NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authoriz
Incorrect Authorization vulnerability in NicheAddons Events Addon for Elementor allows Accessing Functionality Not Prope
A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-only pri
Vulnerabilities in the web-based management interface of ClearPass Policy Manager allow an attacker with read-only privi
Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the d
Windows Boot Manager Security Feature Bypass Vulnerability
An improper authorization vulnerability in Darktrace mobile app (Android) prior to version 6.0.15 allows disabled and lo
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In versions 0.2.15, 0.2.16 and 0.3.0
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without manda
An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting fr
Fluid is an open source Kubernetes-native distributed dataset orchestrator and accelerator for data-intensive applicatio
A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an una
A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR
A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a flaw in access contro
Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attacke
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions sta
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.3.0 and prior to
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.1, macOS Big Sur 11.
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be abl
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be abl
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4. An a
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Bi
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to b
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to b
Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infra
Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT
An issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause a persistent denial of service
An issue found in FlightAware v.5.8.0 for Android allows unauthorized apps to cause a persistent denial of service by ma
An issue found in Sleep v.20230303 for Android allows unauthorized apps to cause a persistent denial of service by manip
In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master passwo
This issue was addressed with improved data protection. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5
A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filt
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14. An app may
An app may be able to access protected user data. This issue is fixed in macOS Sonoma 14, macOS Ventura 13.6.1. The issu
In Settings, there is a possible way to control private DNS settings from a secondary user due to a permissions bypass.
An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persi
XWiki Platform is a generic wiki platform. Starting in version 3.0-milestone-1, it's possible to execute a script with t
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform
Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27 does not correctly perf
Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated
An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed i
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 o
Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300
An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authe
vantage6 is privacy preserving federated learning infrastructure. Prior to version 4.0.0, malicious users may try to get
vantage6 is privacy preserving federated learning infrastructure. The endpoint /api/collaboration/{id}/task is used to c
The myStickymenu WordPress plugin before 2.6.5 does not adequately authorize some ajax calls, allowing any logged-in use
The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing
Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass aut
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1,
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started