CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,360 vulnerabilities with CWE-863
CVE-2026-61325 HIGH
Oracle Advanced Benefits 12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 7.6
CVE-2026-60951 HIGH
Oracle Time and Labor 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60663 CRITICAL
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 9.9
CVE-2026-60320 HIGH
Oracle Data Integrator 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Sensitive Data Exposure via HTTP
CVSS 7.5
CVE-2026-43947 HIGH
FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass
CVE-2026-43946 HIGH
FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue
CVE-2026-43945 HIGH
FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
CVE-2026-65054 LOW
MediaCMS Private Media Metadata Disclosure via Playlist Ownership Loophole
CVSS 3.1
CVE-2026-47697 HIGH
Shelf has cross-organization IDOR: authenticated users could read/attach another workspace's assets, tags, custodians, bookings, QR codes and audit data
CVSS 7.1
CVE-2026-56146 MEDIUM
Improper Access Control in Kibana Leading to Unauthorized Data Modification and Information Disclosure
CVSS 5.4
CVE-2026-56144 MEDIUM
Incorrect Authorization in Elasticsearch Leading to Information Disclosure
CVSS 5.3
CVE-2026-49092 MEDIUM
Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Information Exposure
CVSS 4.3
CVE-2026-47407 CRITICAL
PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation
CVE-2026-15829 HIGH
SQL Injection and Security Boundary Bypass in googleapis/mcp-toolbox
CVE-2026-65049 CRITICAL
Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via nf_delete_all_data AJAX Action
CVSS 9.3
CVE-2026-59851 HIGH
Libssh: libssh: authentication bypass via missing gssapi principal check
CVSS 8.8
CVE-2026-47128 MEDIUM
nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`
CVSS 6.1
CVE-2026-64651 MEDIUM
AI SDK OpenCode Harness Tool Relay Authorization Bypass
CVE-2026-64650 MEDIUM
AI SDK Codex Harness Tool Relay Authorization Bypass
CVE-2026-44231 CRITICAL
RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint
CVSS 9.1
CVE-2026-63755 MEDIUM
SurrealDB before 3.1.0 Permission Bypass via WHERE Clause
CVSS 6.5
CVE-2026-63751 MEDIUM
SurrealDB before 3.1.0 Field Permission Bypass via JSON Patch
CVSS 4.3
CVE-2026-63749 MEDIUM
SurrealDB before 3.1.0 Authentication Bypass via LIVE SELECT
CVSS 4.3
CVE-2026-63742 MEDIUM
SurrealDB before 3.1.0 Field Permission Bypass via Indexed COUNT
CVSS 4.3
CVE-2026-63740 MEDIUM
SurrealDB before 3.1.4 Array Element Permission Bypass
CVSS 6.5
Details
Vulnerabilities 3,360
Exploit Likelihood High