CWE-863: Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource, but it does not correctly perform the check.

713
Total CVEs
140
Critical
316
High
7.3
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
77
2025
260
2024
164
2023
97
2022
35

Top Affected Vendors

1 Oracle 34
2 Apple 26
3 Adobe 23
4 Google 19
5 Mattermost 18
6 Gitlab 16
7 Ibm 13
8 Apache 10
9 Wso2 7
10 Lunary 7

All Incorrect Authorization CVEs (713)

CVE-2025-20300
4.3

In affected Splunk Enterprise and Cloud Platform versions, a low-privileged user with read-only access to a specific alert can suppress that alert whe...

Jul 7, 2025
CVE-2025-47871
4.3

This vulnerability allows authenticated Mattermost users who are members of a playbook but not members of a linked private channel to access sensitive...

Jun 30, 2025
CVE-2025-49550
4.3

Adobe Commerce has an incorrect authorization vulnerability (CWE-863) that allows attackers to bypass security features and gain limited unauthorized ...

Jun 25, 2025
CVE-2024-3511
4.3

This CVE describes an authorization bypass vulnerability in WSO2 products that allows authenticated users with management console access to retrieve v...

Jun 23, 2025
CVE-2025-3227
4.3

This vulnerability allows authenticated Mattermost users without proper channel management permissions to add or remove users from public and private ...

Jun 20, 2025
CVE-2025-3880
4.3

This vulnerability in the Poll, Survey & Quiz Maker Plugin by Opinion Stage for WordPress allows authenticated attackers with Contributor-level access...

Jun 17, 2025
CVE-2025-40568
4.3

This vulnerability allows authenticated remote attackers with 'guest' role privileges to terminate legitimate user sessions in affected Siemens indust...

Jun 10, 2025
CVE-2024-7097
EPSS 22.1% 4.3

This vulnerability allows attackers to create unauthorized user accounts in WSO2 products regardless of self-registration settings. It affects WSO2 pr...

May 30, 2025
CVE-2025-48473
4.3

This vulnerability in FreeScout allows authenticated users to view messages from conversations they shouldn't have access to when creating new convers...

May 29, 2025
CVE-2025-3645
4.3

This vulnerability in Moodle allows users to bypass authorization checks in a messaging web service, enabling them to view other users' names and onli...

Apr 25, 2025
CVE-2025-27571
4.3

This vulnerability allows authenticated users to view metadata from archived channels even when the 'Allow Users to View Archived Channels' setting is...

Apr 16, 2025
CVE-2025-27188
4.3

CVE-2025-27188 is an improper authorization vulnerability in Adobe Commerce that allows attackers to bypass security controls and escalate privileges ...

Apr 8, 2025
CVE-2025-30155
4.3

Tuleap's REST API fails to enforce read permissions on parent trackers, allowing authenticated users to access tracker data they shouldn't have permis...

Mar 31, 2025
CVE-2025-30741
4.3

A Pixelfed vulnerability allows unauthorized users to follow private accounts and view private posts across Fediverse servers. This affects all Pixelf...

Mar 25, 2025
CVE-2025-24920
4.3

Mattermost fails to restrict bookmark creation and updates in archived channels, allowing authenticated users to create or modify bookmarks in channel...

Mar 21, 2025
CVE-2025-25274
4.3

This vulnerability allows authenticated users to execute slash commands in archived Mattermost channels, bypassing intended restrictions. It affects M...

Mar 21, 2025
CVE-2025-1472
4.3

Mattermost versions 9.11.x through 9.11.8 have an authorization flaw where users with the Viewer role configured with 'No Access to Reporting' can sti...

Mar 19, 2025
CVE-2025-0652
4.3

This CVE describes an information disclosure vulnerability in GitLab EE/CE that allows unauthorized users to access confidential information intended ...

Mar 13, 2025
CVE-2025-2045
4.3

This CVE describes an improper authorization vulnerability in GitLab EE that allows users with limited permissions to access potentially sensitive pro...

Mar 6, 2025
CVE-2025-24526
4.3

This vulnerability allows authenticated Mattermost users to export archived channel contents even when the 'Allow users to view archived channels' set...

Feb 24, 2025
CVE-2025-0516
4.3

This CVE describes an improper authorization vulnerability in GitLab CE/EE that allows users with limited permissions to perform unauthorized actions ...

Feb 12, 2025
CVE-2025-24436
4.3

Adobe Commerce has an incorrect authorization vulnerability that allows low-privileged attackers to bypass security features and view select informati...

Feb 11, 2025
CVE-2025-24421
4.3

Adobe Commerce has an incorrect authorization vulnerability that allows low-privileged attackers to bypass security features and read select data with...

Feb 11, 2025
CVE-2025-24419
4.3

CVE-2025-24419 is an incorrect authorization vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security features and modi...

Feb 11, 2025
CVE-2025-24869
4.3

CVE-2025-24869 is an information disclosure vulnerability in SAP NetWeaver Application Server Java that allows unauthorized access to endpoint data re...

Feb 11, 2025
CVE-2025-24872
4.3

This vulnerability in SAP ABAP Platform's ABAP Build Framework allows authenticated attackers to access a specific transaction without proper authoriz...

Feb 11, 2025
CVE-2025-23419
4.3

This CVE describes a client certificate authentication bypass vulnerability in nginx when multiple server blocks share the same IP/port. Attackers can...

Feb 5, 2025
CVE-2024-22316
4.3

CVE-2024-22316 is an improper access control vulnerability in IBM Sterling File Gateway that allows authenticated users to perform unauthorized action...

Jan 27, 2025
CVE-2025-24400
4.3

The Jenkins Eiffel Broadcaster Plugin vulnerability allows attackers who can create credentials with the same ID as legitimate ones in different crede...

Jan 22, 2025
CVE-2025-21562
4.3

This vulnerability in Oracle PeopleSoft Enterprise CC Common Application Objects allows authenticated attackers with low privileges to read sensitive ...

Jan 21, 2025
CVE-2025-21517
4.3

This vulnerability in Oracle JD Edwards EnterpriseOne Tools allows authenticated attackers with low privileges to modify data via HTTP requests. It af...

Jan 21, 2025
CVE-2024-57683
4.3

This vulnerability allows unauthenticated attackers to modify URL filter settings on affected D-Link DIR-816A2 routers via a crafted POST request. Att...

Jan 16, 2025
CVE-2024-13270
4.3

This CVE describes an incorrect authorization vulnerability in Drupal's Freelinking module that allows forceful browsing. Attackers can bypass intende...

Jan 9, 2025
CVE-2023-52943
4.3

This vulnerability allows authenticated users to perform unauthorized actions on the alerting function in Synology Surveillance Station. Attackers wit...

Dec 4, 2024
CVE-2024-45125
4.3

Adobe Commerce has an incorrect authorization vulnerability that allows low-privileged attackers to bypass security features and potentially modify da...

Oct 10, 2024
CVE-2024-47160
4.3

This vulnerability in JetBrains YouTrack allows unauthorized users to access global application configuration data. It affects all YouTrack instances ...

Sep 19, 2024
CVE-2024-7266
4.3

This vulnerability allows logged-in users in the EZD RP system to list all users, including those from other organizations, violating access control b...

Aug 7, 2024
CVE-2024-6150
4.3

This vulnerability in Citrix Provisioning allows non-admin users to temporarily disrupt target VM availability through improper authorization checks. ...

Jul 10, 2024
CVE-2024-31402
4.3

An incorrect authorization vulnerability in Cybozu Garoon allows authenticated users to delete Shared To-Do data they shouldn't have access to. This a...

Jun 11, 2024
CVE-2019-1192
4.3

This CVE describes a Same-Origin Policy bypass vulnerability in Microsoft browsers that allows attackers to force browsers to send cross-origin data t...

Aug 14, 2019
CVE-2025-43904
4.2

This vulnerability in SchedMD Slurm allows a Coordinator user to escalate privileges to Administrator level through the accounting system. It affects ...

Jan 16, 2026
CVE-2025-66433
4.2

HTCondor Access Point versions 24.7.3 through 25.3.0 allow authenticated users to impersonate other users on the local machine by submitting batch job...

Nov 30, 2025
CVE-2025-64641
4.1

This vulnerability allows malicious Mattermost users to create posts with fake Jira plugin actions that exfiltrate Jira tickets when other users inter...

Dec 24, 2025
CVE-2025-20999
4.1

This vulnerability allows secondary users on Samsung Galaxy Tablets to access the primary owner's saved Wi-Fi passwords due to improper authorization ...

Jul 8, 2025
CVE-2025-43307
4.0

This macOS vulnerability allows applications to bypass security checks and access sensitive user data without proper authorization. It affects macOS s...

Sep 15, 2025
CVE-2024-47148
4.0

This CVE describes an incorrect privilege assignment vulnerability in certain Honor products. Successful exploitation could cause device service excep...

Dec 26, 2024
CVE-2024-34652
4.0

This vulnerability allows local attackers to bypass authorization checks in Samsung's kperfmon performance monitoring component, enabling unauthorized...

Sep 4, 2024
CVE-2024-34650
4.0

This vulnerability allows local attackers to bypass authorization checks in CocktailbarService on Samsung devices, enabling access to privileged Edge ...

Sep 4, 2024
CVE-2025-13324
3.7

This vulnerability allows attackers who obtain remote cluster invite tokens to authenticate as remote clusters and perform limited actions on shared c...

Dec 17, 2025
CVE-2025-15288
3.1

CVE-2025-15288 is an improper access control vulnerability in Tanium Interact that could allow authenticated users to access data or perform actions b...

Jan 29, 2026

About Incorrect Authorization (CWE-863)

The product performs an authorization check when an actor attempts to access a resource, but it does not correctly perform the check.

Our database tracks 713 CVEs classified as CWE-863, with 140 rated critical and 316 rated high severity. The average CVSS score for Incorrect Authorization vulnerabilities is 7.3.

External reference: View CWE-863 on MITRE CWE →

Monitor Incorrect Authorization Vulnerabilities

Get alerted when new Incorrect Authorization CVEs affect your infrastructure.

Start Monitoring Free