CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

2,832 vulnerabilities with CWE-863
CVE-2026-40515 HIGH
OpenHarness Permission Bypass via grep and glob root argument
CVSS 7.5
CVE-2026-24749 MEDIUM
Silverstripe Assets Module has a DBFile::getURL() permission bypass
CVSS 5.3
CVE-2026-39350 MEDIUM
Istio AuthorizationPolicy Incorrect Regex Matching of Dots in serviceAccounts Fields Allows Policy Bypass
CVSS 5.4
CVE-2026-33888 MEDIUM
ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API
CVSS 5.3
CVE-2026-6383 MEDIUM
Kubevirt: kubevirt: unauthorized subresource access due to improper rbac evaluation
CVSS 5.4
CVE-2026-4857 HIGH
SailPoint IdentityIQ Debug UI Incorrect Authorization
CVSS 8.4
CVE-2026-6290 HIGH
Velociraptor Query() Plugin Misapplies Permissions To Orgs
CVSS 8.0
CVE-2026-40291 HIGH
Chamilo LMS has Privilege Escalation via API User Role Modification
CVSS 8.8
CVE-2026-24069 MEDIUM
Improper Enforcement of Disabled Accounts in WebUI SSO in Kiuwan SAST
CVSS 5.4
CVE-2026-40191 MEDIUM
ClearanceKit has a policy bypass via dual-path Endpoint Security events checking only source path
CVE-2026-35657 MEDIUM
OpenClaw < 2026.3.25 - Authorization Bypass in HTTP Session History Route
CVSS 6.5
CVE-2026-35653 HIGH
OpenClaw < 2026.3.24 - Incorrect Authorization in POST /reset-profile via browser.request
CVSS 8.1
CVE-2026-35619 MEDIUM
OpenClaw < 2026.3.24 - Authorization Bypass via HTTP /v1/models Endpoint
CVSS 4.3
CVE-2026-35596 MEDIUM
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
CVSS 4.3
CVE-2026-40224 MEDIUM
Systemd < 260 - Privilege Escalation
CVSS 6.7
CVE-2026-33551 LOW
OpenStack Keystone <26.1.1 - Privilege Escalation
CVSS 3.5
CVE-2026-2712 MEDIUM
WP-Optimize <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update and Image Manipulation
CVSS 5.4
CVE-2026-35645 HIGH
OpenClaw < 2026.3.25 - Privilege Escalation via Synthetic operator.admin in deleteSession
CVSS 8.1
CVE-2026-35635 MEDIUM
OpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology Chat
CVSS 4.8
CVE-2026-34512 HIGH
OpenClaw < 2026.3.25 - Improper Access Control in /sessions/:sessionKey/kill Endpoint
CVSS 8.1
CVE-2026-40071 MEDIUM
pyLoad WebUI JSON permission mismatch lets ADD/DELETE users invoke MODIFY-only actions
CVSS 5.4
CVE-2026-39957 MEDIUM
Lychee has Broken Access Control in SharingController::listAll() leaks private album sharing metadata to unauthorized users
CVSS 4.3
CVE-2026-2619 MEDIUM
Incorrect Authorization in GitLab
CVSS 4.3
CVE-2026-1752 MEDIUM
Incorrect Authorization in GitLab
CVSS 4.3
CVE-2026-33461 HIGH
Incorrect Authorization in Kibana Fleet Leading to Information Disclosure
CVSS 7.7
Details
Vulnerabilities 2,832
Exploit Likelihood High