CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,363 vulnerabilities with CWE-863
CVE-2026-6290 HIGH
Velociraptor Query() Plugin Misapplies Permissions To Orgs
CVSS 8.0
CVE-2026-40291 HIGH
Chamilo LMS has Privilege Escalation via API User Role Modification
CVSS 8.8
CVE-2026-24069 MEDIUM
Improper Enforcement of Disabled Accounts in WebUI SSO in Kiuwan SAST
CVSS 5.4
CVE-2026-40191 MEDIUM
ClearanceKit Endpoint Security Events - Policy Bypass
CVE-2026-35657 MEDIUM
OpenClaw < 2026.3.25 - Authorization Bypass in HTTP Session History Route
CVSS 6.5
CVE-2026-35653 HIGH
OpenClaw < 2026.3.24 - Incorrect Authorization in POST /reset-profile via browser.request
CVSS 8.1
CVE-2026-35619 MEDIUM
OpenClaw < 2026.3.24 - Authorization Bypass via HTTP /v1/models Endpoint
CVSS 4.3
CVE-2026-35596 MEDIUM
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
CVSS 4.3
CVE-2026-40224 MEDIUM
systemd 259-259.2 - Local Privilege Escalation via Varlink Root Namespace Access
CVSS 6.7
CVE-2026-33551 LOW
OpenStack Keystone <26.1.1 - Privilege Escalation
CVSS 3.5
CVE-2026-2712 MEDIUM
WP-Optimize <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update and Image Manipulation
CVSS 5.4
CVE-2026-35645 HIGH
OpenClaw < 2026.3.25 - Privilege Escalation via Synthetic operator.admin in deleteSession
CVSS 8.1
CVE-2026-35635 MEDIUM
OpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology Chat
CVSS 4.8
CVE-2026-34512 HIGH
OpenClaw < 2026.3.25 - Improper Access Control in /sessions/:sessionKey/kill Endpoint
CVSS 8.1
CVE-2026-40071 MEDIUM
pyLoad WebUI JSON permission mismatch lets ADD/DELETE users invoke MODIFY-only actions
CVSS 5.4
CVE-2026-39957 MEDIUM
Lychee has Broken Access Control in SharingController::listAll() leaks private album sharing metadata to unauthorized users
CVSS 4.3
CVE-2026-2619 MEDIUM
Incorrect Authorization in GitLab
CVSS 4.3
CVE-2026-1752 MEDIUM
Incorrect Authorization in GitLab
CVSS 4.3
CVE-2026-33461 HIGH
Incorrect Authorization in Kibana Fleet Leading to Information Disclosure
CVSS 7.7
CVE-2026-33460 MEDIUM
Incorrect Authorization in Kibana Fleet Leading to Information Disclosure
CVSS 4.3
CVE-2026-27140 HIGH
Go cmd/go < 1.25.9 and < 1.26.2 - SWIG Build-Time Code Execution
CVSS 8.8
CVE-2026-39381 MEDIUM
Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`
CVSS 4.3
CVE-2026-39331 HIGH
ChurchCRM <7.1.0 Family API - Authorization Bypass
CVSS 8.1
CVE-2026-22682 HIGH
OpenHarness Improper Access Control via File Tools
CVSS 7.1
CVE-2026-35604 HIGH
File Browser share links remain accessible after Share/Download permissions are revoked
CVSS 8.1
Details
Vulnerabilities 3,363
Exploit Likelihood High