CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

2,832 vulnerabilities with CWE-863
CVE-2026-33460 MEDIUM
Incorrect Authorization in Kibana Fleet Leading to Information Disclosure
CVSS 4.3
CVE-2026-27140 HIGH
Code execution vulnerability in SWIG code generation in cmd/go
CVSS 8.8
CVE-2026-39381 MEDIUM
Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`
CVSS 4.3
CVE-2026-39331 HIGH
ChurchCRM has an API Authorization Bypass Allows Authenticated User to Deactivate, Modify, and Spam Arbitrary Families
CVSS 8.1
CVE-2026-22682 HIGH
OpenHarness Improper Access Control via File Tools
CVSS 7.1
CVE-2026-35604 HIGH
File Browser share links remain accessible after Share/Download permissions are revoked
CVSS 8.1
CVE-2026-35586 MEDIUM
Authorization Bypass for SSL Certificate/Key Configuration Due to Option Name Mismatch in pyload-ng
CVSS 6.8
CVE-2026-35491 MEDIUM
Pi-hole FTL: CLI API sessions can import Teleporter archives and modify configuration
CVSS 6.1
CVE-2026-35490 CRITICAL
changedetection.io has an Authentication Bypass via Decorator Ordering
CVSS 9.8
CVE-2026-5384 MEDIUM
runZero Platform incorrect credential scope
CVSS 5.8
CVE-2026-5383 MEDIUM
runZero Explorer missing authorization check
CVSS 4.4
CVE-2026-5382 LOW
runZero Platform MCP endpoint information leak
CVSS 3.0
CVE-2026-5381 LOW
runZero Platform task information leak
CVSS 2.2
CVE-2026-5380 MEDIUM
runZero Platform cleartext secret exposure
CVSS 5.3
CVE-2026-5379 LOW
runZero Platform MCP certification information leak
CVSS 3.0
CVE-2026-5378 MEDIUM
runZero Platform user creation leak
CVSS 5.8
CVE-2026-5374 MEDIUM
runZero Platform MCP information leak
CVSS 5.8
CVE-2026-35464 HIGH
pyLoad has an incomplete fix for CVE-2026-33509: unprotected storage_folder enables arbitrary file write to Flask session store and code execution
CVSS 7.5
CVE-2026-28808 CRITICAL
ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)
CVSS 9.8
CVE-2026-35442 HIGH
Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries
CVSS 8.1
CVE-2026-35412 HIGH
Directus has a TUS Upload Authorization Bypass Allows Arbitrary File Overwrite
CVSS 7.1
CVE-2026-34972 MEDIUM
OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision
CVSS 5.0
CVE-2026-35029 HIGH
LiteLLM affected by privilege escalation via unrestricted proxy configuration endpoint
CVSS 8.8
CVE-2026-5574 MEDIUM
Technostrobe HI-LED-WR120-G2 FsBrowseClean deletefile authorization
CVSS 6.5
CVE-2026-34953 CRITICAL
PraisonAI: Authentication Bypass in OAuthManager.validate_token()
CVSS 9.1
Details
Vulnerabilities 2,832
Exploit Likelihood High