In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of th
In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to ad
Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location wh
Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is
Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data.
Incorrect Authorization vulnerability in OpenText™ ZENworks Configuration Management (ZCM) allows Unauthorized Use of De
While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correc
An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploite
Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p p
Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution
SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not per
Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting
A vulnerability has been found in didi DDMQ 1.0 and classified as critical. Affected by this vulnerability is an unknown
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Script Engine). Supported versions tha
CloudStack account-users by default use username and password based authentication for API and UI access. Account-users
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create n
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions
Incorrect Authorization vulnerability in Bit Apps Bit Form Pro bitformpro allows Accessing Functionality Not Properly Co
A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated Glob
Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: R
Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: R
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the la
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain a
Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to page
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate
Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system c
Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spo
In lunary-ai/lunary version 1.2.4, an improper access control vulnerability allows members with team management permissi
Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-pri
Pomerium is an identity and context-aware access proxy. The Pomerium databroker service is responsible for managing all
Access permission verification vulnerability in the App Multiplier module Impact: Successful exploitation of this vulner
In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permission
An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. An attacker within RF range can obtain a cleartext copy
phpMyFAQ is an Open Source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The 'sharing FAQ'
An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In project
Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3,
Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited us
In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles
An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter rel
In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users w
The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow us
Tolgee is an open-source localization platform. When API key created by admin user is used it bypasses the permission ch
Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git re
The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and
Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtainin
Incorrect Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Inclusi
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Com
In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their p
In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started