CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

2,832 vulnerabilities with CWE-863
CVE-2026-4363 LOW
Incorrect Authorization in GitLab
CVSS 3.7
CVE-2026-28864 LOW
Apple Ios And Ipados < 18.7.7 - Denial of Service
CVSS 3.3
CVE-2026-33330 HIGH
FileRise ONLYOFFICE integration allows read-only users to overwrite files via forged save callback
CVSS 7.1
CVE-2026-33326 MEDIUM
@keystone-6/core: `isFilterable` bypass via `cursor` parameter in findMany
CVSS 4.3
CVE-2026-33527 MEDIUM
Parse Server: Session update endpoint allows overwriting server-generated session fields
CVSS 4.3
CVE-2026-33421 MEDIUM
Parse Server: LiveQuery bypasses CLP pointer permission enforcement
CVSS 6.5
CVE-2026-33676 MEDIUM
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read
CVSS 6.5
CVE-2026-33668 HIGH
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect
CVSS 8.1
CVE-2026-33316 HIGH
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement
CVSS 8.1
CVE-2026-28755 MEDIUM
NGINX ngx_stream_ssl_module vulnerability
CVSS 5.4
CVE-2026-32642 MEDIUM
Apache Artemis, Apache ActiveMQ Artemis: Temporary address auto-created for OpenWire consumer without createAddress permission
CVSS 4.3
CVE-2026-4639 HIGH
Galaxy Software Services|Vitals ESP - Incorrect Authorization
CVSS 8.8
CVE-2026-27646 MEDIUM
OpenClaw <2026.3.7 - Sandbox Escape
CVSS 6.1
CVE-2026-27183 MEDIUM
OpenClaw < 2026.3.7 - Shell Approval Gating Bypass via Dispatch Wrapper Depth Mismatch
CVSS 5.3
CVE-2026-33650 HIGH
AVideo's Video Moderator Privilege Escalation via Ownership Transfer Enables Arbitrary Video Deletion
CVSS 7.6
CVE-2026-32899 MEDIUM
OpenClaw < 2026.2.25 - Sender Policy Bypass in Slack Reaction and Pin Event Handlers
CVSS 4.3
CVE-2026-32895 MEDIUM
OpenClaw < 2026.2.26 - Sender Authorization Bypass in Slack System Event Handlers
CVSS 5.4
CVE-2026-32067 LOW
OpenClaw < 2026.2.26 - Cross-Account Authorization Bypass in DM Pairing Store
CVSS 3.7
CVE-2026-32058 LOW
OpenClaw < 2026.2.26 - Approval Context-Binding Weakness in system.run via host=node
CVSS 2.6
CVE-2026-32051 HIGH
OpenClaw < 2026.3.1 - Authorization Bypass in Agent Runs via Owner-Only Tool Access
CVSS 8.8
CVE-2026-32050 LOW
OpenClaw < 2026.2.25 - Unauthorized Reaction Status Event Enqueue via Access Check Bypass
CVSS 3.7
CVE-2026-32042 HIGH
OpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway Authentication
CVSS 8.8
CVE-2026-33428 MEDIUM
Discourse Allows Unauthorized Access to Deleted Posts Index via Group Membership
CVSS 6.5
CVE-2026-33424 MEDIUM
PM access granted through invites after access revocation
CVSS 5.9
CVE-2026-33291 MEDIUM
Discourse user can create Zendesk tickets even when it does not have access to topic
CVSS 5.4
Details
Vulnerabilities 2,832
Exploit Likelihood High