In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, an
Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to be
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, an
Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functi
Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 1
LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoin
The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side,
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions req
The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which RE
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
EVerest is an EV charging software stack. Prior to version 2026.02.0, during RemoteStop processing, a delayed authorizat
EVerest is an EV charging software stack. Prior to version 2026.02.0, even immediately after CSMS performs a RemoteStop
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permis
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other toke
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share toke
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permi
EVerest is an EV charging software stack. Prior to version 2026.02.0, when WithdrawAuthorization is processed before the
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z
OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, mode
Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain owner
OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord butto
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before
A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unkn
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token
Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reportin
In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assign
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below,
Juju is an open source application orchestration engine that enables any application operation on any infrastructure at
October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information dis
Admidio is an open-source user management solution. Prior to version 5.0.9, the contacts_data.php endpoint uses a weaker
Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthoriz
Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configur
OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the in
Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affe
SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to
The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds th
Incorrect Authorization vulnerability in Drupal Drupal Canvas allows Forceful Browsing.This issue affects Drupal Canvas:
Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16
OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that al
Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents version
Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue a
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started