CWE-863: Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource, but it does not correctly perform the check.

708
Total CVEs
138
Critical
313
High
7.3
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
77
2025
260
2024
164
2023
97
2022
35

Top Affected Vendors

1 Oracle 34
2 Apple 26
3 Adobe 22
4 Google 19
5 Mattermost 18
6 Gitlab 16
7 Ibm 13
8 Apache 10
9 Wso2 7
10 Lunary 7

All Incorrect Authorization CVEs (708)

CVE-2025-54253
KEV EPSS 44.1% 10.0

CVE-2025-54253 is a critical misconfiguration vulnerability in Adobe Experience Manager Forms that allows unauthenticated attackers to execute arbitra...

Aug 5, 2025
CVE-2023-4617
10.0

This vulnerability allows remote attackers to bypass authorization controls in the Govee Home mobile app, enabling them to control smart devices belon...

Dec 19, 2024
CVE-2022-21141
10.0

This critical vulnerability affects Cambium Networks wireless devices, allowing attackers to bypass authorization checks on API functions. Attackers c...

Feb 18, 2022
CVE-2021-38503
10.0

This vulnerability allows malicious iframes to bypass sandbox restrictions when loading XSLT stylesheets, enabling script execution and top-level fram...

Dec 8, 2021
CVE-2026-28466
9.9

OpenClaw gateway versions before 2026.2.14 have an authorization bypass vulnerability where authenticated clients can manipulate node.invoke parameter...

Mar 5, 2026
CVE-2025-21556
9.9

This critical vulnerability in Oracle Agile PLM Framework allows authenticated attackers with low privileges to completely compromise the system via H...

Jan 21, 2025
CVE-2024-4447
9.9

This vulnerability exposes sensitive session and user data through Direct Web Remoting API endpoints, allowing authenticated administrators to obtain ...

Jul 26, 2024
CVE-2024-38369
9.9

This vulnerability in XWiki Platform allows privilege escalation through macro execution context manipulation. When using the include macro, content e...

Jun 24, 2024
CVE-2024-21010
9.9

This critical vulnerability in Oracle Hospitality Simphony Enterprise Server allows authenticated attackers with low privileges to remotely compromise...

Apr 16, 2024
CVE-2023-35166
9.9

This vulnerability in XWiki Platform allows attackers to execute arbitrary wiki content with the privileges of the TipsPanel author by creating a mali...

Jun 20, 2023
CVE-2023-32069
9.9

This CVE allows authenticated users in XWiki Platform to execute arbitrary code with the privileges of the XWiki.ClassSheet document author, potential...

May 9, 2023
CVE-2021-26753
9.9

CVE-2021-26753 is an authenticated remote code execution vulnerability in NeDi network management software. An authenticated attacker can inject PHP c...

Feb 12, 2021
CVE-2020-35948
9.9

This vulnerability in the XCloner WordPress plugin allows authenticated attackers to modify arbitrary files, including critical PHP files like wp-conf...

Jan 1, 2021
CVE-2026-28474
9.8

This vulnerability allows attackers to bypass allowlist restrictions in Nextcloud Talk by changing their display name to match an allowlisted user ID....

Mar 5, 2026
CVE-2026-25875
9.8

This vulnerability allows attackers to bypass authorization in PlaciPy placement management systems by manipulating JWT claims. Attackers can escalate...

Feb 9, 2026
CVE-2026-23837
9.8

CVE-2026-23837 is an authentication bypass vulnerability in MyTube that allows unauthenticated attackers to access protected administrative functions....

Jan 19, 2026
CVE-2025-13184
9.8

This critical vulnerability allows unauthenticated attackers to enable Telnet service and gain root access with blank password on Totolink X5000R rout...

Dec 10, 2025
CVE-2025-55469
9.8

CVE-2025-55469 is an incorrect access control vulnerability in youlai-boot v2.21.1 that allows attackers to bypass authentication and escalate privile...

Nov 26, 2025
CVE-2025-41346
9.8

CVE-2025-41346 is an authorization bypass vulnerability in WinPlus v24.11.27 that allows attackers to impersonate any user by knowing their numerical ...

Nov 18, 2025
CVE-2025-10611
9.8

This critical vulnerability in WSO2 products allows attackers to bypass authentication and authorization checks for certain REST APIs, enabling unauth...

Oct 16, 2025
CVE-2025-36157
9.8

This vulnerability allows unauthenticated remote attackers to modify server property files in IBM Jazz Foundation, potentially enabling unauthorized a...

Aug 24, 2025
CVE-2025-55213
9.8

OpenFGA versions 1.9.3 to 1.9.4 contain an improper policy enforcement vulnerability in Check and ListObject calls. This allows attackers to bypass au...

Aug 18, 2025
CVE-2025-49825
EPSS 11.5% 9.8

CVE-2025-49825 is a critical authentication bypass vulnerability in Teleport Community Edition that allows remote attackers to gain unauthorized acces...

Jun 17, 2025
CVE-2025-20674
9.8

This vulnerability in MediaTek WLAN AP drivers allows attackers to inject arbitrary packets without proper permission checks, enabling remote privileg...

Jun 2, 2025
CVE-2024-6914
9.8

This vulnerability allows attackers to reset any user's password via a flawed SOAP admin service in WSO2 products, leading to complete account takeove...

May 22, 2025
CVE-2025-27645
9.8

This vulnerability in Vasion Print (formerly PrinterLogic) allows attackers to install malicious extensions by exploiting insecure HTTP permission met...

Mar 5, 2025
CVE-2024-13258
9.8

This vulnerability allows attackers to bypass authorization controls in Drupal's REST & JSON API Authentication module, enabling forceful browsing to ...

Jan 9, 2025
CVE-2024-56431
9.8

CVE-2024-56431 is a disputed vulnerability in libtheora's huffdec.c where oc_huff_tree_unpack contains an invalid negative left shift operation. The v...

Dec 25, 2024
CVE-2024-31695
9.8

A misconfiguration in the fingerprint authentication mechanism of the Binance mobile app allows attackers to bypass authentication when adding a new f...

Nov 14, 2024
CVE-2024-48176
9.8

Lylme Spage v1.9.5 has an authentication bypass vulnerability due to missing login attempt limits and static verification codes. Attackers can brute-f...

Nov 5, 2024
CVE-2024-48237
9.8

WTCMS 1.0 has an incorrect access control vulnerability in the HomebaseController that allows attackers to bypass authentication and authorization mec...

Oct 25, 2024
CVE-2024-41617
9.8

Money Manager EX WebApp version 1.2.2 has an access control vulnerability where the redirect_if_not_loggedin function doesn't properly terminate execu...

Oct 24, 2024
CVE-2024-7108
9.8

CVE-2024-7108 is an incorrect authorization vulnerability in National Keep Cyber Security Services CyberMath that allows attackers to access functiona...

Sep 26, 2024
CVE-2024-42966
9.8

This vulnerability allows unauthenticated attackers to retrieve the apmib configuration file containing administrative credentials from TOTOLINK N350R...

Aug 15, 2024
CVE-2024-6202
9.8

HaloITSM versions up to 2.146.1 have a SAML XML Signature Wrapping vulnerability that allows anonymous attackers to impersonate any user by knowing th...

Aug 6, 2024
CVE-2024-6782
9.8

An improper access control vulnerability in Calibre e-book management software allows unauthenticated attackers to execute arbitrary code remotely. Th...

Aug 6, 2024
CVE-2024-6695
9.8

This vulnerability allows unauthenticated attackers to gain administrative access to affected systems by exploiting a logic flaw in the user registrat...

Jul 31, 2024
CVE-2024-36536
9.8

CVE-2024-36536 is an insecure permissions vulnerability in fabedge v0.8.1 that allows attackers to access service account tokens. This enables privile...

Jul 24, 2024
CVE-2023-38389
9.8

CVE-2023-38389 is an incorrect authorization vulnerability in the Artbees JupiterX Core WordPress plugin that allows unauthenticated attackers to bypa...

Jun 21, 2024
CVE-2024-36265
9.8

This CVE describes an incorrect authorization vulnerability in Apache Submarine Server Core that allows unauthorized access to sensitive functionality...

Jun 12, 2024
CVE-2024-4146
9.8

This CVE describes an authorization bypass vulnerability in lunary-ai/lunary version v1.2.13 that allows unauthorized users to access and manipulate p...

Jun 8, 2024
CVE-2024-31682
9.8

This vulnerability allows attackers to bypass fingerprint authentication in Phone Cleaner: Boost & Clean v2.2.0 due to incorrect access control in a d...

Jun 3, 2024
CVE-2024-35353
9.8

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Diño Physics School Assistant version 2.3. Attackers can manipulate th...

May 30, 2024
CVE-2024-28394
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of the Advanced Plugins reportsstatistics ...

Mar 19, 2024
CVE-2023-6036
9.8

The Web3 WordPress plugin before version 3.0.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to log in as any ...

Feb 12, 2024
CVE-2023-22518
9.8

CVE-2023-22518 is an improper authorization vulnerability in Confluence Data Center and Server that allows unauthenticated attackers to reset the appl...

Oct 31, 2023
CVE-2023-34051
9.8

CVE-2023-34051 is an authentication bypass vulnerability in VMware Aria Operations for Logs that allows unauthenticated attackers to inject files and ...

Oct 20, 2023
CVE-2023-43119
9.8

An access control vulnerability in Extreme Networks Switch Engine (EXOS) allows attackers to gain escalated privileges via crafted telnet commands thr...

Oct 16, 2023
CVE-2023-5521
9.8

This vulnerability allows attackers to bypass authorization checks in KernelSU, a root solution for Android devices. Attackers could gain unauthorized...

Oct 11, 2023
CVE-2023-40309
9.8

CVE-2023-40309 is an authentication bypass vulnerability in SAP CommonCryptoLib that allows authenticated users to escalate privileges by bypassing au...

Sep 12, 2023

About Incorrect Authorization (CWE-863)

The product performs an authorization check when an actor attempts to access a resource, but it does not correctly perform the check.

Our database tracks 708 CVEs classified as CWE-863, with 138 rated critical and 313 rated high severity. The average CVSS score for Incorrect Authorization vulnerabilities is 7.3.

External reference: View CWE-863 on MITRE CWE →

Monitor Incorrect Authorization Vulnerabilities

Get alerted when new Incorrect Authorization CVEs affect your infrastructure.

Start Monitoring Free