CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,041 vulnerabilities with CWE-863
CVE-2026-44832 HIGH
Snipe-IT: Privilege Escalation via API Permissions Assignment
CVSS 8.8
CVE-2026-3660 CRITICAL
IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Authentication Bypass
CVSS 9.8
CVE-2026-44314 MEDIUM
Traccar: Missing edit authorization on device image upload allows read-only users to write files
CVSS 4.3
CVE-2026-8046 HIGH
Incorrect Authorization in CODESYS Control
CVSS 8.1
CVE-2026-9350 HIGH
NousResearch hermes-agent Batch Runner approval.py check_all_command_guards authorization
CVSS 7.3
CVE-2026-6406 HIGH
Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag
CVSS 8.8
CVE-2026-40166 HIGH
authentik: Non-admin user can retrieve confidential OAuth client_secret via /api/v3/oauth2/access_tokens/
CVE-2026-39966 MEDIUM
TypeBot: Async filter() bypasses authorization, allowing IDOR in getLinkedTypebots and leaking cross-workspace bot definitions
CVSS 6.5
CVE-2026-28735 MEDIUM
Mattermost - GitHub OAuth Scope Validation
CVSS 5.4
CVE-2026-46595 CRITICAL
Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh
CVSS 10.0
CVE-2026-8350 HIGH
Concrete Cms < 9.5.0 - Privilege Escalation
CVSS 8.8
CVE-2026-47102 HIGH
LiteLLM < 1.83.10 Privilege Escalation via User Update
CVSS 8.8
CVE-2026-47101 HIGH
LiteLLM < 1.83.14 Privilege Escalation via API Key Generation
CVSS 8.8
CVE-2026-4055 MEDIUM
Insufficient permission validation on cross-team playbook run creation
CVSS 4.3
CVE-2026-20238 MEDIUM
Improper Access Control through Role Inheritance in Splunk AI Toolkit app
CVSS 6.5
CVE-2026-34600 MEDIUM
Joplin Server delta API returns note content after share access is revoked
CVSS 5.7
CVE-2026-34579 MEDIUM
MantisBT <2.28.2 Private Issue Monitoring - Authorization Bypass
CVE-2026-42526 MEDIUM
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
CVSS 5.3
CVE-2026-41470 MEDIUM
LIVE555 < 2026.04.22 RTSP Server Authorization Bypass via Session Token
CVSS 5.9
CVE-2026-42096 HIGH
Broken Access Control in Sparx Pro Cloud Server
CVSS 8.8
CVE-2026-21789 MEDIUM
HCL Connections is vulnerable to broken access control
CVSS 4.6
CVE-2026-6343 MEDIUM
Mattermost Playbooks Plugin - Public Playbook Unauthorized Access
CVSS 4.3
CVE-2026-4286 LOW
Mattermost Playbooks Plugin - Unauthorized Team Transfer
CVSS 3.1
CVE-2026-28732 MEDIUM
Mattermost 10.11.0-10.11.13 11.4.0-11.4.3 11.5.0-11.5.1 - Slash Command Hijacking via Trigger-Word Bypass
CVSS 4.3
CVE-2026-6342 MEDIUM
Mattermost Plugins - Incorrect Authorization via Namespace Prefix Bypass
CVSS 4.3
Details
Vulnerabilities 3,041
Exploit Likelihood High