Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associate
Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have no
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Incorrect Authorization v
Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The suppor
An authenticated data.all user is able to perform mutating UPDATE operations on persisted Notification records in data.a
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds th
A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a re
Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on W
Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles
A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak N
Incorrect authorization vulnerability in Alert.Setting webapi component in Synology Surveillance Station before 9.2.0-11
Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289
Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authen
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Le
A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to
Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privilege
Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause de
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization hea
The MSAL library enabled acquisition of security tokens to call protected APIs. MSAL.NET applications targeting Xamarin
Insufficient access controls in ASP kernel may allow a privileged attacker with access to AMD signing keys and the BIOS
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2
changedetection.io is an open source tool designed to monitor websites for content changes. In affected versions the AP
An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8
The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. T
There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of opera
Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based o
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17
BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web E
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 p
TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree wit
An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause de
Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can b
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize t
Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4
Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to
An authentication issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, m
ClickHouse is an open-source column-oriented database management system. A bug exists in the cloud ClickHouse offering p
In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restri
SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to execute a program that r
Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version
Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access o
Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-2 and prior to versions 14.10.4 and 15.0-rc
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t
Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authent
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started