Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-863

MITRE ↗

Incorrect Authorization

351
CRITICAL
1,194
HIGH
1,775
MEDIUM
193
LOW
3,657 CVEs · Page 4/74
8.8
CVE-2026-7387

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to req

8.8
CVE-2026-53828

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authentic

8.8
CVE-2016-20075

WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users

8.8
CVE-2026-56075

PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode appro

8.8
CVE-2026-56424

MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong ent

8.8
CVE-2026-56232

Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited

8.8
CVE-2026-54998

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

8.8
CVE-2026-27775

Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allo

8.8
CVE-2026-14536

Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attack

8.8
CVE-2026-56086

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r

8.8
CVE-2026-15125

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbi

8.8
CVE-2026-57215

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindi

8.8
CVE-2026-1359

The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due t

8.8
CVE-2026-62190

OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-t

8.8
CVE-2026-47303

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over

8.8
CVE-2026-55242

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated use

8.8
CVE-2026-63085

Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticate

8.8
CVE-2026-62202

OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allow

8.8
CVE-2026-62217

OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the f

8.8
CVE-2026-62223

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows

8.8
CVE-2026-62228

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust ca

8.8
CVE-2025-71390

SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames agains

8.8
CVE-2026-59851

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the

8.8
CVE-2026-65015

n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-executio

8.8
CVE-2026-65601

Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider.

8.8
CVE-2026-65602

Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRo

8.8
CVE-2026-17568

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-adm

8.8
CVE-2026-14167

A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level inclu

8.8
CVE-2026-69118

Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows

8.8
CVE-2026-62872

Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.

8.8
CVE-2026-71387

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the

8.8
CVE-2026-49473

@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization in

8.8
CVE-2026-73305

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRo

8.8
CVE-2026-73841

OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchore

8.8
CVE-2026-72831

The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in it

8.8
CVE-2026-61574

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list r

8.8
CVE-2026-48508

Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/aut

8.8
CVE-2026-70408

An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has adm

8.8
CVE-2026-68561

Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permiss

8.8
CVE-2026-77234

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to exec

8.8
CVE-2026-76836

AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission gu

8.8
CVE-2026-49050

General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2

8.8
CVE-2026-80202

Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions

8.8
CVE-2026-55485

Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0,

8.6
CVE-2026-31998

OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plu

8.6
CVE-2026-32173

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.

8.6
CVE-2026-55638

9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/da

8.6
CVE-2026-47988

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A

8.6
CVE-2026-48396

Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the cont

8.5
CVE-2025-69414

Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call wit

Frequently Asked Questions

What is CWE-863?

CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-863?

There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.

How can I protect against CWE-863 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.

Detect CWE-863 Vulnerabilities

CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.

Get Started