Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block perm
macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control. The project imports users by default, and the test
Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it doe
On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may b
Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a
Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) allows Functionality Misuse.This issue affe
Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affec
XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes applic
The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing
Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This
ZITADEL is an open source identity management system. Starting in version 2.53.0 and prior to versions 4.0.0-rc.2, 3.3.2
Vulnerability in the Oracle Database component of Oracle Database Server. Supported versions that are affected are 19.2
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This cou
Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of
IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH s
Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can
SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to
lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth
An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpo
NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause i
Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough ri
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permissi
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Appli
Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch ser
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that c
A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access
Valtimo is a platform for Business Process Automation. In versions starting from 11.0.0.RELEASE to 11.3.3.RELEASE and 12
A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard a
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect
In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninst
Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, w
Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Technology Foundation). S
Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Service Requests). Supported v
Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in th
HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authentic
The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to esca
On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, there is no check to ensure that
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application incorrectly chec
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the System does not provide a ch
Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets
Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus vers
Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operati
Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Multiplatform Sync Error
An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being p
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started