File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a non-staf
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, when the Vikunja API returns tas
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, an aut
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, a low-
When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using
OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization.
PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to
Juju is an open source application orchestration engine that enables any application operation on any infrastructure at
A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function del
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sessionKey/history route
Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only re
Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perfor
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.5, the clientPrivileges option d
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints t
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Be
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /a
lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_l
The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenti
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.acc
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privile
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.upda
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpo
Outline is a service that allows for collaborative documentation. Prior to 1.7.0, the shares.create API accepts both col
Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELE
phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermiss
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open
In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could a
TypeBot is a chatbot builder tool. In versions 3.15.2, the getLinkedTypebots API endpoint returns full bot definitions t
A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown
Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could a
OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows re
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used th
Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated
OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows a
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can e
The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 Thi
OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication t
Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the GET /api/v3/shares en
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution
Mythic before 3.4.0.60 contains a broken hasura permission filter on the payload_build_step table with an always-satisfi
MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows re
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started