Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-863

MITRE ↗

Incorrect Authorization

351
CRITICAL
1,194
HIGH
1,775
MEDIUM
193
LOW
3,657 CVEs · Page 30/74
6.5
CVE-2025-57728

In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files

6.5
CVE-2025-9376

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to

6.5
CVE-2025-25010

Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectl

6.5
CVE-2025-54246

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that cou

6.5
CVE-2025-43784

Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024

6.5
CVE-2025-59714

In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.

6.5
CVE-2025-27236

A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have

6.5
CVE-2025-54267

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an

6.5
CVE-2025-62651

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for th

6.5
CVE-2025-11971

GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5

6.5
CVE-2025-34273

Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administ

6.5
CVE-2025-63687

An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/

6.5
CVE-2025-59111

Windu CMS is vulnerable to Broken Access Control in user editing functionality. Malicious attacker can send a GET reques

6.5
CVE-2025-66424

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40

6.5
CVE-2025-65900

Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due

6.5
CVE-2025-66581

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0,

6.4
CVE-2025-21403

On-Premises Data Gateway Information Disclosure Vulnerability

6.4
CVE-2024-51417

An issue in System.Linq.Dynamic.Core before 1.6.0 allows remote access to properties on reflection types and static prop

6.4
CVE-2024-42013

In GRAU DATA Blocky before 3.1, Blocky-Gui has a Client-Side Enforcement of Server-Side Security vulnerability. An attac

6.4
CVE-2025-46544

In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles.

6.4
CVE-2025-62648

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive

6.3
CVE-2025-1214

A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file

6.3
CVE-2024-49808

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity

6.3
CVE-2025-8807

A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been declared as critical. This vulnerability affects un

6.3
CVE-2025-9602

A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. P

6.3
CVE-2025-23262

NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause in

6.3
CVE-2025-11438

A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /cust

6.3
CVE-2025-15390

A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edi

6.1
CVE-2025-21570

Vulnerability in the Oracle Life Sciences Argus Safety product of Oracle Health Sciences Applications (component: Login)

6.1
CVE-2025-24200 KEV

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4

6.1
CVE-2024-9098

In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new membe

6.1
CVE-2025-21582

Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Suppo

6.1
CVE-2025-30748

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). S

6.0
CVE-2024-13947

Device commissioning parameters in ASPECT may be modified by an external source if administrative credentials become com

5.9
CVE-2025-54265

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an

5.9
CVE-2025-66378

Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacke

5.7
CVE-2025-11060

A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or gu

5.7
CVE-2025-9955

An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission res

5.6
CVE-2025-0580

A vulnerability was found in Shiprocket Module 3 on OpenCart. It has been rated as critical. Affected by this issue is s

5.6
CVE-2024-2321

An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed direct

5.6
CVE-2025-13813

A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the f

5.5
CVE-2025-21533

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a

5.5
CVE-2025-21555

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

5.5
CVE-2025-24114

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma

5.5
CVE-2025-30440

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Vent

5.5
CVE-2024-8270

The macOS Rocket.Chat application is affected by a vulnerability that allows bypassing Transparency, Consent, and Contr

5.5
CVE-2025-30739

Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Suppo

5.5
CVE-2025-50085

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

5.5
CVE-2025-43251

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.6. A local

5.5
CVE-2025-26442

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent

Frequently Asked Questions

What is CWE-863?

CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-863?

There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.

How can I protect against CWE-863 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.

Detect CWE-863 Vulnerabilities

CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.

Get Started