CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,363 vulnerabilities with CWE-863
CVE-2026-35586 MEDIUM
Authorization Bypass for SSL Certificate/Key Configuration Due to Option Name Mismatch in pyload-ng
CVSS 6.8
CVE-2026-35491 MEDIUM
Pi-hole FTL: CLI API sessions can import Teleporter archives and modify configuration
CVSS 6.1
CVE-2026-35490 CRITICAL
changedetection.io <0.54.8 Route Decorators - Authentication Bypass
CVSS 9.8
CVE-2026-5384 MEDIUM
runZero Platform incorrect credential scope
CVSS 5.8
CVE-2026-5383 MEDIUM
runZero Explorer missing authorization check
CVSS 4.4
CVE-2026-5382 LOW
runZero Platform MCP endpoint information leak
CVSS 3.0
CVE-2026-5381 LOW
runZero Platform task information leak
CVSS 2.2
CVE-2026-5380 MEDIUM
runZero Platform cleartext secret exposure
CVSS 5.3
CVE-2026-5379 LOW
runZero Platform MCP certification information leak
CVSS 3.0
CVE-2026-5378 MEDIUM
runZero Platform user creation leak
CVSS 5.8
CVE-2026-5374 MEDIUM
runZero Platform MCP information leak
CVSS 5.8
CVE-2026-35464 HIGH
pyLoad <=0.5.0b3.dev96 - Flask Session Store Code Execution
CVSS 7.5
CVE-2026-28808 CRITICAL
ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)
CVSS 9.8
CVE-2026-35442 HIGH
Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries
CVSS 8.1
CVE-2026-35412 HIGH
Directus <11.16.1 TUS Uploads - Arbitrary File Overwrite
CVSS 7.1
CVE-2026-34972 MEDIUM
OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision
CVSS 5.0
CVE-2026-35029 HIGH
LiteLLM affected by privilege escalation via unrestricted proxy configuration endpoint
CVSS 8.8
CVE-2026-5574 MEDIUM
Technostrobe HI-LED-WR120-G2 FsBrowseClean deletefile authorization
CVSS 6.5
CVE-2026-34953 CRITICAL
PraisonAI: Authentication Bypass in OAuthManager.validate_token()
CVSS 9.1
CVE-2026-27447 MEDIUM
OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup
CVSS 4.8
CVE-2026-33105 CRITICAL
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-32213 CRITICAL
Azure AI Foundry Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-32173 HIGH
Azure SRE Agent Information Disclosure Vulnerability
CVSS 8.6
CVE-2026-34376 HIGH
PdfDing: Password-protected share bypass via direct serve endpoint
CVSS 7.5
CVE-2026-34453 HIGH
SiYuan: Broken access control in /api/bookmark/getBookmark allows unauthenticated publish visitors to read password-protected bookmarked content
CVSS 7.5
Details
Vulnerabilities 3,363
Exploit Likelihood High