CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,126 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 57 of 83
- CVE-2025-12925HIGHCVSS 7.3EG 7.32025-11-10
A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/deleteDic of the file src/main/java/com/rymcu/forest/lucene/api/UserDicController.java. Th…
- CVE-2025-12971MEDIUMCVSS 4.3EG 4.32025-11-27
The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on the 'wcp_change_post_folder' …
- CVE-2025-13063HIGHCVSS 7.3EG 7.32025-11-12
A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead to missing authorization. The attack may be performed from remote. The exploit has been published and may be used. Mul…
- CVE-2025-13184CRITICALCVSS 9.8EG 9.82025-12-10
Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same …
- CVE-2025-13324LOWCVSS 3.7EG 3.72025-12-17
Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which …
- CVE-2025-13432MEDIUMCVSS 4.3EG 4.32025-11-21
Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with…
- CVE-2025-13468MEDIUMCVSS 5.4EG 5.42025-11-20
A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comment/delete_gallery/delete_event of the file admin/admin_class.php of the component Delete …
- CVE-2025-13480MEDIUMCVSS 6.5EG 6.52026-04-20
Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only resources via improperly protected API endpoints. This includes sensitive information such as system logs and parts of sy…
- CVE-2025-13653MEDIUMCVSS 4.3EG 4.32025-12-01
In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which allows authenticated users to use specially crafted requests to read documents from data streams without having the res…
- CVE-2025-13734MEDIUMCVSS 5.4EG 5.42026-03-03
IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data beyond their authorized access permissions.
- CVE-2025-13753MEDIUMCVSS 4.3EG 4.32026-01-09
The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data due to an incorrect authorization check on the save_table() function in all versions up to, and including, 2.0.19. T…
- CVE-2025-13767MEDIUMCVSS 4.3EG 4.32025-12-24
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker wit…
- CVE-2025-13806HIGHCVSS 7.3EG 7.32025-12-01
A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthModu…
- CVE-2025-13813MEDIUMCVSS 5.6EG 5.62025-12-01
A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the component Storage Management Endpoint. The manipulation leads to missing authorization. The attack…
- CVE-2025-13829HIGHCVSS 8.6EG 8.62025-12-01
Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user. Critical information retrieved: * APIKEY (1 year user Session) * RefreshToke…
- CVE-2025-13928HIGHCVSS 7.5EG 7.52026-01-22
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to cause a denial of service condition by exploiting …
- CVE-2025-13985MEDIUMCVSS 5.3EG 5.32026-01-28
Incorrect Authorization vulnerability in Drupal Entity Share allows Forceful Browsing.This issue affects Entity Share: from 0.0.0 before 3.13.0.
- CVE-2025-14016MEDIUMCVSS 5.4EG 5.42025-12-04
A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/delete. Such manipulation of the argument ids leads to improper authorization. The attack can …
- CVE-2025-14081MEDIUMCVSS 4.3EG 4.32025-12-17
The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and including, 2.11.0. This is due to a flaw in the secure fields mechanism where field keys are stored in the allowed fields l…
- CVE-2025-1415MEDIUMCVSS 5.1EG 5.12025-05-21
A low-privileged user is able to obtain information about tasks executed on devices controlled by Proget MDM (Mobile Device Management), as well as details of the devices like their UUIDs needed for exploitation of CVE-2025-1416. In order…
- CVE-2025-1416HIGHCVSS 7.0EG 7.02025-05-21
In Proget MDM, a low-privileged user can retrieve passwords for managed devices and subsequently use functionalities restricted by the MDM (Mobile Device Management). For it to happen, they must know the UUIDs of targetted devices, which …
- CVE-2025-1417MEDIUMCVSS 4.6EG 4.62025-05-21
In Proget MDM, a low-privileged user can access information about changes contained in backups of all devices managed by the MDM (Mobile Device Management). This information include user ids, email addresses, first names, last names and de…
- CVE-2025-1418MEDIUMCVSS 5.1EG 5.12025-05-21
A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which contain details about allowed/prohibited functions. The profiles do not reveal any sensitive information (including their …
- CVE-2025-14305HIGHCVSS 7.8EG 7.82025-12-17
ListCheck.exe developed by Acer has a Local Privilege Escalation vulnerability. Authenticated local attackers can replace ListCheck.exe with a malicious executable of the same name, which will be executed by the system and result in privil…
- CVE-2025-14318MEDIUMCVSS 4.3EG 4.32025-12-18
Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using Web Companion despite Print and Download Prevention module being enabled.
- CVE-2025-14352MEDIUMCVSS 5.3EG 5.32026-01-07
The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect authorization in the room-single.php shortcode handler in all versions up to, and including, 1.0.3. This is due to the plugi…
- CVE-2025-14562LOWCVSS 3.1EG 3.12026-07-29
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with developer-role permission…
- CVE-2025-1472MEDIUMCVSS 4.3EG 4.32025-03-19
Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.
- CVE-2025-14774HIGHCVSS 7.4EG 7.42026-06-03
Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
- CVE-2025-14866HIGHCVSS 8.8EG 8.82026-01-23
The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.1. This is due to a misconfigured capability check on the 'save_secondary_roles_field' function. This makes it p…
- CVE-2025-14943MEDIUMCVSS 4.3EG 4.32026-01-10
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.7.2. This is due to a misconfigured authorization check on the 'getShipItemFul…
- CVE-2025-14986LOWCVSS 1.3EG 1.32025-12-30
When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Namespace field rather than the outer, authorized ExecuteMult…
- CVE-2025-14987MEDIUMCVSS 5.3EG 5.32025-12-30
When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task commands (e.g. StartChildWorkflowExecution, SignalExternalWorkflowExecution, RequestCancelExternalWorkflowExecution) to …
- CVE-2025-1501MEDIUMCVSS 4.3EG 4.32025-08-26
An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.1.0 due to a specific access restriction not being properly enforced for users with limited privileges. An authenticat…
- CVE-2025-15023HIGHCVSS 8.8EG 8.82026-05-14
Incorrect Authorization vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows Exploiting Incorrectly Configured Access Control Security Levels. …
- CVE-2025-15085MEDIUMCVSS 4.3EG 4.32025-12-25
A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java of the component Balanc…
- CVE-2025-15119LOWCVSS 3.1EG 3.12025-12-28
A vulnerability was detected in JeecgBoot up to 3.9.0. This issue affects the function queryPageList of the file /sys/sysDepartRole/list. The manipulation of the argument deptId results in improper authorization. The attack can be executed…
- CVE-2025-15120LOWCVSS 3.1EG 3.12025-12-28
A flaw has been found in JeecgBoot up to 3.9.0. Impacted is the function getDeptRoleList of the file /sys/sysDepartRole/getDeptRoleList. This manipulation of the argument departId causes improper authorization. The attack is possible to be…
- CVE-2025-15122LOWCVSS 3.1EG 3.12025-12-28
A vulnerability was found in JeecgBoot up to 3.9.0. The impacted element is the function loadDatarule of the file /sys/sysDepartRole/datarule/. Performing manipulation of the argument departId/roleId results in improper authorization. It i…
- CVE-2025-15123LOWCVSS 3.1EG 3.12025-12-28
A vulnerability was determined in JeecgBoot up to 3.9.0. This affects an unknown function of the file /sys/sysDepartPermission/datarule/. Executing manipulation can lead to improper authorization. It is possible to launch the attack remote…
- CVE-2025-15124LOWCVSS 3.1EG 3.12025-12-28
A vulnerability was identified in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The manipulation of the argument departId leads to improper authorization. The attack can be init…
- CVE-2025-15125LOWCVSS 3.1EG 3.12025-12-28
A security flaw has been discovered in JeecgBoot up to 3.9.0. Affected is the function queryDepartPermission of the file /sys/permission/queryDepartPermission. The manipulation of the argument departId results in improper authorization. Th…
- CVE-2025-15126LOWCVSS 3.1EG 3.12025-12-28
A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position/getPositionUserList. This manipulation of the argument positionId causes improper authori…
- CVE-2025-15288LOWCVSS 4.3EG 3.12026-01-29
Tanium addressed an improper access controls vulnerability in Interact.
- CVE-2025-15321LOWCVSS 2.7EG 2.72026-02-05
Tanium addressed an improper input validation vulnerability in Tanium Appliance.
- CVE-2025-15322MEDIUMCVSS 4.3EG 4.32026-01-30
Tanium addressed an improper access controls vulnerability in Tanium Server.
- CVE-2025-15342MEDIUMCVSS 4.3EG 4.32026-02-05
Tanium addressed an improper access controls vulnerability in Reputation.
- CVE-2025-15390MEDIUMCVSS 6.3EG 6.32025-12-31
A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edit-user.php. The manipulation results in missing authorization. It is possible to launch the attack remotely. The exploi…
- CVE-2025-15395MEDIUMCVSS 5.4EG 4.32026-02-02
IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violations that allows the users to view or access/perform actions beyond their expected capability.
- CVE-2025-1540LOWCVSS 3.1EG 3.12025-03-06
An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read…
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →