CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,127 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 67 of 83
- CVE-2026-15320MEDIUMCVSS 5.4EG 5.42026-07-10
A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function rt.ReloadConfig of the file pkg/channels/pico/pico.go. Performing a manipulation of the argument message.send results in missing authoriza…
- CVE-2026-15332MEDIUMCVSS 6.3EG 6.32026-07-10
A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. The impacted element is an unknown function of the file channel/channel.py of the component Message Endpoint. The manipulation results in missing authorization. The atta…
- CVE-2026-15507MEDIUMCVSS 6.3EG 6.32026-07-12
A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation results in missing authorization. Remote expl…
- CVE-2026-1553MEDIUMCVSS 4.8EG 4.82026-02-04
Incorrect Authorization vulnerability in Drupal Drupal Canvas allows Forceful Browsing.This issue affects Drupal Canvas: from 0.0.0 before 1.0.4.
- CVE-2026-15541HIGHCVSS 7.3EG 7.32026-07-13
A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component Master Websocket Handler. Executing a manipulation of the argument Agent ca…
- CVE-2026-15630CRITICALCVSS 9.9EG 9.92026-07-23
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
- CVE-2026-15641HIGHCVSS 7.1EG 7.12026-07-14
Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoin…
- CVE-2026-15704CRITICALCVSS 9.8EG 9.82026-07-24
In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The sh…
- CVE-2026-15752HIGHCVSS 7.3EG 7.32026-07-14
A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the component Backend User Endpoint. Performing a manipulation results…
- CVE-2026-15829HIGHCVSS 8.6EG 8.62026-07-21
A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timesta…
- CVE-2026-16017MEDIUMCVSS 6.3EG 6.32026-07-17
A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file tools/tool_cron.go of the component cron Chat Tool. The manipulation results in missing authorization. The attack may be …
- CVE-2026-16119MEDIUMCVSS 6.3EG 6.32026-07-18
A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval.go of the component WebSocket Approval Endpoint. Performing a manipulation results in inc…
- CVE-2026-16122MEDIUMCVSS 4.3EG 4.32026-07-18
A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results i…
- CVE-2026-16123MEDIUMCVSS 6.3EG 6.32026-07-18
A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the file internal/http/tools_invoke.go of the component Invoke Endpoint. This manipulation cause…
- CVE-2026-16126HIGHCVSS 7.3EG 7.32026-07-18
A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of the file claw/services/swarm/swarm.c of the component Swarm RPC Receiver. This manipulation causes incorrect authoriza…
- CVE-2026-16195MEDIUMCVSS 6.3EG 6.32026-07-18
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. The manipulation results in incorrect auth…
- CVE-2026-16197MEDIUMCVSS 6.3EG 6.32026-07-18
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. Such manipulation lea…
- CVE-2026-16200HIGHCVSS 7.3EG 7.32026-07-19
A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of the component RPC Handler. The manipulation leads to incorrect authorization. Remote exploi…
- CVE-2026-16215MEDIUMCVSS 6.5EG 6.52026-07-19
A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the component OAuth Credential Revoke Handler. Performing a manipulation results in missing authorization. The attack is possible …
- CVE-2026-17039LOWCVSS 3.1EG 3.12026-07-24
A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certi…
- CVE-2026-1734MEDIUMCVSS 5.3EG 5.32026-02-02
A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. This vulnerability affects unknown code of the file crmeb/app/api/controller/v1/CrontabController.php of the component crontab Endpoint. The manipulation results in missi…
- CVE-2026-1752MEDIUMCVSS 4.3EG 4.32026-04-08
GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with developer-role permissions to modify protected envi…
- CVE-2026-17529MEDIUMCVSS 6.3EG 6.32026-07-27
A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument req.func_tool leads to incorrect authorization. The attack ma…
- CVE-2026-17530MEDIUMCVSS 6.3EG 6.32026-07-27
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/astr_agent_tool_exec.py of the component Subagent. The manipula…
- CVE-2026-17568HIGHCVSS 8.8EG 8.82026-07-27
Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a …
- CVE-2026-1768MEDIUMCVSS 4.3EG 4.32026-02-24
A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.This issue affects Devolutions Server: before 2025.3.15.
- CVE-2026-18236CRITICALCVSS 9.3EG 9.32026-07-29
A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool conf…
- CVE-2026-18255HIGHCVSS 7.2EG 7.22026-07-29
A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot ac…
- CVE-2026-1897MEDIUMCVSS 4.3EG 4.32026-02-05
A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/methods/positionHistory.js of the component Position-History Tracking. The manipulation results in missing authorization…
- CVE-2026-1999MEDIUMCVSS 6.5EG 6.52026-02-18
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to merge their own pull request into a repository without having push access by exploiting an authorization bypass in the enable_a…
- CVE-2026-20238MEDIUMCVSS 6.5EG 6.52026-05-20
In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app contain…
- CVE-2026-20624MEDIUMCVSS 5.5EG 5.52026-02-11
An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.
- CVE-2026-20960HIGHCVSS 8.0EG 8.02026-01-16
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
- CVE-2026-20992LOWCVSS 3.3EG 3.32026-03-16
Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.
- CVE-2026-21031HIGHCVSS 7.8EG 7.82026-06-05
Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.
- CVE-2026-21036MEDIUMCVSS 5.5EG 5.52026-06-05
Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information.
- CVE-2026-2126MEDIUMCVSS 5.3EG 5.32026-02-18
The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 20260113. This is due to the `usp_get_submitted_category()` fu…
- CVE-2026-21274HIGHCVSS 7.8EG 7.82026-01-13
Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could leverage this vulnerability to bypas…
- CVE-2026-21285MEDIUMCVSS 4.3EG 4.32026-03-11
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could …
- CVE-2026-21286MEDIUMCVSS 5.3EG 5.32026-03-11
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this …
- CVE-2026-21289HIGHCVSS 7.5EG 7.52026-03-11
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this …
- CVE-2026-21296MEDIUMCVSS 4.3EG 4.32026-03-11
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could …
- CVE-2026-21297MEDIUMCVSS 4.3EG 4.32026-03-11
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could …
- CVE-2026-21309HIGHCVSS 7.5EG 7.52026-03-11
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this …
- CVE-2026-21359MEDIUMCVSS 4.7EG 4.72026-03-11
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this …
- CVE-2026-2141HIGHCVSS 8.8EG 8.82026-02-08
A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/kakarote/gateway/service/impl/PermissionServiceImpl.java of the component URL Handler. Perfo…
- CVE-2026-21621MEDIUMCVSS 5.3EG 5.32026-03-05
Incorrect Authorization vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.API.OAuthController' module) allows Privilege Escalation. An API key created with read-only permissions (domain: "api", resource: "read") can be escalated to ful…
- CVE-2026-21721HIGHCVSS 8.1EG 8.12026-01-27
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on othe…
- CVE-2026-21722MEDIUMCVSS 5.3EG 5.32026-02-12
Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those …
- CVE-2026-21789MEDIUMCVSS 4.6EG 4.62026-05-18
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →