A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, ma
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 pr
Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may be unexpectedly wea
Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner ca
Incorrect access control in the firmware update and download processes of Ruochan Smart v4.4.7 allows attackers to acces
Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows att
Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to
Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access se
Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access se
Incorrect access control in the firmware update and download processes of DreamCatcher Life v1.8.7 allows attackers to a
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass a
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configu
Deno is a JavaScript, TypeScript, and WebAssembly runtime. In version 1.39.0, use of raw file descriptors in `op_node_ip
Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Con
Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSO
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 pr
Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed
OpenFGA is a high-performance and flexible authorization/permission engine. Some end users of OpenFGA v1.5.0 or later ar
Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged use
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub <
Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Work Definition I
The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and
Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users o
This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on A
Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an interne
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Ser
Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Site Hierarchy Flows). Supported ve
Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price List). Supported vers
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported ve
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Diagnostics). Supported
Vulnerability in the Oracle Incentive Compensation product of Oracle E-Business Suite (component: Compensation Plan). S
Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Tasks). Support
Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Field Service Engineer Portal).
Vulnerability in the Oracle Quoting product of Oracle E-Business Suite (component: User Interface). Supported versions
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Messages). Supported version
Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integrat
Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (componen
Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (component: Auctions). Supported versions that
Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Authoring). Supported vers
Vulnerability in the Oracle Financials product of Oracle E-Business Suite (component: Common Components). Supported ver
Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payro
In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to
Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos us
A vulnerability exists in the web-authentication component of the SDM600. If exploited an attacker could escalate privil
Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to In
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users w
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID
Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate pri
Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authentic
Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started