Inadequate validation of permissions when employing remote tools and macros via the context menu within Devolutions Re
In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows blocked users (bloc
Broken Access Control in Betheme theme <= 26.6.1 on WordPress.
An issue was discovered in Joomla! 4.0.0 through 4.2.4. A missing ACL check allows non super-admin users to access com_a
The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for several AJAX actions, only
thmmniii/fbs-core is an open source feedback system for students. In versions prior to 1.5.3 when querying `subresults`,
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorrect Authorization vul
An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting fr
Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized u
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated att
A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking
Versions of Sage 300 through 2022 implement role-based access controls that are only enforced client-side. Low-privilege
Operation restriction bypass vulnerability in MultiReport of Cybozu Garoon 5.15.0 allows a remote authenticated attacker
Improper access control vulnerability in the system date/time setting page of SolarView Compact SV-CPT-MC310 versions pr
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard
OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via
In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Bu
Android applications with unpatched vulnerabilities can be launched from a browser using Intents, exposing users to thes
Exposure of Sensitive Information to an unauthorized actor vulnerability in MB Connect Lines mbCONNECT24, mymbCONNECT24
Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download docum
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorr
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorr
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorr
A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and vi
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions sta
Mattermost fails to verify channel membership when linking a board to a channel allowing a low-privileged authenticated
The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficie
The FULL - Customer plugin for WordPress is vulnerable to Information Disclosure via the /health REST route in versions
An improper authorization vulnerability exists where an authenticated, low privileged remote attacker could view a list
The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowin
A non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset up
An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability all
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized
An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting fr
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting fr
An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16
The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing us
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then. Apache Airflow, versions b
An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting fr
An issue has been discovered in GitLab affecting all versions starting from 9.2 before 16.4.3, all versions starting fro
An issue was discovered in Zammad before 6.2.0. When listing tickets linked to a knowledge base answer, or knowledge bas
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0,
Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens displayed on the job con
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.11.15, 1.
Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, re
A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability al
An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated at
IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to securit
Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access u
Improper authorization verification vulnerability in Samsung Email prior to version 6.1.90.4 allows attackers to read sa
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started