Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to
SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-adm
Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 t
OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including blo
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization b
Velociraptor versions prior to 0.76.4 contain a cross organization authorization bypass in the HTTP API. A user with onl
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A
Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-channel authorization bypass vulnerability in stock-loc
The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permission
In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI t
October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identifie
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE
By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18,
Official Document Management System developed by 2100 Technology has a Incorrect Authorization vulnerability, allowing a
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, users a
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderat
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-adm
A vulnerability has been discovered in eladmin v2.7 and before. This vulnerability allows for an arbitrary user password
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/conte
DeepAudit is a multi-agent system for code vulnerability discovery. In 3.0.4 and earlier, there is an improper access co
WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only bo
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to 1.35.
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to merge th
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, under iMessage `groupPolicy=allowlist`, group authoriza
An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data acces
An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab acces
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s ce
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulne
Sensitive information disclosure due to improper authorization checks. The following products are affected: Acronis Cybe
Netmaker makes networks with WireGuard. Prior to version 1.5.0, the user update handler (PUT /api/users/{username}) lack
Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the wor
OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live Event
Copyparty is a portable file server. Prior to 1.20.12, there was a missing permission-check in the shares feature (the s
Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the
FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly r
OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a secu
OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the Feishu allowFrom allowlist imp
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started