CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,112 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 27 of 83
- CVE-2021-42288MEDIUMCVSS 5.7EG 6.12021-11-10
Windows Hello Security Feature Bypass Vulnerability
- CVE-2021-42292CRITICALCVSS 7.8EG 9.0⚠ KEV2021-11-10
Microsoft Excel Security Feature Bypass Vulnerability
- CVE-2021-42299MEDIUMCVSS 5.6EG 5.62021-10-20
Microsoft Surface Pro 3 Security Feature Bypass Vulnerability
- CVE-2021-42671HIGHCVSS 7.5EG 7.52021-11-05
An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access controls and access all t…
- CVE-2021-4268HIGHCVSS 4.3EG 8.82022-12-21
A vulnerability, which was classified as problematic, was found in phpRedisAdmin up to 1.17.3. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to…
- CVE-2021-42725HIGHCVSS 7.8EG 7.82021-11-16
Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interac…
- CVE-2021-4275HIGHCVSS 4.3EG 8.82022-12-21
A vulnerability, which was classified as problematic, was found in katlings pyambic-pentameter. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The name o…
- CVE-2021-42758HIGHCVSS 8.8EG 8.82021-12-08
An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to execute any command as an admin user with full access rights via bypassing the GUI restric…
- CVE-2021-42837CRITICALCVSS 9.8EG 9.82021-11-05
An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the native login page. Any valid user from the SAML/OAuth provider can be used as the username wit…
- CVE-2021-42855HIGHCVSS 7.8EG 7.82022-03-10
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file to store a json string that contains a list of IDs and pre-configured commands. The config file is subsequently used by…
- CVE-2021-42954HIGHCVSS 7.8EG 7.82021-11-17
Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is vulnerable to weak file permissions by allowing full control for Windows Everyone user grou…
- CVE-2021-42955HIGHCVSS 7.3EG 7.82021-11-17
Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user can reset the passwo…
- CVE-2021-43051HIGHCVSS 7.1EG 7.12021-12-14
The Spotfire Server component of TIBCO Software Inc.'s TIBCO Spotfire Server, TIBCO Spotfire Server, and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows malicious custom API clients with network access to ex…
- CVE-2021-43145HIGHCVSS 8.1EG 8.12022-02-04
With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.
- CVE-2021-43337MEDIUMCVSS 6.5EG 6.52021-11-17
SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access control rules in SlurmDBD may permit users to request job scripts and environment …
- CVE-2021-4334HIGHCVSS 8.8EG 8.82023-10-20
The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpd_update_options function in versions up to, and including, 4.6.9. This makes it possible…
- CVE-2021-43411HIGHCVSS 7.5EG 7.52021-11-07
An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already has the new privileges, but still refers to the old task and is accessible through the ol…
- CVE-2021-43414HIGHCVSS 7.0EG 7.02021-11-07
An issue was discovered in GNU Hurd before 0.9 20210404-9. The use of an authentication protocol in the proc server is vulnerable to man-in-the-middle attacks, which can be exploited for local privilege escalation to get full root access.
- CVE-2021-4352MEDIUMCVSS 5.3EG 5.32023-06-07
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated at…
- CVE-2021-43553LOWCVSS 3.1EG 3.12021-11-17
PI Vision could disclose information to a user with insufficient privileges for an AF attribute that is the child of another attribute and is configured as a Limits property.
- CVE-2021-43560MEDIUMCVSS 5.3EG 5.32021-11-22
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
- CVE-2021-43703CRITICALCVSS 9.8EG 9.82021-12-09
An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console.
- CVE-2021-43771HIGHCVSS 7.8EG 7.82021-11-30
Trend Micro Antivirus for Mac 2021 v11 (Consumer) is vulnerable to an improper access control privilege escalation vulnerability that could allow an attacker to establish a connection that could lead to full local privilege escalation with…
- CVE-2021-43781MEDIUMCVSS 6.4EG 6.42021-12-06
Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is publi…
- CVE-2021-43858HIGHCVSS 8.8EG 8.82021-12-27
MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTTP API call that allows for updating policy for a user and gaining higher privileges. The p…
- CVE-2021-43948MEDIUMCVSS 4.3EG 4.32022-02-15
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected…
- CVE-2021-43974MEDIUMCVSS 5.3EG 5.32022-01-11
An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, but does not respect the server-side setting that determines if anonymous users are allowed to register new accounts. C…
- CVE-2021-44204HIGHCVSS 7.8EG 7.82022-02-04
Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147, Acronis Cyber Protect …
- CVE-2021-44465MEDIUMCVSS 4.3EG 5.32023-04-25
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the system, v…
- CVE-2021-44586HIGHCVSS 7.5EG 7.52022-01-10
An issue was discovered in dst-admin v1.3.0. The product has an unauthorized arbitrary file download vulnerability that can expose sensitive information.
- CVE-2021-44595HIGHCVSS 8.8EG 8.82022-04-29
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to the ElevationService.exe and execute arbitrary code without any validation with SYSTEM privi…
- CVE-2021-44836MEDIUMCVSS 4.3EG 4.32022-01-18
An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it is possible for an unprivileged user to reopen a risk with a POST request, using the risqueID parameter to identify the …
- CVE-2021-44877HIGHCVSS 7.5EG 7.52021-12-21
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Incorrect Access Control. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web applicat…
- CVE-2021-45074MEDIUMCVSS 4.3EG 5.42022-03-02
JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.
- CVE-2021-45089MEDIUMCVSS 5.2EG 5.22021-12-21
Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control.
- CVE-2021-45091MEDIUMCVSS 4.3EG 4.32021-12-21
Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control.
- CVE-2021-45102HIGHCVSS 8.8EG 8.82021-12-16
An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon using a SciToken, a user may be granted authorizations beyond what the token should allow.
- CVE-2021-45310MEDIUMCVSS 5.3EG 5.32022-02-14
Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to an improper access restriction. Users information such as first name, last name, acount id, server uuid, email address,…
- CVE-2021-45339HIGHCVSS 7.8EG 7.82021-12-27
Privilege escalation vulnerability in Avast Antivirus prior to 20.4 allows a local user to gain elevated privileges by "hollowing" trusted process which could lead to the bypassing of Avast self-defense.
- CVE-2021-45379HIGHCVSS 8.8EG 8.82021-12-30
Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in as another user without its password.
- CVE-2021-45457HIGHCVSS 7.5EG 7.52022-01-06
In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0…
- CVE-2021-45466CRITICALCVSS 9.8EG 9.82022-12-26
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder.
- CVE-2021-45730MEDIUMCVSS 6.0EG 6.02022-05-19
JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrat…
- CVE-2021-46371HIGHCVSS 7.5EG 7.52022-02-14
antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information.
- CVE-2021-46418HIGHCVSS 7.5EG 7.52022-04-07
An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.
- CVE-2021-46419CRITICALCVSS 9.1EG 9.12022-04-07
An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.
- CVE-2021-46561HIGHCVSS 7.2EG 7.22022-01-26
controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational administrator to transfer a user account to an arbitrary new organization, and thereby achie…
- CVE-2021-46785MEDIUMCVSS 5.3EG 5.32022-05-13
The Property module has a vulnerability in permission control.This vulnerability can be exploited to obtain the unique device identifier.
- CVE-2021-46890CRITICALCVSS 9.8EG 9.82023-07-05
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
- CVE-2021-46891CRITICALCVSS 9.8EG 9.82023-07-05
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →