CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,047 vulnerabilities with CWE-863
CVE-2025-13480 MEDIUM
Incorrect authorization in Fudo Enterprise
CVSS 6.5
CVE-2025-40897 HIGH
Incorrect authorization for Threat Intelligence in Guardian/CMC before 26.0.0
CVSS 8.1
CVE-2025-68153 MEDIUM
Juju: Resource poisoning
CVSS 6.5
CVE-2025-68152 MEDIUM
Juju: Read All Controller Logs From Compromised Workload
CVSS 4.9
CVE-2025-71278 HIGH
XenForo OAuth2 Unauthorized Scope Request
CVSS 8.8
CVE-2025-69196 MEDIUM
FastMCP OAuth Proxy token reuse across MCP servers
CVSS 6.5
CVE-2025-12555 MEDIUM
GitLab CE/EE 15.1-18.7.5/18.8-18.8.5/18.9-18.9.1 - Info Disclosure
CVSS 4.3
CVE-2025-13734 MEDIUM
IBM DOORS Next 7.1-7.2 - Privilege Escalation
CVSS 5.4
CVE-2025-9572 MEDIUM
Foreman 1.22.0-3.16.1 - Incorrect Authorization via GraphQL API
CVSS 5.0
CVE-2025-4960 HIGH
EPSON InstallNavi Helper - Privilege Escalation
CVSS 7.8
CVE-2025-15342 MEDIUM
Tanium Reputation 6.3.0-6.3.227 - Incorrect Authorization
CVSS 4.3
CVE-2025-15321 LOW
Tanium TanOS 1.8.3-1.8.3.0196 - Incorrect Authorization
CVSS 2.7
CVE-2025-70997 MEDIUM
eladmin < 2.7 - Unauthenticated Arbitrary Password Reset
CVSS 6.5
CVE-2025-67856 MEDIUM
Moodle < 4.1.22 - Incorrect Authorization in Badge Awarding Process
CVSS 5.4
CVE-2025-15395 MEDIUM
IBM Jazz Foundation 7.0.3-7.0.3 iFix019 and 7.1.0-7.1.0 iFix005 - Incorrect Authorization
CVSS 4.3
CVE-2025-15525 MEDIUM
Ajax Load More - Unauthorized Access
CVSS 5.3
CVE-2025-15322 MEDIUM
Tanium Server - Privilege Escalation
CVSS 4.3
CVE-2025-15288 LOW
Tanium Interact - Privilege Escalation
CVSS 3.1
CVE-2025-69289 MEDIUM
Discourse < 3.5.4 - Privilege Escalation via Email Change Bypass
CVSS 5.4
CVE-2025-69218 MEDIUM
Discourse < 3.5.4, < 2025.11.2, < 2025.12.1, < 2026.1.0 - Incorrect Authorization in Admin Report
CVSS 6.5
CVE-2025-68933 MEDIUM
Discourse < 3.5.4, < 2025.11.2, < 2025.12.1, < 2026.1.0 - Broken Access Control via Post Ownership Transfer
CVSS 6.9
CVE-2025-68666 MEDIUM
Discourse <3.5.4, <2025.11.2, <2025.12.1, <2026.1.0 - Info Disclosure
CVSS 6.5
CVE-2025-13985 MEDIUM
Drupal Entity Share < 3.13.0 - Incorrect Authorization via Forceful Browsing
CVSS 5.3
CVE-2025-68660 MEDIUM
Discourse <3.5.4,2025.11.2,2025.12.1,2026.1.0 - Auth Bypass
CVSS 5.4
CVE-2025-66719 CRITICAL
Free5gc NRF 1.4.0 - Incorrect Authorization via Crafted targetNF Value
CVSS 9.1
Details
Vulnerabilities 3,047
Exploit Likelihood High