Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the file upload p
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /a
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized po
Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locati
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authoriz
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorize
OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allo
Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), whic
Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/rout
SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to
A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the funct
SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMIS
SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through g
SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths
SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permis
SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allo
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure v
Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification
An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessi
OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service
OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/custom_options/:id resol
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscri
The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allo
Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients wit
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legac
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync
Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a tra
Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only
The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability
The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability
A bundle writer may create misleading release promotion information under specific conditions.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 1
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that u
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolatio
An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authen
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
Public-only API token restriction is not enforced on team API routes
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private rep
OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another projec
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauthorization and person
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for f
Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined
MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check permissions consistentl
MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissio
In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use the Representational
Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricte
The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0
Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in
Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started