Permanent Fork PR Workflow Approval Gate Bypass
iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users
RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API v
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete
The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user
M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions b
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions up to and includin
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z
Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permis
Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability wh
WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowis
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_ap
OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly valida
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which
OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device ide
OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers wi
Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticated rem
OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config and /debug command handle
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagen
XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using O
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/updat
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at
Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object mod
Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in Discord text approval commands that allows n
Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perfor
OpenClaw before 2026.3.31 contains an incomplete scope-clearing vulnerability in trusted-proxy authentication mode that
OpenClaw before 2026.4.8 contains a role bypass vulnerability in the device.token.rotate function that allows minting to
OpenClaw before 2026.4.8 contains an improper authorization vulnerability where the node.pair.approve method accepts ope
OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override
OpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybo
OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization th
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configur
Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry an
Incorrect Authorization vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Indus
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.12, the
Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of per
LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role
LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint c
Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to pr
The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When EC
Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vulnerability that allows authenticated use
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permissio
OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped client
mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows au
The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project eva
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started