CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,107 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 8 of 83
- CVE-2020-0065MEDIUMCVSS 5.5EG 5.52020-05-14
An improper authorization in the receiver component of the Android Suite Daemon.Product: AndroidVersions: Android SoCAndroid ID: A-149813448
- CVE-2020-0084HIGHCVSS 7.8EG 7.82020-03-10
In several functions of NotificationManagerService.java, there are missing permission checks. This could lead to local escalation of privilege by creating fake system notifications with no additional execution privileges needed. User inter…
- CVE-2020-0085HIGHCVSS 7.8EG 7.82020-03-10
In setBluetoothTethering of PanService.java, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege to activate tethering with no additional execution privileges needed. Us…
- CVE-2020-0087MEDIUMCVSS 5.5EG 5.52020-03-10
In getProcessPss of ActivityManagerService.java, there is a possible side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploi…
- CVE-2020-0090MEDIUMCVSS 5.5EG 5.52020-05-14
An improper authorization in the receiver component of Email.Product: AndroidVersions: Android SoCAndroid ID: A-149813048
- CVE-2020-0097HIGHCVSS 7.8EG 7.82020-05-14
In various methods of PackageManagerService.java, there is a possible permission bypass due to a missing condition for system apps. This could lead to local escalation of privilege with User privileges needed. User interaction is not neede…
- CVE-2020-0115HIGHCVSS 7.8EG 7.82020-06-10
In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution pri…
- CVE-2020-0288MEDIUMCVSS 5.5EG 5.52020-09-17
In PackageManager, there is a missing permission check. This could lead to local information disclosure across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android…
- CVE-2020-0389MEDIUMCVSS 5.5EG 5.52020-09-17
In createSaveNotification of RecordingService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed…
- CVE-2020-0395MEDIUMCVSS 5.5EG 5.52020-09-17
In showNotification of EmergencyCallbackModeService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not …
- CVE-2020-0396MEDIUMCVSS 5.5EG 5.52020-09-17
In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Pr…
- CVE-2020-0397MEDIUMCVSS 5.5EG 5.52020-09-17
In getNotificationBuilder of CarrierServiceStateTracker.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is …
- CVE-2020-0399MEDIUMCVSS 5.5EG 5.52020-09-17
In showLimitedSimFunctionWarningNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interac…
- CVE-2020-0473MEDIUMCVSS 4.6EG 4.62020-12-15
In updateIncomingFileConfirmNotification of BluetoothOppNotification.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing an attacker with physical possession of the device to transfer fil…
- CVE-2020-0477MEDIUMCVSS 5.5EG 5.52020-12-15
In sendLinkConfigurationChangedBroadcast of ClientModeImpl.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of the current network configuration with no add…
- CVE-2020-0479HIGHCVSS 7.8EG 7.82020-12-15
In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a malicious app to access files available to the DocumentProvider without user permission, with n…
- CVE-2020-0480HIGHCVSS 7.8EG 7.82020-12-15
In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a caller to copy, move, or delete files accessible to Documents…
- CVE-2020-0481LOWCVSS 3.3EG 3.32020-12-15
In AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a non-system app to send a broadcast it shouldn't have permissions to send, with no additional execution privileges n…
- CVE-2020-0523MEDIUMCVSS 4.4EG 4.42021-02-17
Improper access control in the firmware for the Intel(R) Ethernet I210 Controller series of network adapters before version 3.30 may potentially allow a privileged user to enable a denial of service via local access.
- CVE-2020-0525MEDIUMCVSS 4.4EG 4.42021-02-17
Improper access control in firmware for the Intel(R) Ethernet I210 Controller series of network adapters before version 3.30 may allow a privileged user to potentially enable denial of service via local access.
- CVE-2020-0702MEDIUMCVSS 6.8EG 6.82020-02-11
A security feature bypass vulnerability exists in Surface Hub when prompting for credentials, aka 'Surface Hub Security Feature Bypass Vulnerability'.
- CVE-2020-0981HIGHCVSS 8.8EG 8.82020-04-15
A security feature bypass vulnerability exists when Windows fails to properly handle token relationships.An attacker who successfully exploited the vulnerability could allow an application with a certain integrity level to execute code at …
- CVE-2020-10081MEDIUMCVSS 6.5EG 6.52020-03-13
GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.
- CVE-2020-10116MEDIUMCVSS 5.3EG 5.32020-03-17
cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI calls (SEC-541).
- CVE-2020-10117CRITICALCVSS 9.1EG 9.12020-03-17
cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542).
- CVE-2020-10120HIGHCVSS 7.2EG 7.22020-03-17
cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545).
- CVE-2020-10145HIGHCVSS 7.8EG 7.82021-05-27
The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a …
- CVE-2020-10194MEDIUMCVSS 6.5EG 6.52020-03-20
cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs from the intended behavior in which the domain of the authenticated user must match the domai…
- CVE-2020-10239HIGHCVSS 8.8EG 8.82020-03-16
An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.
- CVE-2020-10510HIGHCVSS 8.1EG 8.12020-03-27
Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. After login, attackers can use a specific URL, access unauthorized functionality and data.
- CVE-2020-10534CRITICALCVSS 9.8EG 9.82020-03-12
In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to the case in which an IP address is contai…
- CVE-2020-10539CRITICALCVSS 9.8EG 9.82021-02-05
An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user login, checks the submitted password against the user password's MD5 hash stored in the database. It is also compared …
- CVE-2020-10676HIGHCVSS 8.8EG 8.82023-12-12
In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a different project.
- CVE-2020-10786HIGHCVSS 8.8EG 8.82020-04-21
A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs.
- CVE-2020-10839MEDIUMCVSS 6.8EG 6.82020-03-24
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via a SIM card. The Samsung ID is SVE-2019-16193 (February 2020).
- CVE-2020-10952MEDIUMCVSS 6.5EG 6.52020-03-27
GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.
- CVE-2020-11209MEDIUMCVSS 5.5EG 5.52020-11-12
Improper authorization in DSP process could allow unauthorized users to downgrade the library versions in SD820, SD821, SD820, QCS603, QCS605, SDA855, SA6155P, SA6145P, SA6155, SA6155P, SD855, SD 675, SD660, SD429, SD439
- CVE-2020-11282HIGHCVSS 7.8EG 7.82021-02-22
Improper access control when using mmap with the kgsl driver with a special offset value that can be provided to map the memstore of the GPU to user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer…
- CVE-2020-11628MEDIUMCVSS 5.3EG 5.32020-04-08
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. It is intended to support restriction of available remote protocols (CMP, ACME, REST, etc.) through the system configuration. These restrictions can be bypassed by mo…
- CVE-2020-11680MEDIUMCVSS 6.5EG 6.52020-06-04
Castel NextGen DVR v1.0.0 is vulnerable to authorization bypass on all administrator functionality. The application fails to check that a request was submitted by an administrator. Consequently, a normal user can perform actions including,…
- CVE-2020-11707HIGHCVSS 8.8EG 8.82020-04-12
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlinks or Junctions. As a result, a low-privileged user (non-admin) can craft a Junction Link in a directory he has full co…
- CVE-2020-11753HIGHCVSS 8.8EG 8.82020-04-20
An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0,…
- CVE-2020-11844CRITICALCVSS 10.0EG 10.02020-05-29
Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybrid Cloud Management. Versions 2018.05 to 2019.11. - ArcSight Investigate. versions 2.4.0, 3.0.0 and 3.1.0. - ArcSight Tr…
- CVE-2020-11855HIGHCVSS 7.8EG 7.82020-09-22
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow local attackers on the OBR host to execute code with escalated privileges.
- CVE-2020-11889MEDIUMCVSS 5.3EG 5.32020-04-21
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups.
- CVE-2020-11891MEDIUMCVSS 5.3EG 5.32020-04-21
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of usergroups.
- CVE-2020-12030CRITICALCVSS 10.0EG 10.02021-09-29
There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports u…
- CVE-2020-12053CRITICALCVSS 9.8EG 9.82020-06-22
In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoint could be authorized without a private key.
- CVE-2020-12391HIGHCVSS 7.5EG 7.52020-05-26
Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that should have been blocked, albeit with a unique opaque origin. This vulnerability affects F…
- CVE-2020-12477HIGHCVSS 7.5EG 7.52020-04-29
The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →