CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,112 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 28 of 83
- CVE-2022-0027MEDIUMCVSS 4.3EG 4.32022-05-11
An improper authorization vulnerability in Palo Alto Network Cortex XSOAR software enables authenticated users in non-Read-Only groups to generate an email report that contains summary information about all incidents in the Cortex XSOAR in…
- CVE-2022-0117MEDIUMCVSS 6.5EG 6.52022-02-12
Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2022-0143CRITICALCVSS 9.3EG 9.82022-09-19
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remo…
- CVE-2022-0164MEDIUMCVSS 4.3EG 4.32022-02-21
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary e…
- CVE-2022-0172MEDIUMCVSS 5.3EG 6.52022-01-18
An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was possible to bypass the IP restriction for public projects through GraphQL allowing unauthorised users to read titles of…
- CVE-2022-0273MEDIUMCVSS 6.5EG 6.52022-01-30
Improper Access Control in Pypi calibreweb prior to 0.6.16.
- CVE-2022-0305MEDIUMCVSS 6.5EG 6.52022-02-12
Inappropriate implementation in Service Worker API in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
- CVE-2022-0309MEDIUMCVSS 6.5EG 6.52022-02-12
Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- CVE-2022-0333LOWCVSS 3.8EG 3.82022-01-25
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been rest…
- CVE-2022-0334MEDIUMCVSS 4.3EG 4.32022-01-25
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the …
- CVE-2022-0373MEDIUMCVSS 4.3EG 4.32022-04-01
Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address
- CVE-2022-0390MEDIUMCVSS 4.3EG 4.32022-04-01
Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.
- CVE-2022-0404MEDIUMCVSS 6.5EG 6.52022-04-04
The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param belongs to the plugin when processing requests to the cf7md_dismiss_notice action, allowing…
- CVE-2022-0406MEDIUMCVSS 4.3EG 4.32022-04-03
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
- CVE-2022-0442MEDIUMCVSS 4.3EG 4.32022-03-07
The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.
- CVE-2022-0451MEDIUMCVSS 6.5EG 6.52022-02-18
Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirectio…
- CVE-2022-0482CRITICALCVSS 9.1EG 9.12022-03-09
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
- CVE-2022-0574MEDIUMCVSS 6.5EG 6.52022-05-16
Improper Access Control in GitHub repository publify/publify prior to 9.2.8.
- CVE-2022-0577MEDIUMCVSS 6.5EG 6.52022-03-02
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.
- CVE-2022-0580HIGHCVSS 7.1EG 7.12022-02-14
Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0.
- CVE-2022-0594MEDIUMCVSS 5.3EG 5.32022-07-25
The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, all…
- CVE-2022-0633MEDIUMCVSS 6.5EG 6.52022-02-17
The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as…
- CVE-2022-0670CRITICALCVSS 9.1EG 9.12022-07-25
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows …
- CVE-2022-0720MEDIUMCVSS 5.4EG 5.42022-03-28
The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name a…
- CVE-2022-0726MEDIUMCVSS 5.4EG 5.42022-02-23
Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.
- CVE-2022-0727MEDIUMCVSS 5.4EG 5.42022-02-23
Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.
- CVE-2022-0732HIGHCVSS 7.5EG 7.52022-02-24
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.
- CVE-2022-0735CRITICALCVSS 10.0EG 10.02022-03-28
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal run…
- CVE-2022-0740MEDIUMCVSS 3.1EG 4.32022-04-04
Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before …
- CVE-2022-0756MEDIUMCVSS 6.5EG 6.52022-03-07
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
- CVE-2022-0762MEDIUMCVSS 5.5EG 5.52022-02-26
Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3.
- CVE-2022-0775MEDIUMCVSS 4.3EG 4.32024-01-16
The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment
- CVE-2022-0821MEDIUMCVSS 6.5EG 6.52022-03-11
Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.
- CVE-2022-0824CRITICALCVSS 8.8EG 9.02022-03-02
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.
- CVE-2022-0825MEDIUMCVSS 5.4EG 5.42022-04-04
The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full…
- CVE-2022-0829HIGHCVSS 8.1EG 8.12022-03-02
Improper Authorization in GitHub repository webmin/webmin prior to 1.990.
- CVE-2022-0837MEDIUMCVSS 5.4EG 5.42022-04-04
The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the …
- CVE-2022-0860CRITICALCVSS 9.1EG 9.12022-03-11
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
- CVE-2022-0866MEDIUMCVSS 5.3EG 5.32022-05-10
This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a RunAs principal. In particular, the org.jboss.as.ejb3.component.EJBComponent class has an…
- CVE-2022-0920HIGHCVSS 7.5EG 7.52022-04-11
The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data
- CVE-2022-0981HIGHCVSS 8.8EG 8.82022-03-23
A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set …
- CVE-2022-0984MEDIUMCVSS 4.3EG 4.32022-04-29
Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.
- CVE-2022-0985MEDIUMCVSS 4.3EG 4.32022-04-29
Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.
- CVE-2022-1105MEDIUMCVSS 4.3EG 4.32022-04-04
An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an unauthorized user to access pipeline analytics even when public pipelines …
- CVE-2022-1124MEDIUMCVSS 4.3EG 4.32022-05-11
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled
- CVE-2022-1132MEDIUMCVSS 6.1EG 6.12022-07-23
Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS prior to 100.0.4896.60 allowed a local attacker to bypass navigation restrictions via physical access to the device.
- CVE-2022-1177MEDIUMCVSS 4.3EG 4.32022-03-30
Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.
- CVE-2022-1193MEDIUMCVSS 4.3EG 4.32022-04-11
Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain cir…
- CVE-2022-1223MEDIUMCVSS 6.5EG 6.52022-04-04
Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
- CVE-2022-1224MEDIUMCVSS 6.5EG 6.52022-04-04
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →