HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certai
Information disclosure and manipulation due to improper authorization checks. The following products are affected: Acron
An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved.
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's rea
The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup
There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper director
The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure
Lychee is a free, open-source photo-management tool. Prior to 7.1.0, an authorization vulnerability exists in Lychee's a
The CP Image Store with Slideshow plugin for WordPress is vulnerable to authorization bypass in all versions up to, and
EVerest is an EV charging software stack. Prior to version 2025.9.0, once the validity of the received V2G message has b
EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequen
Tanium addressed an improper access controls vulnerability in Tanium Server.
Due to inadequate access control, authenticated users of certain HIKSEMI NAS products can manipulate other users' file r
IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violatio
A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/m
Tanium addressed an improper access controls vulnerability in Reputation.
WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allow
A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publi
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creati
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0
The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for Wor
A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to acc
Discourse is an open source discussion platform. Versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 have an IDOR (Insec
In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting i
Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cy
Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cy
Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acr
Unauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Prot
Unauthorized data access due to insufficient access control validation. The following products are affected: Acronis Cyb
Sensitive information disclosure due to improper access control. The following products are affected: Acronis Cyber Prot
Netmaker makes networks with WireGuard. Prior to version 1.5.0, a user assigned the platform-user role can retrieve Wire
Kubewarden is a policy engine for Kubernetes. Kubewarden cluster operators can grant permissions to users to deploy name
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.7.6, 18.8 before 18.8.6, and 1
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when editing a project budget and
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file p
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissions in
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail to verify run_create permission for empty playbookId, which
OpenClaw versions prior to 2026.2.25 fail to consistently apply sender-policy checks to reaction_* and pin_* non-message
Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application us
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Keystone is a content management system for Node.js. Prior to version 6.5.2, {field}.isFilterable access control can be
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.11
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restric
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In versiosn 2.3.
In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started