
OpenClaw < 2026.3.31 - Session Visibility Bypass via session_status in Unsandboxed Invocations
CVSS 4.3
CVE-2026-41348 MEDIUM
OpenClaw < 2026.3.31 - Group DM Channel Allowlist Bypass via Discord Slash Commands
CVSS 5.4
CVE-2026-41344 MEDIUM
OpenClaw < 2026.3.28 - Privilege Escalation via chat.send /verbose Parameter
CVSS 5.4
CVE-2026-41909 MEDIUM
OpenClaw < 2026.4.20 - Improper Authorization in Paired-Device Pairing Actions
CVSS 5.4
CVE-2026-41908 MEDIUM
OpenClaw < 2026.4.20 - Scope Enforcement Bypass in Assistant-Media Route
CVSS 4.3
CVE-2026-41233 MEDIUM
Froxlor <2.3.6 Domains.add() - Reseller Quota Bypass
CVSS 5.4
CVE-2026-41232 MEDIUM
Froxlor <2.3.6 EmailSender::add() - Domain Ownership Bypass
CVSS 5.0
CVE-2026-5377 MEDIUM
Incorrect Authorization in GitLab
CVSS 4.3
Details
Vulnerabilities 3,363
Exploit Likelihood High