Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low-privileged user to impersonat
On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision co
XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in TOPdesk v12.10.12 allows bad actors with credential
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incor
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly whe
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the
Passwork before 6.2.0 allows remote authenticated users to bypass 2FA by sending all one million of the possible 6-digit
An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starti
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM o
In removePermission of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permissions withou
In getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible way to bypass DISALLOW_CO
In multiple functions of SensorService.cpp, there is a possible access of accurate sensor data due to a permissions bypa
In multiple functions of BackupHelper.java, there is a possible way for an app to get permissions previously granted to
A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.
In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restr
Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and
VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDM
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUp
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUp
Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 wind
In registerReceiverWithFeature of ActivityManagerService.java, there is a possible way for isolated processes to registe
The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain so
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows unauthorized apps to cause escalation of privileg
An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause an escalation of Privileges via the datab
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able
An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could a
An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could a
An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could a
there is a possible way to bypass the protected confirmation screen due to Failure to lock display power. This could lea
In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the loc
In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the
In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic err
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization
In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This
In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to l
API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs. Resource properties secured with
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2,
A vulnerability in the secure boot implementation on affected Aruba 9200 and 9000 Series Controllers and Gateways allows
An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically be
Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacke
Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authe
During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device t
The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with t
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started