CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,114 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 32 of 83
- CVE-2022-25584HIGHCVSS 7.5EG 7.52022-04-05
Seyeon Tech Co., Ltd FlexWATCH FW3170-PS-E Network Video System 4.23-3000_GY allows attackers to access sensitive information.
- CVE-2022-25649HIGHCVSS 5.0EG 8.82022-08-05
Multiple Improper Access Control vulnerabilities in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress.
- CVE-2022-25685HIGHCVSS 7.5EG 7.52022-12-13
Denial of service in Modem module due to improper authorization while error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- CVE-2022-25899CRITICALCVSS 9.8EG 9.82022-08-18
Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before versions 2.0.2 and 2.2.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
- CVE-2022-2597HIGHCVSS 5.4EG 8.82022-09-05
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS …
- CVE-2022-26017HIGHCVSS 8.0EG 8.02022-08-18
Improper access control in the Intel(R) DSA software for before version 22.2.14 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
- CVE-2022-26143CRITICALCVSS 9.8EG 9.8⚠ KEV2022-03-10
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive …
- CVE-2022-26279CRITICALCVSS 9.8EG 9.82022-03-24
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
- CVE-2022-26479CRITICALCVSS 9.8EG 9.82022-07-17
An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authentication.
- CVE-2022-26501CRITICALCVSS 9.8EG 9.8⚠ KEV2022-03-17
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
- CVE-2022-26563HIGHCVSS 8.8EG 8.82023-07-18
An issue was discovered in Tildeslash Monit before 5.31.0, allows remote attackers to gain escilated privlidges due to improper PAM-authorization.
- CVE-2022-26572HIGHCVSS 7.5EG 7.52022-04-04
Xerox ColorQube 8580 was discovered to contain an access control issue which allows attackers to print, view the status, and obtain sensitive information.
- CVE-2022-2661CRITICALCVSS 9.9EG 9.92022-08-16
Sequi PortBloque S has an improper authorization vulnerability, which may allow a low-privileged user to perform administrative functions using specifically crafted requests.
- CVE-2022-26629CRITICALCVSS 9.1EG 9.12022-03-24
An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.
- CVE-2022-26668HIGHCVSS 7.3EG 7.32022-06-20
ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform partial system operations or cause partial disrupt of service.
- CVE-2022-26676CRITICALCVSS 9.8EG 9.82022-04-07
aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scripts to control the system or disrupt service.
- CVE-2022-26767MEDIUMCVSS 5.5EG 5.52022-05-26
The issue was addressed with additional permissions checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to bypass Privacy preferences.
- CVE-2022-26834HIGHCVSS 7.5EG 7.52022-06-13
Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to obtain the information stored in the product because the product is set to accept HTTP connections from the WAN side by de…
- CVE-2022-26857CRITICALCVSS 9.0EG 9.02022-05-26
Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass blocked functionalities and…
- CVE-2022-26913HIGHCVSS 7.4EG 7.42022-05-10
Windows Authentication Information Disclosure Vulnerability
- CVE-2022-26949MEDIUMCVSS 5.3EG 6.52022-03-30
Archer 6.x through 6.9 SP2 P1 (6.9.2.1) contains an improper access control vulnerability on attachments. A remote authenticated malicious user could potentially exploit this vulnerability to gain access to files that should only be allowe…
- CVE-2022-27055HIGHCVSS 7.5EG 7.52022-04-19
ecjia-daojia 1.38.1-20210202629 is vulnerable to information leakage via content/apps/installer/classes/Helper.php. When the web program is installed, a new environment file is created, and the database information is recorded, including t…
- CVE-2022-27128CRITICALCVSS 9.8EG 9.82022-04-10
An incorrect access control issue at /admin/run_ajax.php in zbzcms v1.0 allows attackers to arbitrarily add administrator accounts.
- CVE-2022-27134HIGHCVSS 7.5EG 7.52022-05-13
EOSIO batdappboomx v327c04cf has an Access-control vulnerability in the `transfer` function of the smart contract which allows remote attackers to win the cryptocurrency without paying ticket fee via the `std::string memo` parameter.
- CVE-2022-27484MEDIUMCVSS 5.4EG 5.42022-08-03
A unverified password change in Fortinet FortiADC version 6.2.0 through 6.2.3, 6.1.x, 6.0.x, 5.x.x allows an authenticated attacker to bypass the Old Password check in the password change form via a crafted HTTP request.
- CVE-2022-27511HIGHCVSS 8.1EG 8.12022-06-16
Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator cr…
- CVE-2022-27551MEDIUMCVSS 5.3EG 6.52022-08-03
HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.
- CVE-2022-27575LOWCVSS 3.3EG 3.32022-04-11
Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission.
- CVE-2022-27583CRITICALCVSS 9.1EG 9.12022-10-31
A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affected firmware version to potentially impact the availability of the FlexiCompact.
- CVE-2022-27608MEDIUMCVSS 6.0EG 6.02022-04-04
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administrator privileges. This could result in a user disabling anti-tampering mechanisms which would then …
- CVE-2022-27609MEDIUMCVSS 6.0EG 6.02022-04-04
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of services by users with Administrator privileges. This could result in a user disabling Forcepoint One En…
- CVE-2022-27642HIGHCVSS 8.8EG 8.82023-03-29
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists wi…
- CVE-2022-27645HIGHCVSS 8.8EG 8.82023-03-29
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_co…
- CVE-2022-27661MEDIUMCVSS 4.3EG 4.32022-07-04
Operation restriction bypass vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Workflow.
- CVE-2022-27668CRITICALCVSS 9.8EG 9.82022-06-14
Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77,…
- CVE-2022-2778CRITICALCVSS 9.8EG 9.82022-09-30
In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.
- CVE-2022-27836HIGHCVSS 8.4EG 8.42022-04-11
Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds prop…
- CVE-2022-27838HIGHCVSS 7.7EG 7.82022-04-11
Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege.
- CVE-2022-28067HIGHCVSS 8.6EG 8.62022-05-04
An incorrect access control issue in Sandboxie Classic v5.55.13 allows attackers to cause a Denial of Service (DoS) in the Sandbox via a crafted executable.
- CVE-2022-28321CRITICALCVSS 9.8EG 9.82022-09-19
The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via …
- CVE-2022-28542MEDIUMCVSS 6.8EG 6.82022-04-11
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as Galaxy Store permission.
- CVE-2022-28601MEDIUMCVSS 6.5EG 6.52022-05-10
A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass…
- CVE-2022-2861MEDIUMCVSS 6.5EG 6.52022-09-26
Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts into WebUI via a crafted HTML page.
- CVE-2022-28704HIGHCVSS 7.2EG 7.22022-06-13
Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to log in with the root privilege and perform an arbitrary operation if the product is in its default settings in which is se…
- CVE-2022-28718MEDIUMCVSS 4.3EG 4.32022-07-04
Operation restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.5.1 allow a remote authenticated attacker to alter the data of Bulletin.
- CVE-2022-28749MEDIUMCVSS 6.5EG 6.52022-06-15
Zooms On-Premise Meeting Connector MMR before version 4.8.113.20220526 fails to properly check the permissions of a Zoom meeting attendee. As a result, a threat actor in the Zooms waiting room can join the meeting without the consent of th…
- CVE-2022-28753HIGHCVSS 7.1EG 7.12022-08-11
Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other par…
- CVE-2022-28754HIGHCVSS 7.1EG 7.12022-08-11
Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other par…
- CVE-2022-28774MEDIUMCVSS 5.5EG 5.52022-05-11
Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted.
- CVE-2022-28775MEDIUMCVSS 5.1EG 5.12022-04-11
Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker to write the file without Samsung Flow permission.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →