CWE-863: Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource, but it does not correctly perform the check.

710
Total CVEs
138
Critical
315
High
7.3
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
77
2025
260
2024
164
2023
97
2022
35

Top Affected Vendors

1 Oracle 34
2 Apple 26
3 Adobe 23
4 Google 19
5 Mattermost 18
6 Gitlab 16
7 Ibm 13
8 Apache 10
9 Wso2 7
10 Lunary 7

All Incorrect Authorization CVEs (710)

CVE-2023-5009
8.2

This vulnerability allows attackers to bypass security controls in GitLab EE and execute pipeline jobs as arbitrary users via scheduled security scan ...

Sep 19, 2023
CVE-2023-26484
8.2

This vulnerability in KubeVirt allows a compromised Kubernetes node to use the virt-handler service account to modify other node specifications, poten...

Mar 15, 2023
CVE-2026-25767
8.1

In LavinMQ versions before 2.6.8, authenticated users with the 'Policymaker' management tag can bypass access controls to create shovels, allowing the...

Feb 12, 2026
CVE-2026-21721
8.1

This CVE describes an authorization bypass in Grafana's dashboard permissions API where permission checks only validate the action permission without ...

Jan 27, 2026
CVE-2025-41078
8.1

This vulnerability in Viafirma Documents v3.7.129 allows authenticated users without proper privileges to access other users' data, manipulate user ac...

Jan 12, 2026
CVE-2023-7322
8.1

Nagios Log Server versions before 2024R1 have an incorrect authorization vulnerability where authenticated users without proper API permissions can ac...

Oct 30, 2025
CVE-2025-62506
8.1

MinIO versions before RELEASE.2025-10-15T17-29-55Z contain a privilege escalation vulnerability where restricted service accounts and STS accounts can...

Oct 16, 2025
CVE-2025-54263
8.1

Adobe Commerce has an incorrect authorization vulnerability that allows low-privileged attackers to bypass security controls and maintain unauthorized...

Oct 14, 2025
CVE-2025-3719
8.1

An access control vulnerability in CLI functionality allows authenticated users with limited privileges to execute administrative commands. This enabl...

Oct 7, 2025
CVE-2025-30743
8.1

This vulnerability in Oracle Lease and Finance Management allows authenticated attackers with network access to manipulate critical data or access sen...

Jul 15, 2025
CVE-2025-52890
8.1

This vulnerability in Incus versions 6.12 and 6.13 allows attackers to bypass MAC and IP filtering security options when using ACLs on bridged devices...

Jun 25, 2025
CVE-2025-48466
8.1

This vulnerability allows unauthenticated remote attackers to send malicious Modbus TCP packets to manipulate Digital Outputs on affected devices. Att...

Jun 24, 2025
CVE-2025-48475
8.1

CVE-2025-48475 is an authorization bypass vulnerability in FreeScout help desk software where authenticated users without mailbox or conversation acce...

May 29, 2025
CVE-2025-48474
8.1

FreeScout help desk software versions before 1.8.180 contain an access control vulnerability where users with 'show_only_assigned_conversations' enabl...

May 29, 2025
CVE-2024-41140
8.1

This vulnerability allows attackers with existing user accounts to escalate privileges by exploiting incorrect authorization checks in the update user...

Jan 29, 2025
CVE-2025-21516
8.1

This vulnerability in Oracle Customer Care allows authenticated attackers with low privileges to perform unauthorized data manipulation and access via...

Jan 21, 2025
CVE-2025-21506
8.1

This vulnerability in Oracle Project Foundation allows authenticated attackers with low privileges to manipulate or access sensitive data via HTTP req...

Jan 21, 2025
CVE-2024-3379
8.1

An incorrect authorization vulnerability in lunary-ai/lunary allows users with 'Member' role to regenerate private keys for projects they shouldn't ha...

Nov 14, 2024
CVE-2024-21278
8.1

This vulnerability in Oracle Contract Lifecycle Management for Public Sector allows authenticated attackers with network access via HTTP to perform un...

Oct 15, 2024
CVE-2024-21280
8.1

This vulnerability in Oracle Service Contracts allows authenticated attackers with low privileges to perform unauthorized data manipulation and access...

Oct 15, 2024
CVE-2024-21282
8.1

This vulnerability in Oracle Financials (E-Business Suite) allows authenticated attackers with low privileges to perform unauthorized data manipulatio...

Oct 15, 2024
CVE-2024-21276
8.1

This vulnerability in Oracle Work in Process allows authenticated attackers with network access to manipulate critical data or gain unauthorized acces...

Oct 15, 2024
CVE-2024-21267
8.1

This vulnerability in Oracle Cost Management allows authenticated attackers with network access to manipulate critical data or access sensitive inform...

Oct 15, 2024
CVE-2024-21269
8.1

This vulnerability in Oracle Incentive Compensation allows authenticated attackers with low privileges to perform unauthorized data manipulation and a...

Oct 15, 2024
CVE-2024-21271
8.1

This vulnerability in Oracle Field Service allows authenticated attackers with low privileges to perform unauthorized data manipulation and access sen...

Oct 15, 2024
CVE-2024-21265
8.1

This vulnerability in Oracle Site Hub allows authenticated attackers with low privileges to perform unauthorized data manipulation and access sensitiv...

Oct 15, 2024
CVE-2024-45588
8.1

This vulnerability allows authenticated attackers to bypass access controls in Symphony XTS Web Trading platform's Preference module APIs. By manipula...

Sep 3, 2024
CVE-2024-41964
8.1

This vulnerability in Kirby CMS allows attackers with Panel access to manipulate language definitions despite permission restrictions. Users with rest...

Aug 29, 2024
CVE-2024-21149
8.1

This vulnerability in Oracle Enterprise Asset Management allows authenticated attackers with low privileges to manipulate critical data or access sens...

Jul 16, 2024
CVE-2024-27312
8.1

CVE-2024-27312 is an authorization vulnerability in ManageEngine PAM360 version 6601 that allows low-privileged users to perform administrative action...

May 20, 2024
CVE-2024-31452
8.1

OpenFGA versions 1.5.0 to 1.5.2 contain an authorization bypass vulnerability in Check and ListObjects APIs when using models with exclusion or inters...

Apr 16, 2024
CVE-2024-27105
8.1

This vulnerability allows less privileged users to bypass file permission controls in Frappe framework, enabling them to delete or clone files they sh...

Mar 21, 2024
CVE-2023-47320
8.1

Silverpeas Core 6.3.1 and earlier versions have an incorrect access control vulnerability that allows low-privileged users to execute administrator-on...

Dec 13, 2023
CVE-2023-34923
8.1

This vulnerability allows attackers with valid Identity Provider credentials to impersonate any TOPdesk user by manipulating SAML responses through XM...

Jun 22, 2023
CVE-2023-31435
8.1

This vulnerability in evasys software allows authenticated attackers to bypass authorization controls and access unauthorized data through direct func...

May 2, 2023
CVE-2023-25017
8.1

CVE-2023-25017 is an incorrect authorization vulnerability in RIFARTEK IOT Wall devices that allows authenticated users with general privileges to acc...

Mar 27, 2023
CVE-2022-24721
8.1

CVE-2022-24721 is an authorization bypass vulnerability in CometD web messaging framework that allows any remote user to subscribe to and publish on i...

Mar 15, 2022
CVE-2021-39156
8.1

This vulnerability allows attackers to bypass Istio's URI path-based authorization policies by sending HTTP requests with URL fragments (#fragment) in...

Aug 24, 2021
CVE-2021-38137
8.1

CVE-2021-38137 is an improper authorization vulnerability in Corero SecureWatch Managed Services where swa-monitor and cns-monitor users can perform a...

Aug 6, 2021
CVE-2021-1539
8.1

This vulnerability allows authenticated remote attackers to bypass authorization controls on Cisco ASR 5000 Series devices running StarOS software. At...

Jun 4, 2021
CVE-2021-21389
8.1

This vulnerability in BuddyPress allows non-privileged users to escalate their privileges to administrator level by exploiting an issue in the REST AP...

Mar 26, 2021
CVE-2021-21013
8.1

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Magento's customer API module. Attackers can access or modify other use...

Jan 13, 2021
CVE-2025-64421
8.0

This vulnerability allows low-privileged users in Coolify to invite themselves as administrators through a race condition exploit. By clicking the inv...

Jan 5, 2026
CVE-2024-45261
8.0

This vulnerability allows attackers to bypass authentication on affected GL-iNet routers by exploiting improperly generated session IDs (SIDs) that ar...

Oct 24, 2024
CVE-2024-2378
8.0

This vulnerability in the SDM600 web-authentication component allows attackers to escalate privileges on affected installations. It affects SDM600 dev...

Apr 30, 2024
CVE-2021-24905
8.0

This vulnerability in the Advanced Contact form 7 DB WordPress plugin allows any authenticated user to delete arbitrary files on the web server due to...

Mar 21, 2022
CVE-2022-24128
8.0

TimescaleDB versions before 2.5.2 contain a privilege escalation vulnerability during extension installation. An unprivileged database user can pre-cr...

Mar 13, 2022
CVE-2021-29437
8.0

This vulnerability allows third-party websites to trick Scratch users into revealing OAuth2 login codes, enabling attackers to impersonate users and g...

Apr 13, 2021
CVE-2026-21274
7.8

An incorrect authorization vulnerability in Adobe Dreamweaver Desktop allows attackers to execute arbitrary code with the current user's privileges. U...

Jan 13, 2026
CVE-2025-47382
7.8

This vulnerability allows memory corruption in the boot loader when loading invalid firmware, potentially enabling attackers to execute arbitrary code...

Dec 18, 2025

About Incorrect Authorization (CWE-863)

The product performs an authorization check when an actor attempts to access a resource, but it does not correctly perform the check.

Our database tracks 710 CVEs classified as CWE-863, with 138 rated critical and 315 rated high severity. The average CVSS score for Incorrect Authorization vulnerabilities is 7.3.

External reference: View CWE-863 on MITRE CWE →

Monitor Incorrect Authorization Vulnerabilities

Get alerted when new Incorrect Authorization CVEs affect your infrastructure.

Start Monitoring Free