The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoint
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a c
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the req
OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with hos
An issue that could expose task information outside of the authorized organization scope has been resolved. This is an i
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another p
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_s
Lack of authorization of the InputManager D-Bus interface in InputPlumber versions before v0.63.0 can lead to local Deni
QGIS is a free, open source, cross platform geographical information system (GIS) The repository contains a GitHub Actio
opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability i
Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other u
Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other u
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9,
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.4-beta
Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. F
Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.2
etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulne
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior are vulnerable to Authorization
authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authent
OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assi
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper authorization in the Upload
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, the mc_issue_update() function in Mantis
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write opera
Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_she
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level p
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8
Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server version
An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify
An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accou
An incorrect visibility condition in the MISP event template builder allowed authenticated non-site-admin users to view
A vulnerability in MISP’s non-REST event editing path allowed an authenticated user with event edit permissions to manip
An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions t
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authorization vulnerability
DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instanc
Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.24, an authentication bypass v
FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-constructi
Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess fun
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/u
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when the "Requ
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share int
MISP’s importModule() path used getEnabledModule() to resolve a single import module by name, but this lookup did not en
An improper authorization check in MISP’s attribute creation endpoint allowed an authenticated user with permission to a
osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Obje
The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter backed by @openai/codex-sdk, which drives the codex command
The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed bridge. Prior to version 1.0.2
A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecastin
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platfor
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthent
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started