CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,110 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 24 of 83
- CVE-2021-36167MEDIUMCVSS 4.3EG 5.32021-12-09
An improper authorization vulnerabiltiy [CWE-285] in FortiClient Windows versions 7.0.0 and 6.4.6 and below and 6.2.8 and below may allow an unauthenticated attacker to bypass the webfilter control via modifying the session-id paramater.
- CVE-2021-36169MEDIUMCVSS 4.2EG 6.02021-12-13
A Hidden Functionality in Fortinet FortiOS 7.x before 7.0.1, FortiOS 6.4.x before 6.4.7 allows attacker to Execute unauthorized code or commands via specific hex read/write operations.
- CVE-2021-36177MEDIUMCVSS 4.2EG 4.32022-02-02
An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to …
- CVE-2021-36183HIGHCVSS 7.4EG 7.82021-11-02
An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for For…
- CVE-2021-36225HIGHCVSS 8.8EG 8.82023-02-06
Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation.
- CVE-2021-36230HIGHCVSS 8.8EG 8.82021-07-20
HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.
- CVE-2021-36232HIGHCVSS 8.8EG 8.82021-08-31
Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.
- CVE-2021-36305MEDIUMCVSS 6.5EG 6.52021-11-12
Dell PowerScale OneFS contains an Unsynchronized Access to Shared Data in a Multithreaded Context in SMB CA handling. An authenticated user of SMB on a cluster with CA could potentially exploit this vulnerability, leading to a denial of se…
- CVE-2021-36311HIGHCVSS 6.0EG 7.82021-11-23
Dell EMC Networker versions prior to 19.5 contain an Improper Authorization vulnerability. Any local malicious user with networker user privileges may exploit this vulnerability to upload malicious file to unauthorized locations and execut…
- CVE-2021-36383MEDIUMCVSS 4.3EG 4.32021-07-12
Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by modified WebSocket resourceSet.getAll data is which the attacker changes the permission field from none to admin. The atta…
- CVE-2021-3658MEDIUMCVSS 6.5EG 6.52022-03-02
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could…
- CVE-2021-36749HIGHCVSS 6.5EG 8.82021-09-24
In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with…
- CVE-2021-36758MEDIUMCVSS 5.4EG 5.42021-07-16
1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to perform privilege escalation. Malicious users authorized to create Secrets Automation access …
- CVE-2021-36778HIGHCVSS 7.3EG 7.32022-05-02
A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects: SUSE Rancher Rancher versions prior to 2.5.12; Rancher vers…
- CVE-2021-36909HIGHCVSS 8.8EG 8.82021-11-18
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and ta…
- CVE-2021-37038HIGHCVSS 7.5EG 7.52021-12-07
There is an Improper access control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-3705CRITICALCVSS 9.8EG 9.82021-11-01
Potential security vulnerabilities have been discovered on a certain HP LaserJet Pro printer that may allow an unauthorized user to reconfigure, reset the device.
- CVE-2021-37101MEDIUMCVSS 6.8EG 6.82021-09-09
There is an improper authorization vulnerability in AIS-BW50-00 9.0.6.2(H100SP10C00) and 9.0.6.2(H100SP15C00). Due to improper authorization mangement, an attakcer can exploit this vulnerability by physical accessing the device and implant…
- CVE-2021-37109HIGHCVSS 7.8EG 7.82022-02-09
There is a security protection bypass vulnerability with the modem.Successful exploitation of this vulnerability may cause memory protection failure.
- CVE-2021-37115MEDIUMCVSS 5.5EG 5.52022-02-09
There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-37234MEDIUMCVSS 6.5EG 6.52023-02-03
Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows remote attackers to view sensitive information via crafted PUT request to Web API.
- CVE-2021-37292HIGHCVSS 7.2EG 7.22022-04-11
An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor account. A malicious user can log in using the backdor account with admin highest privileges and obtain…
- CVE-2021-37409HIGHCVSS 7.8EG 7.82022-08-18
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2021-37421CRITICALCVSS 9.8EG 9.82021-08-30
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.
- CVE-2021-37517HIGHCVSS 7.5EG 7.52022-03-31
An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.
- CVE-2021-37598MEDIUMCVSS 5.3EG 5.32021-08-19
WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
- CVE-2021-37604HIGHCVSS 7.5EG 7.52021-08-05
In version 6.5 of Microchip MiWi software and all previous versions including legacy products, there is a possibility of frame counters being validated/updated prior to the message authentication. With this vulnerability in place, an attac…
- CVE-2021-37605HIGHCVSS 7.5EG 7.52021-08-05
In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only two out of four Message Integrity Check (MIC) bytes.
- CVE-2021-3763MEDIUMCVSS 4.3EG 4.32022-08-23
A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access some limited information even when the role the user is assigned to should not be allow access to the management console.…
- CVE-2021-37705CRITICALCVSS 10.0EG 10.02021-08-13
OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allows an authenticated user from any Azure Active Directory tenant to make authorized API call…
- CVE-2021-37791MEDIUMCVSS 4.9EG 4.92022-06-30
MyAdmin v1.0 is affected by an incorrect access control vulnerability in viewing personal center in /api/user/userData?userCode=admin.
- CVE-2021-37841HIGHCVSS 7.8EG 7.82021-08-12
Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows containers, it can lead to a full container compromise in both process isolation and Hyper-V is…
- CVE-2021-37852HIGHCVSS 7.8EG 7.82022-02-09
ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.
- CVE-2021-37864MEDIUMCVSS 2.6EG 6.52022-01-18
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly acc…
- CVE-2021-3788MEDIUMCVSS 6.8EG 6.82021-11-12
An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device.
- CVE-2021-3793MEDIUMCVSS 6.5EG 6.52021-11-12
An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in info…
- CVE-2021-38016HIGHCVSS 8.8EG 8.82021-12-23
Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
- CVE-2021-38017HIGHCVSS 8.8EG 8.82021-12-23
Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- CVE-2021-38019MEDIUMCVSS 6.5EG 6.52021-12-23
Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2021-38020MEDIUMCVSS 4.3EG 4.32021-12-23
Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2021-38137HIGHCVSS 8.1EG 8.12021-08-06
Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor user’s privileges, allowing a user to perform actions not belonging to his role.
- CVE-2021-38178HIGHCVSS 8.8EG 8.82021-10-12
The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, enables a malicious user to transfer ABAP code artifacts or content, by-passing the e…
- CVE-2021-38312HIGHCVSS 7.1EG 7.12021-09-02
The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templates/” REST Route in “redux-templates/classes/class-a…
- CVE-2021-3833CRITICALCVSS 9.8EG 9.82021-10-07
Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database. An attacker with a specific formatted password could exploit this vulnerability i…
- CVE-2021-38345HIGHCVSS 7.1EG 7.12021-10-14
The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in the wp-admin directory to modify the content of any existing post or page created with th…
- CVE-2021-38362MEDIUMCVSS 6.5EG 6.52022-03-30
In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data.
- CVE-2021-38384CRITICALCVSS 9.8EG 9.82021-08-10
Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implement incorrect access control, because the actual behavior within the Amazon AWS environment is a 20…
- CVE-2021-38454CRITICALCVSS 10.0EG 10.02021-10-12
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
- CVE-2021-38503CRITICALCVSS 10.0EG 10.02021-12-08
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, an…
- CVE-2021-38516CRITICALCVSS 10.0EG 10.02021-08-11
Certain NETGEAR devices are affected by lack of access control at the function level. This affects D6220 before 1.0.0.48, D6400 before 1.0.0.82, D7000v2 before 1.0.0.52, D7800 before 1.0.1.44, D8500 before 1.0.3.43, DC112A before 1.0.0.40,…
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →