A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repo
Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.
Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpo
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studi
OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode where
FileRise is a self-hosted web file manager / WebDAV server. Prior to version 3.10.0, a broken access control issue in Fi
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only oper
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumab
OpenHarness prior to commit 166fcfe contains an improper access control vulnerability in built-in file tools due to inco
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thread editing is autho
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, when `APP_SHOW_ONLY_ASSIGNED_CON
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, `MailboxesController::updateSave
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, Cle
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write perm
OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechani
Admidio is an open-source user management solution. Prior to version 5.0.9, a logic error in Admidio's two-factor authen
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio
Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users
Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner ac
Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.j
Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged P
An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain co
Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user ho
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to be
Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local at
Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allowed a
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in
Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/
MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree
Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who h
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260326.0
Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulne
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and u
OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling th
Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authen
Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a c
Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/ss
OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validatio
Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace).
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin r
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Ng
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Flee
Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is
An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued conn
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started