Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and
containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Event Notific
Infopop Ultimate Bulletin Board up to v5.47a was discovered to allow all messages posted inside private forums to be dis
Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request.
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check
SSPanel-Uim 2023.3 does not restrict access to the /link/ interface which can lead to a leak of user information.
Vulnerability of bypassing the default desktop security controls.Successful exploitation of this vulnerability may cause
Vulnerability of unauthorized access to foreground app information.Successful exploitation of this vulnerability may cau
Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenti
An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorr
An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open th
In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian versions, any user that has the ROLE_FIL
In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the
A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which c
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos 9820, Exynos 980, Ex
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Su
The admin panel for Obl.ong before 1.1.2 allows authorization bypass because the email OTP feature accepts arbitrary num
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to chan
The Strapi Protected Populate Plugin protects `get` endpoints from revealing too much information. Prior to version 1.3.
NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the defau
An attacker could create malicious requests to obtain sensitive information about the web server.
Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE a
Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Re
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends
Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 softwa
Improper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable d
Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentiall
Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the worksp
Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower
KernelSU is a Kernel based root solution for Android. Starting in version 0.6.1 and prior to version 0.7.0, if a KernelS
The Web Stories for WordPress plugin supports the WordPress built-in functionality of protecting content with a password
Wyse Management Suite versions prior to 4.0 contain an improper authorization vulnerability. An authenticated malicious
SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASI
The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installatio
Weak access control in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Se
Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be up
OpenSearch is open-source software suite for search, analytics, and observability applications. Prior to versions 1.3.10
Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from eleva
There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, app
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the
HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle dest
Windows SmartScreen Security Feature Bypass Vulnerability
IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect autho
A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow
In TBD of TBD, there is a possible way to access location information due to a permissions bypass. This could lead to lo
An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started