CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,041 vulnerabilities with CWE-863
CVE-2026-2725 MEDIUM
Improper Authorization in Gerrit allowing Code Review Bypass via "Submitted Together"
CVE-2026-45226 HIGH
Heym < 0.0.21 Authorization Bypass in Workflow Execution
CVSS 7.1
CVE-2026-44260 HIGH
efw4.X: readonly Flag Not Enforced Server-Side
CVSS 8.1
CVE-2026-43948 CRITICAL
wger: cross-tenant password reset and plaintext disclosure via gym=None bypass
CVSS 9.9
CVE-2026-35555 MEDIUM
Subnet Solutions PowerSYSTEM Center Incorrect Authorization
CVSS 6.3
CVE-2026-33570 MEDIUM
Subnet Solutions PowerSYSTEM Center Incorrect Authorization
CVSS 5.7
CVE-2026-26289 HIGH
Subnet Solutions PowerSYSTEM Center Incorrect Authorization
CVSS 8.2
CVE-2026-44221 CRITICAL
ArcadeDB: Cross-database authorization bypass and unsecured newly-created databases
CVSS 9.0
CVE-2026-42889 CRITICAL
Relay Server WebSocket authentication bypass when token is omitted
CVSS 9.1
CVE-2026-34646 HIGH
Adobe Commerce | Incorrect Authorization (CWE-863)
CVSS 7.5
CVE-2026-34645 HIGH
Adobe Commerce | Incorrect Authorization (CWE-863)
CVSS 7.5
CVE-2026-34660 CRITICAL
Adobe Connect | Incorrect Authorization (CWE-863)
CVSS 9.3
CVE-2026-2465 HIGH
Improper Authorization in E-Kalite's Turboard FOR-S
CVSS 8.8
CVE-2026-43913 HIGH
Vaultwarden: Unconfirmed Owner Can Purge Entire Organization Vault
CVSS 8.1
CVE-2026-43889 MEDIUM
Outline: Unauthorized Document Publication via Mixed collectionId+documentId Share
CVSS 6.5
CVE-2026-28951 HIGH
iOS and iPadOS < 18.7.9 and < 26.5, macOS < 14.8.7, < 15.7.7, and < 26.5 - Authorization Bypass to Root Privileges
CVSS 7.8
CVE-2026-28873 HIGH
iOS and iPadOS < 18.7.9 and < 26.4 - Incorrect Authorization
CVSS 7.5
CVE-2026-42884 MEDIUM
Audiobookshelf: Collection endpoints bypass library access controls exposing restricted library data
CVSS 4.3
CVE-2026-42883 MEDIUM
Audiobookshelf: Cross-library file exfiltration via unscoped bulk download endpoint
CVSS 6.5
CVE-2026-42882 CRITICAL
oxyno-zeta/s3-proxy: Security Issues in Resource Path Matching
CVSS 9.4
CVE-2026-45002 MEDIUM
OpenClaw < 2026.4.20 - Hook Session-Key Bypass via Template Mapping
CVSS 5.3
CVE-2026-44998 MEDIUM
OpenClaw < 2026.4.20 - Tool Policy Bypass via Bundled MCP/LSP Tools
CVSS 5.4
CVE-2026-44991 MEDIUM
OpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel Senders
CVSS 4.2
CVE-2026-42313 HIGH
pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy
CVSS 8.3
CVE-2026-42312 MEDIUM
pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification
CVSS 6.8
Details
Vulnerabilities 3,041
Exploit Likelihood High