Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to req
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authentic
WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users
PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode appro
MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong ent
Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allo
Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attack
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbi
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindi
The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due t
OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-t
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated use
Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticate
OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allow
OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the f
OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows
OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust ca
SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames agains
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the
n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-executio
Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider.
Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRo
Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-adm
A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level inclu
Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the
@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization in
Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRo
OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchore
The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in it
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list r
Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/aut
An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has adm
Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permiss
Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to exec
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission gu
General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2
Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0,
OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plu
Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.
9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/da
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the cont
Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call wit
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started