Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-863

MITRE ↗

Incorrect Authorization

351
CRITICAL
1,194
HIGH
1,775
MEDIUM
193
LOW
3,657 CVEs · Page 13/74
6.5
CVE-2026-58254

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.

6.5
CVE-2026-35211

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0

6.5
CVE-2026-58494

Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation a

6.5
CVE-2026-57217

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization

6.5
CVE-2026-57218

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep re

6.5
CVE-2026-10106

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced i

6.5
CVE-2026-62147

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API respons

6.5
CVE-2026-58408

ChurchCRM is an open-source church management system. Prior to version 7.4.0, a low-privileged user can bypass the /admi

6.5
CVE-2026-59889

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From

6.5
CVE-2026-47732

Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a

6.5
CVE-2026-47084

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An aut

6.5
CVE-2026-4938

IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident

6.5
CVE-2026-16215

A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the compone

6.5
CVE-2026-63740

SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users

6.5
CVE-2026-63755

SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses i

6.5
CVE-2026-65594

n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was

6.5
CVE-2026-13060

An authenticated user with limited read privileges may be able to access documents from collections they are not authori

6.5
CVE-2026-7868

IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges an

6.5
CVE-2026-65975

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 u

6.5
CVE-2026-14923

The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a

6.5
CVE-2026-41187

Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Dele

6.5
CVE-2026-18203

A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a gr

6.5
CVE-2026-2411

Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose

6.5
CVE-2026-18572

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policie

6.5
CVE-2026-15254

The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrat

6.5
CVE-2026-68930

Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for reci

6.5
CVE-2026-58139

The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with S

6.5
CVE-2026-71247

Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role t

6.5
CVE-2026-50749

Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authentica

6.5
CVE-2026-64640

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenti

6.5
CVE-2026-48076

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-clie

6.5
CVE-2026-19345

A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/Up

6.5
CVE-2026-72771

n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when

6.5
CVE-2026-48375

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service

6.5
CVE-2026-63512

Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network

6.5
CVE-2026-48411

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A

6.5
CVE-2026-18696

An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to

6.5
CVE-2026-64952

The hunt_delete() VQL function allows deleting hunts.  Velociraptor misapplied the permission check requiring only COLL

6.5
CVE-2026-47227

Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (

6.5
CVE-2026-47230

Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_re

6.5
CVE-2026-73265

RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, Co

6.5
CVE-2026-53786

rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-leve

6.5
CVE-2026-57897

Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

6.5
CVE-2026-19726

The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, all

6.5
CVE-2026-73059

stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChann

6.5
CVE-2026-75480

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls,

6.5
CVE-2026-9859

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles o

6.5
CVE-2026-49976

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update

6.5
CVE-2026-14949

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed th

6.5
CVE-2026-59318

In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully

Frequently Asked Questions

What is CWE-863?

CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-863?

There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.

How can I protect against CWE-863 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.

Detect CWE-863 Vulnerabilities

CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.

Get Started