An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions start
Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to restrict bookmark cre
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, whi
Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This a
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap does not enforce
A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue pe
SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Au
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to check the "Allow Users to View Archived
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to vi
A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not
A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users'
A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they a
Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to check the correct pe
Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing gr
The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss
IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authent
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, when creating a conversation fro
An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK532
The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized modification of
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr
An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned f
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Author
A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown fun
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr
In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.6, and 9.1.9 and Splunk Cloud Platform versions below 9.3.2411.103
An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). S
An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for c
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.
Abnormal Security /v1.0/rbac/users_v2/{USER_ID}/ before 2025-02-19 allows downgrading the privileges of other user accou
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependenc
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration
Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Com
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to modi
MiR software versions prior to version 3.0.0 have insufficient authorization controls when creating text notes, allowin
An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.
A vulnerability has been found in macrozheng mall up to 1.0.3. This affects the function cancelOrder of the file /order/
Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impa
Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2
Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to all members of the user'
A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refre
A vulnerability was found in JhumanJ OpnForm up to 1.9.3. This issue affects some unknown processing of the file /show/i
SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to de
Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive u
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started