Avast Premium Security Sandbox Protection Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability
In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a lo
An authorization issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.5, macOS
MSI Afterburner v4.6.6.16381 Beta 3 is vulnerable to an ACL Bypass vulnerability in the RTCore64.sys driver, which leads
In the Linux kernel, the following vulnerability has been resolved: tracefs: Reset permissions on remount if permission
This issue was addressed with improved permissions checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sono
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows
Logsign Unified SecOps Platform Incorrect Authorization Authentication Bypass Vulnerability. This vulnerability allows l
This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 16. A malicious application may gain
RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is ex
OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions t
The application Sensei Mac Cleaner contains a local privilege escalation vulnerability, allowing an attacker to perform
In installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This could lead to local esca
Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local
An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to
IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 through 8.1.22.0 could allow a remote a
Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume cr
Harbor fails to validate the user permissions when updating tag retention policies. By sending a request to update a t
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.Thi
Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service i
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization
OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability e
The VerifiedBoot module has a vulnerability that may cause authentication errors.Successful exploitation of this vulnera
Permission control vulnerability in the package management module.Successful exploitation of this vulnerability may affe
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting t
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Arch
Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to
An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.
An issue in Flipsnack v.18/03/2024 allows a local attacker to obtain sensitive information via the reader.gz.js file.
DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameter
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization
Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior t
In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior
A vulnerability in Pantera CRM versions 401.152 and 402.072 allows unauthorized attackers to bypass IP-based access cont
OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when cal
Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A non-privilege
An issue in Hideez com.hideez 2.7.8.3 allows a remote attacker to obtain sensitive information via the firmware update p
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia
A vulnerability has been identified in SIMATIC CP 1543-1 V4.0 (6GK7543-1AX10-0XE0) (All versions >= V4.0.44 < V4.0.50).
The python_food ordering system V1.0 has an unauthorized vulnerability that leads to the leakage of sensitive user infor
python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of us
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Pro
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started