CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,041 vulnerabilities with CWE-863
CVE-2026-11577 HIGH
Keycloak: keycloak: privilege escalation via partialimport fgap permission bypass
CVSS 7.2
CVE-2026-21031 HIGH
Samsung Mobile Devices - Improper Authorization in AppBlock
CVSS 7.8
CVE-2026-42547 MEDIUM
IRIS Alerts Can be Falsely Attributed to Customers
CVSS 5.4
CVE-2026-41235 HIGH
Froxlor 2.3.6 FTP Shell Assignment - Authorization Bypass
CVE-2026-50266 LOW
Openstack Neutron - Incorrect Authorization
CVSS 2.2
CVE-2026-10815 MEDIUM
LakshayD02 Hostel-Management-System-PHP Admin Dashboard index.php authorization
CVSS 6.3
CVE-2026-10860 MEDIUM
MISP CRUDComponent delete validation bypass via operator precedence error
CVSS 6.5
CVE-2026-41283 CRITICAL
Openstack Mistral - Incorrect Authorization
CVSS 9.9
CVE-2026-44654 HIGH
LibreChat: Shared-agent editor can globally delete owner's file records — breaks owner's other private agents
CVSS 8.1
CVE-2026-35482 HIGH
alf.io <2.0-M5-2606 Extension Scripts - Sandbox Escape
CVSS 8.0
CVE-2026-10616 MEDIUM
nextlevelbuilder GoClaw Team Task Completion team_tasks_lifecycle.go TeamTasksTool.executeComplete authorization
CVSS 4.3
CVE-2026-3514 HIGH
Authentication Bypass in prefecthq/prefect
CVSS 7.5
CVE-2026-9048 MEDIUM
Slider Revolution 7.0.0-7.0.14 - Authenticated Sensitive Information Exposure via slider.get.full AJAX Action
CVSS 4.3
CVE-2026-22872 CRITICAL
Capsule < 0.13.0 - Authenticated Privilege Escalation via TenantResource RawItems Processing
CVSS 9.1
CVE-2026-45426 LOW
Apache Airflow Log Server - JWT Authorization Bypass
CVSS 3.1
CVE-2026-10211 MEDIUM
AstrBotDevs AstrBot fs.py _normalize_rw_path authorization
CVSS 6.3
CVE-2026-49376 MEDIUM
Jetbrains TeamCity < 2026.1 - Incorrect Authorization
CVSS 6.5
CVE-2026-49369 MEDIUM
Jetbrains YouTrack < 2026.1.13162 - Incorrect Authorization
CVSS 4.3
CVE-2026-48501 HIGH
GitHub CLI tokens leak via `gh attestation` commands
CVSS 7.4
CVE-2026-35674 HIGH
OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route
CVSS 8.8
CVE-2026-35673 MEDIUM
OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes
CVSS 6.5
CVE-2026-34507 MEDIUM
OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks
CVSS 5.4
CVE-2026-32906 MEDIUM
OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Gate
CVSS 4.3
CVE-2026-9808 HIGH
Mautic 7 - Authenticated Authorization Bypass in API v2 Endpoints
CVSS 7.1
CVE-2026-49299 MEDIUM
Openstack Neutron - Incorrect Authorization
Details
Vulnerabilities 3,041
Exploit Likelihood High