The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,047 vulnerabilities with CWE-863
CVE-2026-25859
HIGH
Wekan < 8.20 - Incorrect Authorization in Migration Functionality
CVSS 8.8
CVE-2026-25568
MEDIUM
WeKan < 8.19 - Incorrect Authorization via allowPrivateOnly Setting Bypass
CVSS 4.3
CVE-2026-25566
MEDIUM
WeKan < 8.19 - Incorrect Authorization in Card Move Logic
CVSS 5.4
CVE-2026-25565
MEDIUM
WeKan < 8.19 - Incorrect Authorization in Card Update API
CVSS 6.5
CVE-2026-25561
HIGH
WeKan < 8.19 - Incorrect Authorization in Attachment Upload API
CVSS 7.5
CVE-2026-25729
MEDIUM
DeepAudit < 3.0.4 - Authenticated Sensitive Information Disclosure via User Enumeration Endpoint
CVSS 6.5
CVE-2026-23989
HIGH
OpenCloud Reva <2.42.3, <2.40.3 - Auth Bypass
CVSS 8.2
CVE-2026-24851
HIGH
OpenFGA 1.8.5-1.11.2 - Incorrect Authorization via Check Call Policy Enforcement
CVSS 8.8
CVE-2026-23632
MEDIUM
Gogs < 0.13.4 - Incorrect Authorization via PUT /repos/:owner/:repo/contents/* Endpoint
CVSS 6.5
CVE-2026-23572
HIGH
TeamViewer <15.74.5 - Privilege Escalation
CVSS 7.2
CVE-2026-1897
MEDIUM
WeKan < 8.21 - Missing Authorization in Position-History Tracking
CVSS 4.3
CVE-2026-1553
MEDIUM
Drupal Canvas < 1.0.4 - Incorrect Authorization via Forceful Browsing
CVSS 4.8
CVE-2026-1734
MEDIUM
crmeb < 5.6.3 - Unauthenticated Incorrect Authorization in Crontab Endpoint
CVSS 5.3
CVE-2026-22624
MEDIUM
HIKSEMI HS-AFS-S1H1 >=V5.10.10_Build_251126 - Authenticated Incorrect Authorization
CVSS 4.3
CVE-2026-25040
HIGH
Budibase <3.26.3 - Privilege Escalation
CVSS 8.8
CVE-2026-22806
CRITICAL
vCluster Platform <4.6.0-4.3.10 - Privilege Escalation
CVSS 9.1
CVE-2026-24780
HIGH
AutoGPT Platform < 0.6.44 - Authenticated Remote Code Execution via Disabled BlockInstallationBlock
CVSS 8.8
CVE-2026-24742
MEDIUM
Discourse < 3.5.4, 2025.11.2, 2025.12.1, 2026.1.0 - Incorrect Authorization in Staff Action Logs
CVSS 6.5
CVE-2026-1514
MEDIUM
Official Document Management System - Auth Bypass
CVSS 6.5
CVE-2026-24748
HIGH
Kargo < 1.6.3 - Unauthenticated Incorrect Authorization via GetConfig and RefreshResource Endpoints
CVSS 7.2
CVE-2026-24740
CRITICAL
Dozzle < 9.0.3 - Improper Access Control via Container ID Targeting
CVSS 9.9
CVE-2026-21721
HIGH
Grafana Dashboard Permissions API - Privilege Escalation
CVSS 8.1
CVE-2026-24480
HIGH
QGIS GitHub Actions pre-commit checks - Privileged Pull Request Code Execution
CVE-2026-24003
MEDIUM
EVerest <= 2025.12.1 - Incorrect Authorization via ISO 15118-2 MQTT Messages
CVSS 4.3
CVE-2026-24428
HIGH
Shenzhen Tenda W30E V2 <16.01.0.19(5037) - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities
3,047
Exploit Likelihood
High