Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access
SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3 API accepts an exter
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I
In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supp
Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operati
Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter
Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over
Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application t
Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to rec
Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a su
DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.
Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services).
Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int
Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issu
WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the v
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Insecure Extens
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw i
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma
An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account re
In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead
Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z
IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenti
Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks
Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impers
Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator bac
Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank passw
V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain admini
An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers
The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit all
The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows p
Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue
Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: f
Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 bef
Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus:
An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web reque
The issue was addressed by removing the relevant flags. This issue is fixed in iOS 18.2 and iPadOS 18.2, watchOS 11.2. A
The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, visio
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect A
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions
Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remo
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that c
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that c
Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is
Cryptographic issue occurs due to use of insecure connection method while downloading.
System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator
Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsu
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started