Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-863

MITRE ↗

Incorrect Authorization

351
CRITICAL
1,194
HIGH
1,775
MEDIUM
193
LOW
3,657 CVEs · Page 21/74
4.3
CVE-2026-59217

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the file upload p

4.3
CVE-2026-59227

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /a

4.3
CVE-2026-15286

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized po

4.3
CVE-2026-59154

Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct

4.3
CVE-2026-55472

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locati

4.3
CVE-2026-55462

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authoriz

4.3
CVE-2026-55479

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorize

4.3
CVE-2026-62198

OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allo

4.3
CVE-2026-46635

Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), whic

4.3
CVE-2026-63097

Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/rout

4.3
CVE-2026-63309

SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to

4.3
CVE-2026-16122

A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the funct

4.3
CVE-2026-63733

SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMIS

4.3
CVE-2026-63738

SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through g

4.3
CVE-2026-63742

SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths

4.3
CVE-2026-63749

SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permis

4.3
CVE-2026-63751

SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allo

4.3
CVE-2026-49092

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure v

4.3
CVE-2026-63145

Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification

4.3
CVE-2026-13061

An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessi

4.3
CVE-2026-67439

OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service

4.3
CVE-2026-67528

OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/custom_options/:id resol

4.3
CVE-2026-55499

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscri

4.3
CVE-2026-14929

The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allo

4.3
CVE-2026-62354

Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients wit

4.3
CVE-2026-70484

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legac

4.3
CVE-2026-70488

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync

4.3
CVE-2026-12624

Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a tra

4.3
CVE-2026-72785

Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only

4.3
CVE-2026-15388

The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability

4.3
CVE-2026-18046

The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability

4.3
CVE-2026-68755

A bundle writer may create misleading release promotion information under specific conditions.

4.3
CVE-2026-8667

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 1

4.3
CVE-2026-18433

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that u

4.3
CVE-2026-63295

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolatio

4.3
CVE-2026-19182

An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authen

4.3
CVE-2026-58425

OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

4.3
CVE-2026-58431

Public-only API token restriction is not enforced on team API routes

4.3
CVE-2026-58444

Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private rep

4.3
CVE-2026-74248

OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another projec

4.3
CVE-2026-16045

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauthorization and person

4.3
CVE-2026-16046

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for f

4.3
CVE-2026-70657

Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined

4.3
CVE-2026-45121

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check permissions consistentl

4.3
CVE-2026-45122

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissio

4.3
CVE-2026-76370

In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use the Representational

4.3
CVE-2026-62313

Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricte

4.3
CVE-2026-4245

The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0

4.3
CVE-2026-77923

Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in

4.3
CVE-2026-78946

Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin

Frequently Asked Questions

What is CWE-863?

CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-863?

There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.

How can I protect against CWE-863 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.

Detect CWE-863 Vulnerabilities

CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.

Get Started