CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,063 vulnerabilities with CWE-863
CVE-2025-65900 MEDIUM
Kalmia CMS <0.2.0 - Info Disclosure
CVSS 6.5
CVE-2025-14016 MEDIUM
macrozheng mall-swarm < 1.0.3 - Improper Authorization via /member/readHistory/delete ids Parameter
CVSS 5.4
CVE-2025-66406 MEDIUM
Step CA <0.29.0 - Improper Authorization
CVSS 5.0
CVE-2025-20381 MEDIUM
Splunk MCP Server app <0.2.4 - Auth Bypass
CVSS 5.4
CVE-2025-12756 MEDIUM
Mattermost <11.0.2-10.12.1-10.11.4-10.5.12 - Privilege Escalation
CVSS 4.3
CVE-2025-13653 MEDIUM
Search Guard FLX <4.0.0 - Info Disclosure
CVSS 4.3
CVE-2025-13829 HIGH
Data Illusion Zumbrunn NGSurvey - Info Disclosure
CVE-2025-13813 MEDIUM
mogublog < 5.2 - Missing Authorization in Storage Management Endpoint
CVSS 5.6
CVE-2025-13806 HIGH
nutzam NutzBoot < 2.6.0 - Improper Authorization in Transaction API
CVSS 7.3
CVE-2025-66433 MEDIUM
HTCondor Access Point <25.3.1 - Privilege Escalation
CVSS 4.2
CVE-2025-66424 MEDIUM
Tryton trytond <7.6.11 - Info Disclosure
CVSS 6.5
CVE-2025-66423 HIGH
Tryton trytond <6.0-7.6.11 - Info Disclosure
CVSS 7.1
CVE-2025-66360 HIGH
Logpoint <7.7.0 - Privilege Escalation
CVSS 8.8
CVE-2025-12971 MEDIUM
Folders - Unlimited Folders to Organize Media Library Folder, Pages...
CVSS 4.3
CVE-2025-55469 CRITICAL
youlai-boot <2.21.1 - Privilege Escalation
CVSS 9.8
CVE-2025-9803 HIGH
lunary 1.9.34 - Account Takeover via Improper Google OAuth Audience Validation
CVSS 8.8
CVE-2025-13432 MEDIUM
Terraform 1.0.0-1.0.3 - Incorrect Authorization in State Version Creation
CVSS 4.3
CVE-2025-62189 MEDIUM
LogStare Collector < 2.4.2 - Incorrect Authorization in UserRegistration
CVSS 4.3
CVE-2025-62730 HIGH
soplanning < 1.55.00 - Authenticated Privilege Escalation via User Management Tab
CVSS 8.8
CVE-2025-13468 MEDIUM
SourceCodester Alumni Management System 1.0 - Missing Authorization in Delete Handler
CVSS 5.4
CVE-2025-59111 MEDIUM
Windu CMS 4.1 - Broken Access Control in User Editing Functionality
CVSS 6.5
CVE-2025-41346 CRITICAL
WinPlus 24.11.27 - Incorrect Authorization via Numerical ID Impersonation
CVSS 9.8
CVE-2025-65073 HIGH
OpenStack Keystone < 26.0.1, 27.0.0, 28.0.0 - Incorrect Authorization via AWS Signature
CVSS 7.5
CVE-2025-7736 LOW
GitLab CE/EE <18.3.6-18.5.2 - Auth Bypass
CVSS 3.1
CVE-2025-11865 MEDIUM
GitLab 18.1-18.3.6, 18.4-18.4.4, 18.5-18.5.2 - Incorrect Authorization
CVSS 4.3
Details
Vulnerabilities 3,063
Exploit Likelihood High