Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of cal
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-pfdmanage
Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerabil
ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL
Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerabil
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell end
Kargo manages and automates the promotion of software artifacts. From 1.7.0 to before v1.7.8, v1.8.11, and v1.9.3, the b
OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal appro
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to
In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table
wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git pus
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the modul
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints tha
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th
Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an atta
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.u
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrict
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions duri
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated a
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed clust
Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authoriz
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across project
MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and
VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The admin authorizatio
A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fas
An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allow
OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display n
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t
An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-R
SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability
OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_
Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protect
changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update se
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler
Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions.
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 1,274 CVE records associated with CWE-863 in our database. Of these, 100 are critical severity, 403 are high severity, and 591 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started