OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where Signal group allowlist policy i
OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling th
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control f
GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.1
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken differs from the orig
A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocati
A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of th
On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked cor
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted applic
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the P
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authe
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endp
Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the back
This issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26
October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grained sub-permission c
The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is
Tanium addressed an improper access controls vulnerability in Interact.
Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth type
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being changed when updating p
Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued f
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, an
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_
Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing.
filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, all
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence orac
MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media
A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based autho
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 1
An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization
Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compr
Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compr
Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compr
An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope h
An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resol
Tanium addressed an improper input validation vulnerability in Tanium Appliance.
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, moderators could e
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users can publ
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below,
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and
Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and
Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transf
GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.
The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST
The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST
The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started