CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,107 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 11 of 83
- CVE-2020-2148MEDIUMCVSS 4.3EG 4.32020-03-09
A missing permission check in Jenkins Mac Plugin 1.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials.
- CVE-2020-2188MEDIUMCVSS 4.3EG 4.32020-05-06
A missing permission check in Jenkins Amazon EC2 Plugin 1.50.1 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
- CVE-2020-21990HIGHCVSS 7.5EG 7.52021-04-29
Emmanuel MyDomoAtHome (MDAH) REST API REST API Domoticz ISS Gateway 0.2.40 is affected by an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote attacker can exploit this, via a specia…
- CVE-2020-2228HIGHCVSS 8.8EG 8.82020-07-15
Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnerability.
- CVE-2020-2233MEDIUMCVSS 6.5EG 6.52020-08-12
A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
- CVE-2020-2258MEDIUMCVSS 4.3EG 4.32020-09-16
Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view that HTTP endpoint.
- CVE-2020-22784HIGHCVSS 7.5EG 7.52021-04-28
In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names.
- CVE-2020-23362HIGHCVSS 7.1EG 7.12023-05-09
Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id parameter.
- CVE-2020-23449HIGHCVSS 7.5EG 7.52021-01-26
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information through the userID.
- CVE-2020-24264CRITICALCVSS 9.8EG 9.82021-03-16
Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bind mounts are applied only on the client-side and not the server-side, which can lead to sp…
- CVE-2020-24401MEDIUMCVSS 6.5EG 6.52020-11-09
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisioned under their old role after an administrator removes the role or disables the user's ac…
- CVE-2020-24492MEDIUMCVSS 4.4EG 4.42021-02-17
Insufficient access control in the firmware for the Intel(R) 722 Ethernet Controllers before version 1.5 may allow a privileged user to potentially enable a denial of service via local access.
- CVE-2020-24493MEDIUMCVSS 4.4EG 4.42021-02-17
Insufficient access control in the firmware for the Intel(R) 700-series of Ethernet Controllers before version 8.0 may allow a privileged user to potentially enable denial of service via local access.
- CVE-2020-24494MEDIUMCVSS 4.4EG 4.42021-02-17
Insufficient access control in the firmware for the Intel(R) 722 Ethernet Controllers before version 1.4.3 may allow a privileged user to potentially enable denial of service via local access.
- CVE-2020-24495MEDIUMCVSS 4.4EG 4.42021-02-17
Insufficient access control in the firmware for the Intel(R) 700-series of Ethernet Controllers before version 7.3 may allow a privileged user to potentially enable denial of service via local access.
- CVE-2020-24497MEDIUMCVSS 4.4EG 4.42021-02-17
Insufficient Access Control in the firmware for Intel(R) E810 Ethernet Controllers before version 1.4.1.13 may allow a privileged user to potentially enable denial of service via local access.
- CVE-2020-24503MEDIUMCVSS 5.5EG 5.52021-02-17
Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2020-24595MEDIUMCVSS 5.3EG 5.32020-09-25
Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to retrieve sensitive information due to insufficient access control.
- CVE-2020-24618MEDIUMCVSS 6.5EG 6.52020-08-27
In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.
- CVE-2020-24674HIGHCVSS 8.8EG 8.82020-12-22
In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more priv…
- CVE-2020-24716HIGHCVSS 7.8EG 7.82020-08-27
OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories.
- CVE-2020-24718HIGHCVSS 8.2EG 8.22020-09-25
bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on …
- CVE-2020-24771HIGHCVSS 7.5EG 7.52022-03-30
Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.
- CVE-2020-24941HIGHCVSS 7.5EG 7.52020-09-04
An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting expressions.
- CVE-2020-24981MEDIUMCVSS 5.3EG 5.32020-09-04
An Incorrect Access Control vulnerability exists in /ucms/chk.php in UCMS 1.4.8. This results in information leak via an error message caused by directly accessing the website built by UCMS.
- CVE-2020-25025MEDIUMCVSS 4.3EG 4.32020-09-02
The l10nmgr (aka Localization Manager) extension before 7.4.0, 8.x before 8.7.0, and 9.x before 9.2.0 for TYPO3 allows Information Disclosure (translatable fields).
- CVE-2020-25049CRITICALCVSS 9.8EG 9.82020-08-31
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. StatusBarService has insufficient DEX access control. The Samsung ID is SVE-2020-17797 (August 2020).
- CVE-2020-25055CRITICALCVSS 9.8EG 9.82020-08-31
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows attackers (who control an unprivileged SecureFolder process) to bypass admin restrictions in KnoxContainer. The Samsung…
- CVE-2020-2506CRITICALCVSS 7.3EG 9.8⚠ KEV2021-02-03
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive i…
- CVE-2020-2507CRITICALCVSS 9.8EG 9.82021-02-03
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Helpdesk versions prio…
- CVE-2020-25160MEDIUMCVSS 6.8EG 6.82022-04-14
Improper access controls in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 enables attackers to extract and tamper with the devices network configuration.
- CVE-2020-25167MEDIUMCVSS 4.9EG 6.52022-04-18
OSIsoft PI Vision 2020 versions prior to 3.5.0 could disclose information to a user with insufficient privileges for an AF attribute.
- CVE-2020-25239HIGHCVSS 8.8EG 8.82021-03-15
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization server could be chang…
- CVE-2020-25240HIGHCVSS 8.8EG 8.82021-03-15
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can access services when guessing the url. An attacker could impact availability, integrity and gain information from logs and t…
- CVE-2020-25251CRITICALCVSS 9.1EG 9.12020-09-11
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Client-side authentication is used for critical functions such as adding users or r…
- CVE-2020-25282CRITICALCVSS 9.8EG 9.82020-09-11
An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows attackers to bypass intended access restrictions on property values. The LG ID is LVE-SMP-2…
- CVE-2020-25283CRITICALCVSS 9.8EG 9.82020-09-11
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. BT manager allows attackers to bypass intended access restrictions on a certain mode. The LG ID is LVE-SMP-200021 (September 2020).
- CVE-2020-25284MEDIUMCVSS 4.1EG 4.12020-09-13
The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block devices, aka CID-f44d…
- CVE-2020-25564HIGHCVSS 8.8EG 8.82021-08-11
In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user by directly accessing RemoteMgmtTaskSave (Automation Tasks) feature.
- CVE-2020-25580MEDIUMCVSS 5.3EG 5.32021-03-26
In FreeBSD 12.2-STABLE before r369346, 11.4-STABLE before r369345, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 a regression in the login.access(5) rule processor has the effect of causing rules to fail to match even when they should …
- CVE-2020-25610MEDIUMCVSS 5.3EG 5.32020-12-18
The AWV component of Mitel MiCollab before 9.2 could allow an attacker to gain access to a web conference due to insufficient access control for conference codes.
- CVE-2020-25612MEDIUMCVSS 4.9EG 4.92020-12-18
The NuPoint Messenger of Mitel MiCollab before 9.2 could allow an attacker with escalated privilege to access user files due to insufficient access control. Successful exploit could potentially allow an attacker to gain access to sensitive…
- CVE-2020-25655MEDIUMCVSS 5.7EG 5.72020-11-09
An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permissi…
- CVE-2020-25699HIGHCVSS 7.5EG 7.52020-11-19
In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and ear…
- CVE-2020-25701MEDIUMCVSS 5.3EG 5.32020-11-19
If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the…
- CVE-2020-25722HIGHCVSS 8.8EG 8.82022-02-18
Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause total domain compromise.
- CVE-2020-25869HIGHCVSS 7.5EG 7.52020-09-27
An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of actor ID does not necessarily use the correct database or correct wiki.
- CVE-2020-26028MEDIUMCVSS 4.9EG 4.92020-12-28
An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets.
- CVE-2020-26029MEDIUMCVSS 6.5EG 6.52020-12-28
An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization checks are performed for the actual user and not the one given in the X-On-Behalf-Of head…
- CVE-2020-26102HIGHCVSS 7.5EG 7.52020-09-25
In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →