Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-863

MITRE ↗

Incorrect Authorization

351
CRITICAL
1,194
HIGH
1,775
MEDIUM
193
LOW
3,657 CVEs · Page 38/74
8.6
CVE-2024-44270

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, ma

8.5
CVE-2024-9693

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 pr

8.4
CVE-2024-34346

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may be unexpectedly wea

8.4
CVE-2024-39690

Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner ca

8.4
CVE-2024-48541

Incorrect access control in the firmware update and download processes of Ruochan Smart v4.4.7 allows attackers to acces

8.4
CVE-2024-48542

Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows att

8.4
CVE-2024-48544

Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to

8.4
CVE-2024-48545

Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access se

8.4
CVE-2024-48546

Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access se

8.4
CVE-2024-48547

Incorrect access control in the firmware update and download processes of DreamCatcher Life v1.8.7 allows attackers to a

8.3
CVE-2023-51761

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass a

8.3
CVE-2024-38869

Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configu

8.2
CVE-2024-27933

Deno is a JavaScript, TypeScript, and WebAssembly runtime. In version 1.39.0, use of raw file descriptors in `op_node_ip

8.2
CVE-2023-51405

Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Con

8.2
CVE-2024-32983

Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSO

8.2
CVE-2024-8970

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 pr

8.1
CVE-2024-27105

Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed

8.1
CVE-2024-31452

OpenFGA is a high-performance and flexible authorization/permission engine. Some end users of OpenFGA v1.5.0 or later ar

8.1
CVE-2024-27312

Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged use

8.1
CVE-2024-37300

OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub <

8.1
CVE-2024-21149

Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Work Definition I

8.1
CVE-2024-7624

The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and

8.1
CVE-2024-41964

Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users o

8.1
CVE-2024-45588

This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on A

8.1
CVE-2024-47078

Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an interne

8.1
CVE-2024-47183

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Ser

8.1
CVE-2024-21265

Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Site Hierarchy Flows). Supported ve

8.1
CVE-2024-21266

Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price List). Supported vers

8.1
CVE-2024-21267

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported ve

8.1
CVE-2024-21268

Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Diagnostics). Supported

8.1
CVE-2024-21269

Vulnerability in the Oracle Incentive Compensation product of Oracle E-Business Suite (component: Compensation Plan). S

8.1
CVE-2024-21270

Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Tasks). Support

8.1
CVE-2024-21271

Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Field Service Engineer Portal).

8.1
CVE-2024-21275

Vulnerability in the Oracle Quoting product of Oracle E-Business Suite (component: User Interface). Supported versions

8.1
CVE-2024-21276

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Messages). Supported version

8.1
CVE-2024-21277

Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integrat

8.1
CVE-2024-21278

Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (componen

8.1
CVE-2024-21279

Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (component: Auctions). Supported versions that

8.1
CVE-2024-21280

Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Authoring). Supported vers

8.1
CVE-2024-21282

Vulnerability in the Oracle Financials product of Oracle E-Business Suite (component: Common Components). Supported ver

8.1
CVE-2024-21283

Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payro

8.1
CVE-2024-3379

In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to

8.1
CVE-2024-45106

Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos us

8.0
CVE-2024-2378

A vulnerability exists in the web-authentication component of the SDM600. If exploited an attacker could escalate privil

8.0
CVE-2024-44667

Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to In

8.0
CVE-2024-45260

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users w

8.0
CVE-2024-45261

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID

7.8
CVE-2024-22938

Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate pri

7.8
CVE-2024-1155

Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authentic

7.8
CVE-2024-1156

Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ

Frequently Asked Questions

What is CWE-863?

CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-863?

There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.

How can I protect against CWE-863 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.

Detect CWE-863 Vulnerabilities

CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.

Get Started