CWE-863: Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource, but it does not correctly perform the check.

699
Total CVEs
138
Critical
304
High
7.3
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
77
2025
260
2024
164
2023
97
2022
35

Top Affected Vendors

1 Oracle 34
2 Apple 26
3 Adobe 22
4 Google 19
5 Mattermost 18
6 Gitlab 16
7 Ibm 13
8 Apache 10
9 Wso2 7
10 Lunary 7

All Incorrect Authorization CVEs (699)

CVE-2023-38035
9.8

This vulnerability allows attackers to bypass authentication on the Ivanti MobileIron Sentry administrative interface due to an overly permissive Apac...

Aug 21, 2023
CVE-2023-32748
9.8

This vulnerability allows an unauthenticated attacker with internal network access to execute arbitrary scripts on Mitel MiVoice Connect systems due t...

Aug 14, 2023
CVE-2023-36089
9.8

CVE-2023-36089 is an authentication bypass vulnerability in D-Link DIR-645 routers that allows remote attackers to gain escalated privileges without v...

Jul 31, 2023
CVE-2023-36091
9.8

This CVE describes an authentication bypass vulnerability in D-Link DIR-895 routers running firmware version FW102b07. Remote attackers can exploit a ...

Jul 31, 2023
CVE-2023-31704
9.8

CVE-2023-31704 is an incorrect access control vulnerability in Sourcecodester Online Computer and Laptop Store 1.0 that allows remote attackers to esc...

Jul 13, 2023
CVE-2023-29381
9.8

This vulnerability in Zimbra Collaboration Suite allows remote attackers to bypass authentication mechanisms and escalate privileges by exploiting fla...

Jul 6, 2023
CVE-2022-46080
9.8

This vulnerability in Nexxt Nebula 1200-AC routers allows attackers to bypass authentication and execute arbitrary commands by exploiting the HTTPD se...

Jul 6, 2023
CVE-2021-46890
9.8

This vulnerability in Huawei GPU modules allows attackers to bypass read/write permission checks, potentially leading to unauthorized access to sensit...

Jul 5, 2023
CVE-2023-26258
9.8

Arcserve UDP backup software through version 9.0.6034 has an authentication bypass vulnerability where the getVersionInfo endpoint leaks an AuthUUID t...

Jul 3, 2023
CVE-2023-28698
9.8

CVE-2023-28698 is an authorization bypass vulnerability in Wade Graphic Design FANTSY software that allows unauthenticated attackers to gain administr...

Jun 2, 2023
CVE-2023-30771
9.8

This CVE describes an incorrect authorization vulnerability in Apache IoTDB's web-workbench component (version 0.13.3). Attackers can bypass authoriza...

Apr 17, 2023
CVE-2023-23594
9.8

An authentication bypass vulnerability in CL4NX printer web interfaces allows remote attackers to execute privileged commands without valid credential...

Mar 31, 2023
CVE-2023-26829
9.8

This critical authentication bypass vulnerability in Gladinet CentreStack allows remote attackers to reset passwords for any valid user account withou...

Mar 31, 2023
CVE-2023-1136
9.8

This vulnerability allows unauthenticated attackers to generate valid authentication tokens in Delta Electronics InfraSuite Device Master, leading to ...

Mar 27, 2023
CVE-2023-23064
9.8

CVE-2023-23064 is an incorrect access control vulnerability in TOTOLINK A720R routers that allows unauthenticated attackers to bypass authentication a...

Feb 17, 2023
CVE-2021-32163
9.8

CVE-2021-32163 is an authentication vulnerability in MOSN v0.23.0 that allows attackers to bypass JWT authorization checks through case-sensitive stri...

Feb 17, 2023
CVE-2022-47002
9.8

This vulnerability allows attackers to bypass authentication in Masa CMS by exploiting a flaw in the Remember Me function. Attackers can gain unauthor...

Feb 1, 2023
CVE-2022-35890
9.8

This vulnerability allows attackers to predict previously generated session IDs in Inductive Automation Ignition, enabling session hijacking. Attacker...

Jul 15, 2022
CVE-2022-32294
9.8

Zimbra Collaboration Open Source 8.8.15 logs randomly generated initial login passwords in cleartext via syslog on UDP port 514. This allows attackers...

Jul 11, 2022
CVE-2022-33174
9.8

CVE-2022-33174 is an authentication bypass vulnerability in Powertek-based Power Distribution Units (PDUs) that allows attackers to access administrat...

Jun 13, 2022
CVE-2022-24609
9.8

Luocms v2.0 has an incorrect access control vulnerability that allows attackers to write arbitrary shell files via /admin/templates/template_manage.ph...

Mar 10, 2022
CVE-2022-24307
9.8

Mastodon instances running vulnerable versions have incorrect access control due to improper handling of signed JSON-LD activities. This allows attack...

Feb 3, 2022
CVE-2020-4877
9.8

This vulnerability in IBM Cognos Controller allows attackers to modify application behavior by exploiting public fields in public classes, potentially...

Jan 21, 2022
CVE-2021-20149
9.8

This vulnerability allows attackers to bypass IPv4 firewall rules and access all services on Trendnet AC2600 routers via IPv6 WAN interface. It affect...

Dec 30, 2021
CVE-2021-21693
9.8

This vulnerability in Jenkins allows agents to create temporary files on the controller before access controls are checked, enabling unauthorized file...

Nov 4, 2021
CVE-2020-21124
9.8

CVE-2020-21124 is a critical access control vulnerability in UReport 2.2.9 that allows attackers to reach the designer page without authentication, le...

Sep 15, 2021
CVE-2020-18701
9.8

CVE-2020-18701 is an authentication token invalidation vulnerability in Lin-CMS-Flask v0.1.1 that allows attackers to replay authentication tokens aft...

Aug 16, 2021
CVE-2020-19301
9.8

This vulnerability allows remote attackers to execute arbitrary code on vaeThink v1.0.1 systems by injecting malicious payloads into the condition par...

Aug 3, 2021
CVE-2021-22389
9.8

This is a critical permission control vulnerability in Huawei smartphones that allows attackers to bypass security restrictions and execute arbitrary ...

Aug 2, 2021
CVE-2010-1435
9.8

This vulnerability in Joomla! Core allows attackers to bypass security restrictions and retrieve password reset tokens from the database via an existi...

Jun 21, 2021
CVE-2020-20466
9.8

CVE-2020-20466 allows remote attackers to modify any user's password in White Shark System 1.3.2 via the user_edit_password.php endpoint without authe...

Jun 21, 2021
CVE-2021-28793
9.8

CVE-2021-28793 is an incorrect access control vulnerability in the vscode-restructuredtext extension for Visual Studio Code. It allows arbitrary binar...

Apr 20, 2021
CVE-2020-28872
9.8

This vulnerability allows unauthorized attackers to create valid administrative credentials in Monitorr v1.7.6m, bypassing authentication entirely. Th...

Apr 12, 2021
CVE-2020-24264
9.8

CVE-2020-24264 is an access control vulnerability in Portainer that allows authenticated users to bypass bind mount restrictions and execute arbitrary...

Mar 16, 2021
CVE-2021-21484
9.8

This vulnerability allows attackers to bypass LDAP authentication in SAP HANA Database when the LDAP directory server is configured to permit unauthen...

Mar 9, 2021
CVE-2021-27177
9.8

This vulnerability allows attackers to bypass authentication on FiberHome HG6245D devices by sending a specific decoded string to the telnet server. I...

Feb 10, 2021
CVE-2016-20001
9.8

This vulnerability in Drupal's REST/JSON module allows attackers to bypass node access controls and view restricted content. It affects Drupal 7.x sit...

Jan 1, 2021
CVE-2016-20004
9.8

This vulnerability in Drupal's REST/JSON module allows attackers to bypass field access controls, potentially accessing or modifying restricted conten...

Jan 1, 2021
CVE-2020-27156
9.8

CVE-2020-27156 is a critical authorization bypass vulnerability in Veritas APTARE that allows unauthenticated remote attackers to execute arbitrary co...

Oct 15, 2020
CVE-2020-13957
9.8

This vulnerability in Apache Solr allows attackers to bypass security controls and upload malicious ConfigSets via API without authentication. By comb...

Oct 13, 2020
CVE-2023-31403
9.6

This vulnerability in SAP Business One version 10.0 allows unauthenticated attackers to read, write, and execute files on SMB shared folders used duri...

Nov 14, 2023
CVE-2022-1309
9.6

This vulnerability in Google Chrome's developer tools allows attackers to escape the browser's security sandbox via a malicious HTML page. It affects ...

Jul 25, 2022
CVE-2021-30571
9.6

This vulnerability in Google Chrome DevTools allows a malicious extension to escape the browser's security sandbox when a user visits a crafted HTML p...

Aug 3, 2021
CVE-2024-3033
9.4

An improper authorization vulnerability in the mintplex-labs/anything-llm application allows unauthenticated users to perform destructive actions on t...

Jun 6, 2024
CVE-2025-53391
9.3

This vulnerability in Debian's zuluCrypt package allows local users to escalate privileges to root due to insecure PolicyKit settings. The flaw exists...

Jun 28, 2025
CVE-2024-48548
9.3

This vulnerability in Cloud Smart Lock v2.0.1 allows attackers to discover and exploit a leaked API URL to bind unauthorized physical devices to user ...

Oct 24, 2024
CVE-2021-21276
9.3

CVE-2021-21276 is a critical authentication bypass vulnerability in Polr URL shortener that allows unauthenticated attackers to gain administrative ac...

Feb 1, 2021
CVE-2026-25811
9.1

PlaciPy placement management system version 1.0.0 allows cross-tenant data access by deriving tenant identifiers from user-provided email domains with...

Feb 9, 2026
CVE-2026-22806
9.1

This vulnerability in vCluster Platform allows users with scoped access keys to bypass scope restrictions and access resources outside their intended ...

Jan 29, 2026
CVE-2025-66719
9.1

This vulnerability in Free5gc NRF 1.4.0 allows attackers to bypass scope validation during access token generation by using a crafted targetNF value. ...

Jan 23, 2026

About Incorrect Authorization (CWE-863)

The product performs an authorization check when an actor attempts to access a resource, but it does not correctly perform the check.

Our database tracks 699 CVEs classified as CWE-863, with 138 rated critical and 304 rated high severity. The average CVSS score for Incorrect Authorization vulnerabilities is 7.3.

External reference: View CWE-863 on MITRE CWE →

Monitor Incorrect Authorization Vulnerabilities

Get alerted when new Incorrect Authorization CVEs affect your infrastructure.

Start Monitoring Free