CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,108 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 19 of 83
- CVE-2021-24993MEDIUMCVSS 6.5EG 6.52022-02-07
The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change …
- CVE-2021-25097MEDIUMCVSS 6.5EG 6.52022-02-01
The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authenticated users, such as subscriber to delete arbitrary publication
- CVE-2021-25228MEDIUMCVSS 5.3EG 5.32021-02-04
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about hotfix history.
- CVE-2021-25229MEDIUMCVSS 5.3EG 5.32021-02-04
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the database server.
- CVE-2021-25244MEDIUMCVSS 5.3EG 5.32021-02-04
An improper access control vulnerability in Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain various pieces of configuration informaiton.
- CVE-2021-25245MEDIUMCVSS 5.3EG 5.32021-02-04
An improper access control vulnerability in Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain various pieces of settings informaiton.
- CVE-2021-25246MEDIUMCVSS 6.5EG 6.52021-02-04
An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus agent on an affected …
- CVE-2021-25336LOWCVSS 2.8EG 3.32021-03-04
Improper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to acquire notification access via sending a crafted malicious intent.
- CVE-2021-25337CRITICALCVSS 4.4EG 9.0⚠ KEV2021-03-04
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.
- CVE-2021-25338MEDIUMCVSS 4.4EG 5.22021-03-04
Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to write certain part of RKP EL2 memory region.
- CVE-2021-25340MEDIUMCVSS 5.1EG 5.12021-03-04
Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.
- CVE-2021-25349HIGHCVSS 5.5EG 7.82021-03-25
Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action without permission via hijacking the PendingIntent.
- CVE-2021-25351LOWCVSS 3.2EG 3.22021-03-25
Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.
- CVE-2021-25352HIGHCVSS 5.5EG 7.82021-03-25
Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.
- CVE-2021-25356HIGHCVSS 7.1EG 8.82021-04-09
An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary application, grant device admin permission and then delete several installed application.
- CVE-2021-25366LOWCVSS 3.2EG 3.22021-03-25
Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication.
- CVE-2021-25369CRITICALCVSS 6.2EG 9.0⚠ KEV2021-03-26
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
- CVE-2021-25373HIGHCVSS 5.5EG 7.82021-04-09
Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10.0) and 2.9.01.1 in Android R(11.0) allows local attackers to perform unauthorized action …
- CVE-2021-25374HIGHCVSS 8.6EG 8.62021-04-09
An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data relate…
- CVE-2021-25382MEDIUMCVSS 6.1EG 6.12021-04-23
An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secure Folder via debugging command.
- CVE-2021-25397MEDIUMCVSS 6.8EG 6.82021-06-11
An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.
- CVE-2021-25399HIGHCVSS 7.1EG 7.12021-06-11
Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege.
- CVE-2021-25400HIGHCVSS 7.8EG 7.82021-06-11
Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.
- CVE-2021-25401HIGHCVSS 7.8EG 7.82021-06-11
Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action.
- CVE-2021-25403LOWCVSS 3.3EG 3.32021-06-11
Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component.
- CVE-2021-25405MEDIUMCVSS 5.5EG 5.52021-06-11
An improper access control vulnerability in ScreenOffActivity in Samsung Notes prior to version 4.2.04.27 allows untrusted applications to access local files.
- CVE-2021-25406MEDIUMCVSS 6.5EG 6.52021-06-11
Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT device information.
- CVE-2021-25409LOWCVSS 2.4EG 2.42021-06-11
Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arbitrary notification via physically configuring device.
- CVE-2021-25410HIGHCVSS 7.1EG 7.12021-06-11
Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an escalated privilege.
- CVE-2021-25412HIGHCVSS 7.8EG 7.82021-06-11
An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity with system privilege via untrusted applications.
- CVE-2021-25417HIGHCVSS 7.5EG 7.52021-06-11
Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage.
- CVE-2021-25418HIGHCVSS 7.8EG 7.82021-06-11
Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activity in specific condition.
- CVE-2021-25431MEDIUMCVSS 5.5EG 5.52021-07-08
Improper access control vulnerability in Cameralyzer prior to versions 3.2.1041 in 3.2.x, 3.3.1040 in 3.3.x, and 3.4.4210 in 3.4.x allows untrusted applications to access some functions of Cameralyzer.
- CVE-2021-25433MEDIUMCVSS 5.5EG 5.52021-07-08
Improper authorization vulnerability in Tizen factory reset policy prior to Firmware update JUL-2021 Release allows untrusted applications to perform factory reset using dbus signal.
- CVE-2021-25437CRITICALCVSS 9.8EG 9.82021-07-08
Improper access control vulnerability in Tizen FOTA service prior to Firmware update JUL-2021 Release allows attackers to arbitrary code execution by replacing FOTA update file.
- CVE-2021-25438HIGHCVSS 7.8EG 7.82021-07-08
Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause local file inclusion in webview.
- CVE-2021-25439LOWCVSS 3.3EG 3.32021-07-08
Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause arbitrary webpage loading in webview.
- CVE-2021-25440HIGHCVSS 7.8EG 7.82021-07-08
Improper access control vulnerability in FactoryCameraFB prior to version 3.4.74 allows untrusted applications to access arbitrary files with an escalated privilege.
- CVE-2021-25470HIGHCVSS 7.9EG 7.92021-10-06
An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.
- CVE-2021-25472MEDIUMCVSS 4.0EG 4.02021-10-06
An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.
- CVE-2021-25476MEDIUMCVSS 4.1EG 4.42021-10-06
An information disclosure vulnerability in Widevine TA log prior to SMR Oct-2021 Release 1 allows attackers to bypass the ASLR protection mechanism in TEE.
- CVE-2021-25501MEDIUMCVSS 5.7EG 5.72021-11-05
An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.
- CVE-2021-25506MEDIUMCVSS 4.0EG 4.02021-11-05
Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.
- CVE-2021-25507MEDIUMCVSS 5.7EG 5.72021-11-05
Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure Folder without authorization.
- CVE-2021-25648CRITICALCVSS 9.8EG 9.82021-02-16
Mobile application "Testes de Codigo" 11.4 and prior allows an attacker to gain access to the administrative interface and premium features by tampering the boolean value of parameters "isAdmin" and "isPremium" located on device storage.
- CVE-2021-25652MEDIUMCVSS 4.9EG 5.52021-06-24
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow any local user to access system function…
- CVE-2021-25774MEDIUMCVSS 4.3EG 4.32021-02-03
In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.
- CVE-2021-25777MEDIUMCVSS 5.3EG 5.32021-02-03
In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.
- CVE-2021-25920MEDIUMCVSS 6.5EG 6.52021-03-22
In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads to a malicious user able to read and send sensitive messages on behalf of the victim user.
- CVE-2021-25954MEDIUMCVSS 4.3EG 4.32021-08-09
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, t…
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →