Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-863

MITRE ↗

Incorrect Authorization

351
CRITICAL
1,194
HIGH
1,775
MEDIUM
193
LOW
3,657 CVEs · Page 27/74
8.8
CVE-2024-13282

Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block perm

8.8
CVE-2024-57434

macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control. The project imports users by default, and the test

8.8
CVE-2025-26511

Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-

8.8
CVE-2024-5705

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it doe

8.8
CVE-2025-46265

On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may b

8.8
CVE-2025-27696

Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by

8.8
CVE-2025-40670

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a

8.8
CVE-2025-48445

Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) allows Functionality Misuse.This issue affe

8.8
CVE-2025-48446

Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affec

8.8
CVE-2025-49586

XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes applic

8.8
CVE-2025-5071

The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing

8.8
CVE-2025-5822

Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This

8.8
CVE-2025-53895

ZITADEL is an open source identity management system. Starting in version 2.53.0 and prior to versions 4.0.0-rc.2, 3.3.2

8.8
CVE-2025-30751

Vulnerability in the Oracle Database component of Oracle Database Server. Supported versions that are affected are 19.2

8.8
CVE-2025-20701

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This cou

8.8
CVE-2025-42951

Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of

8.8
CVE-2025-36120

IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH s

8.8
CVE-2025-37736

Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can

8.8
CVE-2025-62730

SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to

8.8
CVE-2025-9803

lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth

8.8
CVE-2025-66360

An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpo

8.7
CVE-2025-23256

NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause i

8.7
CVE-2025-49145

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough ri

8.6
CVE-2025-0781

An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permissi

8.6
CVE-2025-21480 KEV

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

8.6
CVE-2025-21479 KEV

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

8.5
CVE-2025-0359

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Appli

8.5
CVE-2025-44824

Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch ser

8.4
CVE-2025-43565

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that c

8.3
CVE-2024-10109

A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access

8.3
CVE-2025-48881

Valtimo is a platform for Business Process Automation. In versions starting from 11.0.0.RELEASE to 11.3.3.RELEASE and 12

8.3
CVE-2025-3260

A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard a

8.3
CVE-2025-64490

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.

8.2
CVE-2025-24409

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect

8.2
CVE-2025-43917

In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninst

8.2
CVE-2025-59683

Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, w

8.1
CVE-2025-21506

Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Technology Foundation). S

8.1
CVE-2025-21516

Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Service Requests). Supported v

8.1
CVE-2024-41140

Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in th

8.1
CVE-2025-30093

HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authentic

8.1
CVE-2025-43922

The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to esca

8.1
CVE-2025-36546

On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication

8.1
CVE-2025-48472

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, there is no check to ensure that

8.1
CVE-2025-48474

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application incorrectly chec

8.1
CVE-2025-48475

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the System does not provide a ch

8.1
CVE-2025-48466

Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets

8.1
CVE-2025-52890

Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus vers

8.1
CVE-2025-30743

Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operati

8.1
CVE-2025-30744

Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Multiplatform Sync Error

8.1
CVE-2025-3719

An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being p

Frequently Asked Questions

What is CWE-863?

CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-863?

There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.

How can I protect against CWE-863 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.

Detect CWE-863 Vulnerabilities

CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.

Get Started