Common Weakness Enumeration
CWE Definition / CWE-285
CWE-285: Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Published:19 Jul 2006
Organization:MITRE
Modified:30 Apr 2026
