CWE-863: Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource, but it does not correctly perform the check.

710
Total CVEs
138
Critical
315
High
7.3
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
77
2025
260
2024
164
2023
97
2022
35

Top Affected Vendors

1 Oracle 34
2 Apple 26
3 Adobe 23
4 Google 19
5 Mattermost 18
6 Gitlab 16
7 Ibm 13
8 Apache 10
9 Wso2 7
10 Lunary 7

All Incorrect Authorization CVEs (710)

CVE-2025-14305
7.8

CVE-2025-14305 is a local privilege escalation vulnerability in Acer's ListCheck.exe. Authenticated local attackers can replace this executable with m...

Dec 17, 2025
CVE-2025-43387
7.8

A permissions vulnerability in macOS allows malicious applications to escalate privileges to root access. This affects macOS systems running versions ...

Nov 4, 2025
CVE-2025-32333
7.8

This CVE describes a cross-user permission bypass vulnerability in Android's Settings app that allows local privilege escalation without user interact...

Sep 4, 2025
CVE-2025-6018
7.8

This CVE-2025-6018 is a Local Privilege Escalation vulnerability in pam-config that allows unprivileged local users (e.g., SSH users) to gain elevated...

Jul 23, 2025
CVE-2025-25251
7.8

A local privilege escalation vulnerability in FortiClient for macOS allows attackers with local access to gain elevated privileges by sending speciall...

May 28, 2025
CVE-2025-23244
7.8

A vulnerability in NVIDIA GPU Display Driver for Linux allows unprivileged attackers to escalate permissions, potentially leading to code execution, d...

May 1, 2025
CVE-2024-44305
7.8

This vulnerability allows a malicious application to gain root privileges on affected macOS systems. It affects macOS Sonoma versions before 14.6. The...

Mar 21, 2025
CVE-2025-30074
7.8

This vulnerability in Parallels Desktop for macOS on Intel platforms allows local attackers to escalate privileges to root during VM creation. It affe...

Mar 16, 2025
CVE-2024-45328
7.8

This vulnerability allows low-privileged administrators in FortiSandbox to execute elevated CLI commands through the GUI console menu due to incorrect...

Mar 11, 2025
CVE-2024-40771
7.8

This is a memory handling vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileges. Attack...

Jan 15, 2025
CVE-2018-9374
7.8

CVE-2018-9374 is an Android permissions bypass vulnerability in the PackageManagerService that allows local privilege escalation. Attackers can instal...

Nov 28, 2024
CVE-2023-21270
7.8

This Android vulnerability allows malicious apps to retain permissions that should have been revoked during system updates, potentially leading to loc...

Nov 19, 2024
CVE-2024-29821
7.8

This vulnerability in Ivanti DSM allows authenticated local users to execute arbitrary code with elevated privileges due to insecure access control li...

Oct 18, 2024
CVE-2024-48911
7.8

OpenCanary versions before 0.9.4 have a privilege escalation vulnerability where an unprivileged user can modify the configuration file, which is then...

Oct 14, 2024
CVE-2024-47560
7.8

RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability that allows unauthorized processes to execute within the s...

Oct 1, 2024
CVE-2024-44162
7.8

This vulnerability in Xcode allows malicious applications to bypass security controls and access Keychain items containing sensitive user data like pa...

Sep 17, 2024
CVE-2024-38884
7.8

This vulnerability allows a local attacker to bypass authentication mechanisms in Caterease software, potentially gaining unauthorized access to the s...

Aug 2, 2024
CVE-2024-27848
7.8

A permissions checking vulnerability in Apple operating systems allows malicious applications to gain root privileges. This affects macOS, iOS, and iP...

Jun 10, 2024
CVE-2024-36963
7.8

A Linux kernel vulnerability in tracefs where file permissions aren't properly reset during remount operations. This allows files with previously modi...

Jun 3, 2024
CVE-2024-3745
7.8

MSI Afterburner v4.6.6.16381 Beta 3 contains an ACL bypass vulnerability in its RTCore64.sys driver that allows low-privileged users to trigger additi...

May 18, 2024
CVE-2024-22938
7.8

This vulnerability in BossCMS v1.3.0 allows a local attacker to execute arbitrary code and escalate privileges through insecure permissions in the adm...

Jan 30, 2024
CVE-2023-21390
7.8

CVE-2023-21390 is a permission bypass vulnerability in Android's SIM component that allows attackers to evade mobile preference restrictions without u...

Oct 30, 2023
CVE-2023-40117
7.8

This vulnerability allows an attacker with physical access to bypass the Android device lockscreen without authentication. It affects Android devices ...

Oct 27, 2023
CVE-2023-2640
7.8

CVE-2023-2640 is a privilege escalation vulnerability in Ubuntu's overlayfs implementation where unprivileged users can set privileged extended attrib...

Jul 26, 2023
CVE-2023-21254
7.8

This Android vulnerability allows malicious apps to retain one-time permissions after being killed, enabling local privilege escalation without user i...

Jul 13, 2023
CVE-2023-21256
7.8

This vulnerability in Android's Settings app allows attackers to launch arbitrary activities through a logic error in SettingsHomepageActivity.java. I...

Jul 13, 2023
CVE-2023-21225
7.8

This Android kernel vulnerability allows attackers to bypass the protected confirmation screen by exploiting a failure to lock display power. This cou...

Jun 28, 2023
CVE-2023-32353
7.8

This CVE describes a privilege escalation vulnerability in iTunes for Windows where a malicious application could exploit a logic flaw to gain elevate...

Jun 23, 2023
CVE-2022-31644
7.8

This CVE describes BIOS vulnerabilities in certain HP PC products that could allow attackers to execute arbitrary code, escalate privileges, cause den...

Jun 14, 2023
CVE-2022-31646
7.8

This CVE describes BIOS vulnerabilities in certain HP PC products that could allow attackers to execute arbitrary code, escalate privileges, cause den...

Jun 14, 2023
CVE-2023-29766
7.8

This vulnerability in CrossX v1.15.3 for Android allows a local attacker to escalate privileges by manipulating database files. The flaw enables unaut...

Jun 9, 2023
CVE-2023-21117
7.8

This vulnerability allows isolated processes on Android 13 devices to register broadcast receivers without proper permissions, bypassing security rest...

May 15, 2023
CVE-2023-20871
7.8

This CVE describes a local privilege escalation vulnerability in VMware Fusion where an attacker with read/write access to the host OS can elevate pri...

Apr 25, 2023
CVE-2023-20950
7.8

This vulnerability allows malicious apps to bypass Android's background activity launch restrictions using a specially crafted PendingIntent. It enabl...

Apr 19, 2023
CVE-2023-21034
7.8

This vulnerability allows local attackers to bypass sensor permissions on Android 13 devices, potentially accessing sensitive sensor data without prop...

Mar 24, 2023
CVE-2023-20975
7.8

This vulnerability allows local attackers to bypass DISALLOW_CONTENT_CAPTURE restrictions on Android devices, potentially enabling unauthorized conten...

Mar 24, 2023
CVE-2023-20971
7.8

This Android vulnerability allows local attackers to obtain dangerous permissions without user consent due to a logic error in the permission removal ...

Mar 24, 2023
CVE-2021-39789
7.8

This vulnerability in Android's Telecom component allows local attackers to escalate privileges without user interaction by exploiting a missing permi...

Mar 30, 2022
CVE-2019-25058
7.8

CVE-2019-25058 is a privilege escalation vulnerability in USBGuard versions before 1.1.0 where the usbguard-dbus daemon allows unprivileged users to m...

Feb 24, 2022
CVE-2021-3560
7.8

CVE-2021-3560 is a privilege escalation vulnerability in polkit's D-Bus authentication mechanism that allows unprivileged local users to bypass creden...

Feb 16, 2022
CVE-2021-22042
7.8

This vulnerability in VMware ESXi allows attackers with VMX process privileges to access the settingsd service running with high privileges. This coul...

Feb 16, 2022
CVE-2021-45339
7.8

This CVE describes a local privilege escalation vulnerability in Avast Antivirus where an attacker with local access can bypass Avast's self-defense m...

Dec 27, 2021
CVE-2021-0649
7.8

This vulnerability allows local attackers to bypass permissions and reset VPN profiles on Android devices, potentially gaining control over always-on ...

Dec 15, 2021
CVE-2021-26273
7.8

CVE-2021-26273 is an incorrect access control vulnerability in NinjaRMM Agent 5.0.909 that allows local privilege escalation. Attackers can exploit th...

Jul 7, 2021
CVE-2010-2525
7.8

CVE-2010-2525 is a privilege escalation vulnerability in the GFS2 file system's ACL handling. An unprivileged local attacker can exploit this flaw to ...

Jun 22, 2021
CVE-2021-31165
7.8

This vulnerability allows an authenticated attacker to escalate privileges on Windows systems by exploiting a flaw in the Container Manager Service. A...

May 11, 2021
CVE-2021-27086
7.8

CVE-2021-27086 is an elevation of privilege vulnerability in the Windows Service Control Manager (SCM) that allows authenticated attackers to bypass r...

Apr 13, 2021
CVE-2021-28791
7.8

This vulnerability in the unofficial SwiftFormat extension for Visual Studio Code allows remote attackers to execute arbitrary code by tricking users ...

Mar 18, 2021
CVE-2021-26025
7.8

CVE-2021-26025 is a memory corruption vulnerability in ACDSee Professional 2021's image processing component. When processing a specially crafted BMP ...

Jan 26, 2021
CVE-2025-11340
7.7

This vulnerability in GitLab EE allows authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records...

Oct 9, 2025

About Incorrect Authorization (CWE-863)

The product performs an authorization check when an actor attempts to access a resource, but it does not correctly perform the check.

Our database tracks 710 CVEs classified as CWE-863, with 138 rated critical and 315 rated high severity. The average CVSS score for Incorrect Authorization vulnerabilities is 7.3.

External reference: View CWE-863 on MITRE CWE →

Monitor Incorrect Authorization Vulnerabilities

Get alerted when new Incorrect Authorization CVEs affect your infrastructure.

Start Monitoring Free