Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and exe
The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not imple
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly
GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.
A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution on upload and install pa
A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE e
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a
Incorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server b
VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly priv
Authentication bypass vulnerability in Qrio Lock (Q-SL2) firmware version 2.0.9 and earlier allows a network-adjacent at
A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another use
SGUDA U-Lock central lock control service’s lock management function has incorrect authorization. A remote attacker with
SGUDA U-Lock central lock control service’s user management function has incorrect authorization. A remote attacker with
Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensio
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying t
A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user t
An issue was discovered in Tildeslash Monit before 5.31.0, allows remote attackers to gain escilated privlidges due to i
TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerabilit
Improper authorisation of regular users in ProIntegra Uptime DC software (versions below 2.0.0.33940) allows them to cha
An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 throu
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earl
The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a miss
An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted reque
TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows atta
Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker wit
In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have ce
A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unaut
LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scop
Incorrect authorisation in ekorCCP and ekorRCI, which could allow a remote attacker to obtain resources with sensitive i
Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order
A vulnerability was found in KylinSoft kylin-activation on KylinOS and classified as critical. Affected by this issue is
An issue was discovered in Telindus Apsal 3.14.2022.235 b. Unauthorized actions that could modify the application behavi
IBM Administration Runtime Expert for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information
Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities.
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t
DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the defaul
KubeVirt is a virtual machine management add-on for Kubernetes. In versions 0.59.0 and prior, if a malicious user has ta
Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method.
Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenti
Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Function Worker. This issue affects A
Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF
An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions startin
An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.
The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbit
xCAT is a toolkit for deployment and administration of computer clusters. In versions prior to 2.16.5 if zones are confi
There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited
RIFARTEK IOT Wall has a vulnerability of incorrect authorization. An authenticated remote attacker with general user pri
Multiple components (such as Onlinetemplate-Verwaltung, Liste aller Teilbereiche, Umfragen anzeigen, and questionnaire p
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started