NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0
Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation a
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep re
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced i
The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API respons
ChurchCRM is an open-source church management system. Prior to version 7.4.0, a low-privileged user can bypass the /admi
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An aut
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident
A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the compone
SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users
SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses i
n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was
An authenticated user with limited read privileges may be able to access documents from collections they are not authori
IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges an
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 u
The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a
Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Dele
A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a gr
Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policie
The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrat
Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for reci
The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with S
Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role t
Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authentica
Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenti
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-clie
A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/Up
n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to
The hunt_delete() VQL function allows deleting hunts. Velociraptor misapplied the permission check requiring only COLL
Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_re
RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, Co
rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-leve
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, all
stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChann
OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls,
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles o
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update
A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed th
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started