CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,047 vulnerabilities with CWE-863
CVE-2026-25859 HIGH
Wekan < 8.20 - Incorrect Authorization in Migration Functionality
CVSS 8.8
CVE-2026-25568 MEDIUM
WeKan < 8.19 - Incorrect Authorization via allowPrivateOnly Setting Bypass
CVSS 4.3
CVE-2026-25566 MEDIUM
WeKan < 8.19 - Incorrect Authorization in Card Move Logic
CVSS 5.4
CVE-2026-25565 MEDIUM
WeKan < 8.19 - Incorrect Authorization in Card Update API
CVSS 6.5
CVE-2026-25561 HIGH
WeKan < 8.19 - Incorrect Authorization in Attachment Upload API
CVSS 7.5
CVE-2026-25729 MEDIUM
DeepAudit < 3.0.4 - Authenticated Sensitive Information Disclosure via User Enumeration Endpoint
CVSS 6.5
CVE-2026-23989 HIGH
OpenCloud Reva <2.42.3, <2.40.3 - Auth Bypass
CVSS 8.2
CVE-2026-24851 HIGH
OpenFGA 1.8.5-1.11.2 - Incorrect Authorization via Check Call Policy Enforcement
CVSS 8.8
CVE-2026-23632 MEDIUM
Gogs < 0.13.4 - Incorrect Authorization via PUT /repos/:owner/:repo/contents/* Endpoint
CVSS 6.5
CVE-2026-23572 HIGH
TeamViewer <15.74.5 - Privilege Escalation
CVSS 7.2
CVE-2026-1897 MEDIUM
WeKan < 8.21 - Missing Authorization in Position-History Tracking
CVSS 4.3
CVE-2026-1553 MEDIUM
Drupal Canvas < 1.0.4 - Incorrect Authorization via Forceful Browsing
CVSS 4.8
CVE-2026-1734 MEDIUM
crmeb < 5.6.3 - Unauthenticated Incorrect Authorization in Crontab Endpoint
CVSS 5.3
CVE-2026-22624 MEDIUM
HIKSEMI HS-AFS-S1H1 >=V5.10.10_Build_251126 - Authenticated Incorrect Authorization
CVSS 4.3
CVE-2026-25040 HIGH
Budibase <3.26.3 - Privilege Escalation
CVSS 8.8
CVE-2026-22806 CRITICAL
vCluster Platform <4.6.0-4.3.10 - Privilege Escalation
CVSS 9.1
CVE-2026-24780 HIGH
AutoGPT Platform < 0.6.44 - Authenticated Remote Code Execution via Disabled BlockInstallationBlock
CVSS 8.8
CVE-2026-24742 MEDIUM
Discourse < 3.5.4, 2025.11.2, 2025.12.1, 2026.1.0 - Incorrect Authorization in Staff Action Logs
CVSS 6.5
CVE-2026-1514 MEDIUM
Official Document Management System - Auth Bypass
CVSS 6.5
CVE-2026-24748 HIGH
Kargo < 1.6.3 - Unauthenticated Incorrect Authorization via GetConfig and RefreshResource Endpoints
CVSS 7.2
CVE-2026-24740 CRITICAL
Dozzle < 9.0.3 - Improper Access Control via Container ID Targeting
CVSS 9.9
CVE-2026-21721 HIGH
Grafana Dashboard Permissions API - Privilege Escalation
CVSS 8.1
CVE-2026-24480 HIGH
QGIS GitHub Actions pre-commit checks - Privileged Pull Request Code Execution
CVE-2026-24003 MEDIUM
EVerest <= 2025.12.1 - Incorrect Authorization via ISO 15118-2 MQTT Messages
CVSS 4.3
CVE-2026-24428 HIGH
Shenzhen Tenda W30E V2 <16.01.0.19(5037) - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities 3,047
Exploit Likelihood High