CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,041 vulnerabilities with CWE-863
CVE-2026-42843 HIGH
grav-plugin-api: Grav API Privilege Escalation to Super Admin
CVSS 8.8
CVE-2026-42349 HIGH
Clerk: Authorization bypass when combining organization, billing, or reverification checks
CVSS 8.1
CVE-2026-42610 MEDIUM
Grav: Sensitive Information Disclosure via Accounts Service Bypass
CVSS 6.5
CVE-2026-42571 CRITICAL
Privilege Escalation Attack affecting Pelican Web UI
CVE-2026-42296 HIGH
Argo Workflows < 3.7.14/4.0.5 templateReferencing - Strict Mode Bypass
CVSS 8.1
CVE-2026-42137 MEDIUM
Kirby: `pages.access/list` and `files.access/list` permissions are not consistently checked in the REST API and changes dialog
CVSS 6.5
CVE-2026-41432 HIGH
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud
CVSS 7.1
CVE-2026-42160 CRITICAL
Data Space Portal: Incorrect Authorization and Client-Side Enforcement of Server-Side Security in ghcr.io/sovity/ds-portal-ce-backend
CVE-2026-40213 HIGH
OpenStack Cyborg < 14.0.1, 15.0.0-15.0.1, 16.0.0-16.0.1 - Authenticated Incorrect Authorization via Default Policy Rule
CVSS 7.4
CVE-2026-41903 MEDIUM
FreeScout PERM_EDIT_USERS - Notification Subscription IDOR
CVSS 5.4
CVE-2026-41689 MEDIUM
Wallos: Shared local webhook allowlist lets low-privilege users send arbitrary requests to allowlisted internal services
CVSS 6.0
CVE-2026-41660 HIGH
Admidio: Inverted 2FA Reset Authorization Check Lets Group Leaders Strip Admin TOTP
CVSS 7.1
CVE-2026-41657 MEDIUM
Admidio: Cross-Organization Member Data Exposure via Permission Check Mismatch in contacts_data.php
CVSS 4.9
CVE-2026-44110 HIGH
OpenClaw < 2026.4.15 - Authorization Bypass in Matrix Room Control Commands via DM Pairing Store
CVSS 8.8
CVE-2026-6863 MEDIUM
HTTP Filestore Endpoints Misapply Permissions Across Organizations
CVSS 6.8
CVE-2026-39852 HIGH
Quarkus authorization bypass via semicolon path normalization inconsistency
CVSS 8.2
CVE-2026-39402 MEDIUM
lxc lxc-user-nic insufficient ownership validation allows cross-tenant OVS port deletion
CVSS 6.5
CVE-2026-33489 HIGH
CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison
CVSS 7.5
CVE-2026-43530 HIGH
OpenClaw 2026.2.23 < 2026.4.12 - Weakened Exec Approval Binding via busybox and toybox Applet Execution
CVSS 8.8
CVE-2026-42438 HIGH
OpenClaw 2026.4.9 < 2026.4.10 - Sender Policy Bypass in Host Media Attachment Reads
CVSS 7.7
CVE-2026-42434 HIGH
OpenClaw 2026.4.5 < 2026.4.10 - Sandbox Escape via host Parameter Override in Exec Routing
CVSS 8.8
CVE-2026-42220 MEDIUM
Nginx UI < 2.3.8 - node.secret Information Disclosure
CVSS 6.5
CVE-2026-42812 CRITICAL
Apache Polaris: No protection on `write.metadata.path`
CVSS 9.9
CVE-2026-25293 CRITICAL
Snapdragon >=QCA7005 <QCA7005 - Buffer Overflow due to Incorrect Authorization
CVSS 9.6
CVE-2026-43504 MEDIUM
Prosody <0.12.6, 1.0.0-13.0.0 <13.0.5 - Auth Bypass
CVSS 6.5
Details
Vulnerabilities 3,041
Exploit Likelihood High