oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: th
An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this
An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/
The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulne
An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.
Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this v
In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, crea
lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify
Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execut
An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management Sys
An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (ak
Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows
Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 clien
An issue in BURG-WCHTER KG de.burgwachter.keyapp.app 4.5.0 allows a remote attacker to obtain sensitve information via t
An issue in GIANT MANUFACTURING CO., LTD RideLink (tw.giant.ridelink) 2.0.7 allows a remote attacker to obtain sensitive
An issue in SWITCHBOT INC SwitchBot (com.theswitchbot.switchbot) 5.0.4 allows a remote attacker to obtain sensitive info
An issue in Revic Optics Revic Ops (us.revic.revicops) 1.12.5 allows a remote attacker to obtain sensitive information v
An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firm
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 1
Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value of the zeqp system bei
Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving soc
`discourse-microsoft-auth` is a plugin that enables authentication via Microsoft. On sites with the `discourse-microsoft
The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1
facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, when a user
Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, ar
Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to
Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access t
Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to
A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition
authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token me
Evmos is a decentralized Ethereum Virtual Machine chain on the Cosmos Network. Prior to version 19.0.0, a user can creat
AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default
Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.Privileged
Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP al
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enfor
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user
This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Tradi
This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on A
Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass
Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users crea
Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword
An issue in the WaterToken smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have
An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an
Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sens
In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.
An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. A remote
An issue was discovered on Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNE
A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and
An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started