Red is a fully modular Discord bot. Due to a bug in Red's Core API, 3rd-party cogs using the `@commands.can_manage_chann
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App
The OpenTelemetry Collector module AWS firehose receiver is for ingesting AWS Kinesis Data Firehose delivery stream mess
An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.
A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Mo
A vulnerability was found in VIWIS LMS 9.11. It has been classified as critical. Affected is an unknown function of the
An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.
An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6
An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploite
Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows fo
SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit a
juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status cod
Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization
A vulnerability regarding incorrect authorization is found in the firmware upgrade functionality. This allows remote aut
app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensiti
An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.2.9, starting from 17.3 pr
A data.all admin team member who has access to the customer-owned AWS Account where data.all is deployed may be able to
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project source
A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could
OvalEdge 5.2.8.0 and earlier is affected by a Privilege Escalation vulnerability via a POST request to /user/assignuserr
SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave
Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access se
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1, macOS Ventur
Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updat
There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an
Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently
An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 b
Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or admini
The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which coul
Silverstripe Admin provides a basic management interface for the Silverstripe Framework. In versions on the 1.x branch p
sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected
A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then
The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu
Cross-Site Request Forgery (CSRF), Incorrect Authorization vulnerability in wpWax Legal Pages.This issue affects Legal P
Incorrect Authorization vulnerability in Supsystic Data Tables Generator.This issue affects Data Tables Generator: from
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions start
An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gute
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized loss of data due to a missing
In version 1.2.7 of lunary-ai/lunary, any authenticated user, regardless of their role, can change the name of an organi
A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote att
Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP al
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enfor
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the
The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the dup
An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting
In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a pro
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started