When a notification relating to low battery appears for a user with whom the device has been shared, tapping the notific
Incorrect Authorization vulnerability in OpenText™ GroupWise allows Exploiting Incorrectly Configured Access Control Sec
VoidBot Open-Source is a customizable Discord bot. VoidBot Open-Source versions 0.0.1 through 0.8.1 contain a vulnerabil
An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous at
A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client author
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4.
A security issue exists within the 5032 16pt Digital Configurable module’s web server. The web server’s session number i
Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to obtain informat
Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to change other us
Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Securit
The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private to the application its
The Sparkle framework includes a helper tool Autoupdate. Due to lack of authentication of connecting clients a local unp
Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated
An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw i
Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated
A security issue was discovered within Verve Asset Manager allowing unauthorized read-only users to read, update, and de
In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, whe
The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows
Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private
KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Re
When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates
When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task c
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote att
Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficien
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony E
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The content of
Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detect
In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via the Direct Web Remoting
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0,
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. I
The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checkin
An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentif
Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attac
In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to a
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affec
Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained b
Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining th
it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are re
Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.
HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML in
Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration fi
Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality
An Incorrect Access Control issue in SAMPMAX com.sampmax.homemax 2.1.2.7 allows a remote attacker to obtain sensitive in
Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enable
Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_log
WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.
Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the
A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attacker
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started