The Folderly plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability c
A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the fu
Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to disc
An issue has been discovered in GitLab EE affecting all versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 b
LogStare Collector contains an incorrect authorization vulnerability in UserRegistration. If exploited, a non-administra
Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise w
The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vul
In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user pe
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do
The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and incl
Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using W
Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated use
Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated use
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user ch
A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of th
Gitea before 1.25.2 mishandles authorization for deletion of releases.
ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.25,
A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin service
Under certain conditions, an authenticated user request may execute with stale privileges following an intentional chang
HTCondor Access Point before 25.3.1 allows an authenticated user to impersonate other users on the local machine by subm
An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with a
Huawei EG8141A5 devices through V5R019C00S100, EG8145V5 devices through V5R019C00S100, and EG8145V5-V2 devices through V
Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows second
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.
The issue was addressed with additional permissions checks. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Tahoe 26. An
Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions
An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.
XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4,
Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role mod
TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51
feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-writ
Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite to
Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thre
The YoSmart YoLink application through 2025-10-02 has session tokens with unexpectedly long lifetimes.
A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an un
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Node based network policies (
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS
An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. A
A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking
Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channe
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who use Gate
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.
An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 p
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started