CWE-863Class8 in KEV

Incorrect Authorization

Incomplete in the CWE catalog · 2,302 CVEs mapped

2,302
CVEs mapped
8
In KEV
6.5
Median CVSS
What it is

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Recent examples
7.7cvss
CVE-2026-86498

In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission

In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission

HIGHno explanation yet
epss
6.5cvss
CVE-2026-86493

In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards

In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards

MEDIUMno explanation yet
epss
6.5cvss
CVE-2026-86490

In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint

In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint

MEDIUMno explanation yet
epss
The record
Technical detail
CWE ID
CWE-863
Abstraction
Class
Structure
Simple
Status
Incomplete
References (6)