FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in t
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Co
An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary fi
An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control soc
ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4
A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker wh
Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated client
A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow
In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An au
In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the Si
In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-C
Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspac
Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass expose
Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in th
Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide
In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to e
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upg
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Soft
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_tu
CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user
Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the und
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1,
vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-s
CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any
On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-ban
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments a
stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the decay sweep endpoint t
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, W
Flow-Like is a platform for building end-to-end use cases. Prior to version 1.0.4, `GET /api/v1/apps/{app_id}/invoke/pre
Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkActions dispatcher.Thi
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access
Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.20, a community moder
Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allo
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to 1.71
PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion log
Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform o
Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositor
The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a re
Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging socia
Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised
In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped au
In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, appl
On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged n
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started