GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6 are vulnerable to In
A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid infor
Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0,
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xx
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 11225
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 11225
The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can
AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive informat
The SDK for the MediaPlaybackController module has improper permission verification. Successful exploitation of this vul
An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Comme
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorr
nappropriate authorization vulnerability in the SettingsProvider module.Successful exploitation of this vulnerability ma
An issue was discovered in /cgi-bin/adm.cgi in WavLink WavRouter version RPT70HA1.x, allows attackers to force a factory
Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulnerability may affect
An access control issue in WebBoss.io CMS v3.7.0.1 allows attackers to access the Website Backup Tool via a crafted GET
Armeria is a microservice framework Spring supports Matrix variables. When Spring integration is used, Armeria calls Spr
The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by cre
The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64
Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerab
IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restricti
An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization
There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5
An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attack
TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral
Incorrect access control in the AdHoc User creation form of eMudhra emSigner v2.8.7 allows unauthenticated attackers to
Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication.
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affec
Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect servi
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affec
Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-li
An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system
TurboWarp is a desktop application that compiles scratch projects to JavaScript. TurboWarp Desktop versions prior to ver
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_admin
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote
KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate productio
Microsoft Publisher Security Feature Bypass Vulnerability
Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authoriz
In Progress WS_FTP Server before 8.8, it is possible for a host administrator to elevate their privileges via the admini
IS Decisions UserLock MFA 11.01 is vulnerable to authentication bypass using scheduled task.
The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to
DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.3
Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6
A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete a
A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. In affected versions there is a privilege escala
Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and ca
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started