Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-863

MITRE ↗

Incorrect Authorization

351
CRITICAL
1,194
HIGH
1,775
MEDIUM
193
LOW
3,657 CVEs · Page 25/74
CVE-2026-43946

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in t

CVE-2026-43947

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Co

CVE-2026-59678

An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary fi

CVE-2026-44944

An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control soc

CVE-2026-54693

ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4

CVE-2026-18236

A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker wh

CVE-2026-48113

Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated client

CVE-2026-64630

A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.

CVE-2026-69262

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1

CVE-2026-70471

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow

CVE-2026-70472

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-

CVE-2026-70474

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow

CVE-2026-55707

In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An au

CVE-2026-71191

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the Si

CVE-2026-71192

In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-C

CVE-2026-47185

Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspac

CVE-2026-71325

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25

CVE-2026-66059

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass expose

CVE-2026-17594

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in th

CVE-2026-66000

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation

CVE-2026-45808

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide

CVE-2025-30238

In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to e

CVE-2026-13737

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upg

CVE-2026-13738

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Soft

CVE-2026-73213

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_tu

CVE-2026-73221

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user

CVE-2026-18171

Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the und

CVE-2026-73499

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1,

CVE-2026-73652

vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-s

CVE-2026-49989

CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any

CVE-2026-18674

On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-ban

CVE-2026-11817

This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments a

CVE-2026-76238

stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the decay sweep endpoint t

CVE-2026-44252

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, W

CVE-2026-50173

Flow-Like is a platform for building end-to-end use cases. Prior to version 1.0.4, `GET /api/v1/apps/{app_id}/invoke/pre

CVE-2026-19198

Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkActions dispatcher.Thi

CVE-2026-55643

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access

CVE-2026-54742

Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.20, a community moder

CVE-2026-7485

Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allo

CVE-2026-54136

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to 1.71

CVE-2026-62382

PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion log

CVE-2025-63080

Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform o

CVE-2026-75542

Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositor

CVE-2026-77134

The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a re

CVE-2026-78898

Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social

CVE-2026-79088

Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging socia

CVE-2026-79186

Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised

CVE-2026-80182

In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped au

CVE-2026-80184

In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, appl

CVE-2026-79619

On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged n

Frequently Asked Questions

What is CWE-863?

CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-863?

There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.

How can I protect against CWE-863 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.

Detect CWE-863 Vulnerabilities

CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.

Get Started