Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locall
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, Identity
Windows Lock Screen Security Feature Bypass Vulnerability
A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.
Incorrect Authorization vulnerability in Mobatime web application allows Privilege Escalation, Exploiting Incorrectly Co
Sentry is an error tracking and performance monitoring platform. Starting in version 23.6.0 and prior to version 23.6.2,
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access priv
An issue was discovered in TECHView LA5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated priv
An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant
An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain esca
Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechani
Secure Boot Security Feature Bypass Vulnerability
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to th
In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below syste
Improper access control in the Intel(R) CSME software installer before version 2239.3.7.0 may allow an authenticated use
Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user mana
Windows Boot Manager Security Feature Bypass Vulnerability
The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing u
AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in c
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository-scoped tok
Inappropriate implementation in in Permission prompts in Google Chrome on Android prior to 109.0.5414.74 allowed a remot
Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0.
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information
Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to ac
Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9
Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior ver
The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gain
Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of dat
The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4
DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.3
An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid param
An issue in Zammad v5.4.0 allows attackers to bypass e-mail verification using an arbitrary address and manipulate the d
There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured c
A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromS
A Mazda model (2015-2016) can be unlocked via an unspecified method.
GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8
GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG thro
Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with
An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntime
In imgsys, there is a possible system crash due to a mssing ptr check. This could lead to local escalation of privilege
Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Inc
An access control vulnerability was found, due to the restrictions that are applied on actual assertions not being enfor
1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, authenticated attack
Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete ot
In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password.
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started