CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,107 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 12 of 83
- CVE-2020-26121HIGHCVSS 7.5EG 7.52020-09-27
An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protected against "page creation" and the attacker should not be able to create it. This occurs b…
- CVE-2020-26200MEDIUMCVSS 6.8EG 6.82021-02-26
A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agen…
- CVE-2020-26223HIGHCVSS 7.7EG 7.72020-11-13
Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. The perpetrator could query the API v2 O…
- CVE-2020-26250MEDIUMCVSS 6.3EG 6.32020-12-01
OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the deprecated (in jupyterhub 1.2) configuration `Authenticator.whitelist`, which should be transparently mapped to `Authen…
- CVE-2020-26506MEDIUMCVSS 4.3EG 4.32020-11-05
An Authorization Bypass vulnerability in the Marmind web application with version 4.1.141.0 allows users with lower privileges to gain control to files uploaded by administrative users. The accessed files were not visible by the low privil…
- CVE-2020-26555MEDIUMCVSS 5.4EG 5.42021-05-24
Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.
- CVE-2020-26557HIGHCVSS 7.5EG 7.52021-05-24
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute-force attack (unless the AuthValue is s…
- CVE-2020-26559HIGHCVSS 8.8EG 8.82021-05-24
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s public key, and the confirmation numbe…
- CVE-2020-26560HIGHCVSS 8.1EG 8.12021-05-24
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Provisioner, to complete authentication without possessing the AuthValue, and potentially acq…
- CVE-2020-26876HIGHCVSS 7.5EG 7.52020-10-07
The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for course videos and materials) by using the /wp-json REST API, as exploited in the wild in September 2020. This occurs becaus…
- CVE-2020-27156CRITICALCVSS 9.8EG 9.82020-10-15
Veritas APTARE versions prior to 10.5 did not perform adequate authorization checks. This vulnerability could allow for remote code execution by an unauthenticated user.
- CVE-2020-27362HIGHCVSS 8.8EG 8.82021-07-01
An issue exists within the SSH console of Akkadian Provisioning Manager 4.50.02 which allows a low-level privileged user to escape the web configuration file editor and escalate privileges.
- CVE-2020-27609MEDIUMCVSS 5.3EG 5.32020-10-21
BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. This may result in data storage beyond what is authorized for a specific meeting topic or participant.
- CVE-2020-27873MEDIUMCVSS 6.5EG 6.52021-02-04
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exist…
- CVE-2020-27901MEDIUMCVSS 6.3EG 6.32021-04-02
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. A sandboxed process may be able to circumvent sand…
- CVE-2020-28050CRITICALCVSS 9.1EG 9.12021-03-05
Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server.
- CVE-2020-28053MEDIUMCVSS 6.5EG 6.52020-11-23
HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key configuration. Fixed in 1.6.10, 1.7.10, and 1.8.6.
- CVE-2020-28211HIGHCVSS 7.8EG 7.82020-11-19
A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause bypass of authentication when overwriting memory using a debugger.
- CVE-2020-28397MEDIUMCVSS 5.3EG 5.32021-08-10
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7 PLCSIM Advanced (All versions > V2 <…
- CVE-2020-28401MEDIUMCVSS 6.5EG 6.52021-01-29
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access WIP details about jobs he should not have access to.
- CVE-2020-28402HIGHCVSS 5.4EG 8.82021-01-29
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access Launcher Configuration Panel.
- CVE-2020-28404MEDIUMCVSS 6.5EG 6.52021-01-29
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access the Billing page without the appropriate privileges.
- CVE-2020-28405HIGHCVSS 8.8EG 8.82021-01-29
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to change the privileges of any user of the application. This can be used to grant himself the administrative …
- CVE-2020-28406MEDIUMCVSS 6.5EG 6.52021-01-29
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access details about jobs he should not have access to via the Audit Trail Feature.
- CVE-2020-28872CRITICALCVSS 9.8EG 9.82021-04-12
An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows an unauthorized person to create valid credentials.
- CVE-2020-29020CRITICALCVSS 9.1EG 9.12021-03-05
Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All versions prior to 9.4.6…
- CVE-2020-29158MEDIUMCVSS 4.3EG 4.32020-12-28
An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access control on internal Articles via the Ticket detail view.
- CVE-2020-29160HIGHCVSS 7.5EG 7.52020-12-28
An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.
- CVE-2020-29165CRITICALCVSS 9.8EG 9.82021-02-03
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotely gaining administrator privileges.
- CVE-2020-29189HIGHCVSS 8.1EG 8.12020-12-24
Incorrect Access Control vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated attackers to bypass read-only restriction and obtain full access to any folder within the NAS
- CVE-2020-29374LOWCVSS 3.6EG 3.62020-11-28
An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operation…
- CVE-2020-29454MEDIUMCVSS 4.3EG 4.32020-12-02
Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Applications.Settings access.
- CVE-2020-29538MEDIUMCVSS 4.9EG 4.92021-01-29
Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malicious administrative user can potentially exploit this vulnerability to gather information about the system, and may use…
- CVE-2020-29605MEDIUMCVSS 4.3EG 4.32021-01-29
An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary fields of private Issues via bug_arr[]= in a crafted bug_actiongr…
- CVE-2020-3140CRITICALCVSS 9.8EG 9.82020-07-16
A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient valid…
- CVE-2020-3150MEDIUMCVSS 5.9EG 5.92020-07-16
A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could allow an unauthenticated, remote attacker to download sensitive information from the device, which could include the devic…
- CVE-2020-3227CRITICALCVSS 9.8EG 9.82020-06-03
A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute Cisco IOx API commands without proper authorization. The…
- CVE-2020-3229HIGHCVSS 8.8EG 8.82020-06-03
A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remote attacker to execute commands or configuration changes as an Admin user. The vulnerabili…
- CVE-2020-3231MEDIUMCVSS 4.7EG 4.72020-06-03
A vulnerability in the 802.1X feature of Cisco Catalyst 2960-L Series Switches and Cisco Catalyst CDB-8P Switches could allow an unauthenticated, adjacent attacker to forward broadcast traffic before being authenticated on the port. The vu…
- CVE-2020-3335MEDIUMCVSS 5.5EG 5.52020-06-03
A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive information of other users on an affected device. The vulnerability is due to insufficient author…
- CVE-2020-3360MEDIUMCVSS 5.3EG 5.32020-06-18
A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sensitive information on an affected device. The vulnerability is due to improper access contr…
- CVE-2020-3364MEDIUMCVSS 5.3EG 5.32020-06-18
A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the standby…
- CVE-2020-3374CRITICALCVSS 9.9EG 9.92020-07-31
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization, enabling them to access sensitive information, modify the system configuration, o…
- CVE-2020-3386HIGHCVSS 8.8EG 8.82020-07-31
A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privileged account to bypass authorization on the API of an affected device. The vulnerability is…
- CVE-2020-3404HIGHCVSS 7.8EG 7.82020-09-24
A vulnerability in the persistent Telnet/Secure Shell (SSH) CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS) w…
- CVE-2020-3412MEDIUMCVSS 4.3EG 4.32020-08-17
A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to create a scheduled meeting template that would belong to another user in their organization. The vulnerabili…
- CVE-2020-3413MEDIUMCVSS 4.3EG 4.32020-08-17
A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to delete a scheduled meeting template that belongs to another user in their organization. The vulnerability is…
- CVE-2020-3467HIGHCVSS 7.7EG 7.72020-10-08
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. The vulnerability is due to improper en…
- CVE-2020-3472MEDIUMCVSS 5.0EG 5.02020-08-17
A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to access sensitive information. The vulnerability is due to improper access restrictions on users…
- CVE-2020-3473HIGHCVSS 7.8EG 7.82020-09-04
A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local CLI shell user to elevate privileges and gain full administrative control of the device. The vulnerability is …
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →