An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin c
In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur und
The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versi
The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing c
The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing at
The allows any authenticated user to join a private group due to a missing authorization check on a function
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue co
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in t
This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on c
Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows aut
authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one appl
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vu
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are
Archer Platform 2024.03 before version 2024.09 is affected by an API authorization bypass vulnerability related to suppo
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerl
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypa
An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4
baltic-it TOPqw Webportal v1.35.283.2 is vulnerable to Incorrect Access Control in the User Management function in /Apps
An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 b
A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. Th
Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated
Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allo
Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access c
An issue was discovered where improper authorization controls affected certain queries that could allow a malicious acto
SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary au
The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, su
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows
This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on
The AWS Cloud Development Kit (CDK) is an open-source framework for defining cloud infrastructure using code. Customers
Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authentic
Harbor fails to validate the user permissions when updating tag immutability policies. By sending a request to update
IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can
The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do
Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.
Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not Properly Constrained by ACLs.T
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this iss
A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace
When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly autho
Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in M
Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code a
ZITADEL, open source authentication management software, uses Go templates to render the login UI. Under certain circums
Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citr
Information disclosure while sending implicit broadcast containing APP launch information.
An access control vulnerability was discovered in the Reports section due to a specific access restriction not being pro
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users to be considered
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started