Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-863

MITRE ↗

Incorrect Authorization

351
CRITICAL
1,194
HIGH
1,775
MEDIUM
193
LOW
3,657 CVEs · Page 41/74
6.5
CVE-2024-3504

An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin c

6.5
CVE-2024-3404

In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper

6.5
CVE-2022-45168

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur und

6.5
CVE-2024-4390

The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versi

6.5
CVE-2024-1639

The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing c

6.5
CVE-2024-5071

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing at

6.5
CVE-2024-2231

The allows any authenticated user to join a private group due to a missing authorization check on a function

6.5
CVE-2024-5817

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue co

6.5
CVE-2024-6337

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only

6.5
CVE-2024-20466

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat

6.5
CVE-2024-45509

In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in t

6.5
CVE-2024-8601

This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on c

6.5
CVE-2024-6512

Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows aut

6.5
CVE-2024-47077

authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one appl

6.5
CVE-2024-45132

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vu

6.5
CVE-2024-21262

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are

6.5
CVE-2024-49209

Archer Platform 2024.03 before version 2024.09 is affected by an API authorization bypass vulnerability related to suppo

6.5
CVE-2024-20482

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerl

6.5
CVE-2024-20537

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypa

6.5
CVE-2024-44765

An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4

6.5
CVE-2024-45877

baltic-it TOPqw Webportal v1.35.283.2 is vulnerable to Incorrect Access Control in the User Management function in /Apps

6.5
CVE-2024-11669

An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 b

6.5
CVE-2024-42451

A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. Th

6.5
CVE-2024-12196

Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated

6.5
CVE-2024-53949

Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allo

6.5
CVE-2024-55633

Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access c

6.5
CVE-2024-12539

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious acto

6.4
CVE-2024-21736

SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary au

6.4
CVE-2024-28098

The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, su

6.4
CVE-2023-50726

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows

6.4
CVE-2024-29834

This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on

6.4
CVE-2024-45037

The AWS Cloud Development Kit (CDK) is an open-source framework for defining cloud infrastructure using code. Customers

6.4
CVE-2022-31667

Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authentic

6.4
CVE-2022-31669

Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update

6.3
CVE-2023-47716

IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges

6.3
CVE-2024-27288

1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can

6.3
CVE-2024-1677

The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is

6.3
CVE-2024-39871

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do

6.3
CVE-2024-6358

Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.

6.3
CVE-2024-43954

Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not Properly Constrained by ACLs.T

6.3
CVE-2024-9082

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this iss

6.3
CVE-2024-9902

A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace

6.2
CVE-2024-24966

When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly autho

6.2
CVE-2024-34651

Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in M

6.2
CVE-2024-48540

Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code a

6.1
CVE-2024-29892

ZITADEL, open source authentication management software, uses Go templates to render the login UI. Under certain circums

6.1
CVE-2024-42423

Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citr

6.1
CVE-2024-38425

Information disclosure while sending implicit broadcast containing APP launch information.

6.0
CVE-2024-4465

An access control vulnerability was discovered in the Reports section due to a specific access restriction not being pro

5.9
CVE-2024-34701

CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users to be considered

Frequently Asked Questions

What is CWE-863?

CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-863?

There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.

How can I protect against CWE-863 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.

Detect CWE-863 Vulnerabilities

CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.

Get Started