A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/in
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a
Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignm
Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:298 authorized updates
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, a us
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.
OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authori
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-on
FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated
PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals
nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landloc
Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notifica
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin d
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditi
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not p
OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in age
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an attacke
LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows at
This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on t
Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can
A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one
An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization
An issue that allowed administrators to create and update users outside of their authorized organization scope has been
An issue that could allow a credential to be updated and used for a task from outside of the authorized organization sco
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to prope
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag l
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks endpoint
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmi
Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in t
PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normall
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV impo
An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.
Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Incorrect Authorization vulnerability. A low pr
Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive informa
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequ
Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PA
A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers
Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might al
The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to d
Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged a
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started