CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,064 vulnerabilities with CWE-863
CVE-2025-8886 MEDIUM
Usta Information Systems Inc. Aybs Interaktif - Privilege Escalation
CVSS 6.7
CVE-2025-7374 MEDIUM
WP JobHunt <= 7.6 - Authenticated Authorization Bypass via Inactive Account Login
CVSS 5.4
CVE-2025-11340 HIGH
GitLab EE <18.3.4-18.4.2 - Privilege Escalation
CVSS 7.7
CVE-2025-11439 MEDIUM
JhumanJ OpnForm <1.9.3 - Auth Bypass
CVSS 4.3
CVE-2025-11438 MEDIUM
JhumanJ OpnForm <1.9.3 - Auth Bypass
CVSS 6.3
CVE-2025-44824 HIGH
Nagios Log Server < 2024R1.3.2 - Authenticated Denial of Service via Elasticsearch Stop API
CVSS 8.5
CVE-2025-3719 HIGH
Nozomi Networks CMC and Guardian < 25.2.0 - Authenticated Privilege Escalation via CLI Command Execution
CVSS 8.1
CVE-2025-59451 LOW
YoSmart YoLink <2025-10-02 - Info Disclosure
CVSS 3.5
CVE-2025-59449 MEDIUM
YoSmart YoLink MQTT broker <2025-10-02 - SSRF
CVSS 4.9
CVE-2025-10696 MEDIUM
OpenSupports 4.11.0 - Incorrect Authorization via Supervised Users Endpoint
CVSS 5.4
CVE-2025-49641 MEDIUM
Zabbix 6.0.0-6.0.40 - Incorrect Authorization via problem.view.refresh Action
CVSS 4.3
CVE-2025-27236 MEDIUM
Zabbix 6.0.38-6.0.41 - Incorrect Authorization via User Search API
CVSS 6.5
CVE-2025-11239 MEDIUM
KNIME Business Hub <1.16.0 - Info Disclosure
CVSS 4.3
CVE-2025-41246 HIGH
VMware Tools for Windows - Privilege Escalation
CVSS 7.6
CVE-2025-11060 MEDIUM
SurrealDB 2.3.0-2.3.7 - Incorrect Authorization via LIVE SELECT Subscription
CVSS 5.7
CVE-2025-59824 MEDIUM
Omni < 0.48.0 - Incorrect Authorization via WireGuard SideroLink
CVSS 5.4
CVE-2025-43806 MEDIUM
Liferay Digital Experience Platform 2023.Q3.1-2023.Q3.10 - Authenticated Incorrect Authorization in Batch Engine
CVSS 4.3
CVE-2025-59420 HIGH
Authlib < 1.6.4 - Insufficient Verification of Data Authenticity via Critical Header Parameter Bypass
CVSS 7.5
CVE-2025-59714 MEDIUM
Internet2 Grouper 5.17.1-5.20.5 - Incorrect Authorization in Loader Job Configuration
CVSS 6.5
CVE-2025-10016 HIGH
Sparkle framework - Privilege Escalation
CVE-2025-10015 MEDIUM
Sparkle < 2.7.2 - Unauthenticated Incorrect Authorization via XPC Service Registration
CVE-2025-43307 MEDIUM
macOS < 26 - Unauthorized Sensitive User Data Access
CVSS 4.0
CVE-2025-31254 MEDIUM
Safari < 26.0 - Unexpected URL Redirection via Malicious Web Content
CVSS 5.4
CVE-2025-59376 LOW
feisky mcp-kubernetes-server < 0.1.11 - Command Injection via Chained Command Bypass
CVSS 3.7
CVE-2025-43789 MEDIUM
Liferay DXP 2024.Q1.1-2024.Q1.9 & 7.4.0-7.4.3.119 - Incorrect Authorization in JSON WS
CVSS 5.3
Details
Vulnerabilities 3,064
Exploit Likelihood High