Improper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows attackers to read s
Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update th
A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client creden
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault
Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user
A vulnerability, which was classified as problematic, was found in jvvlee MerlinsBoard. This affects an unknown part of
Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL c
Mattermost WelcomeBot plugin fails to to validate the membership status when inviting or adding users to channels allowi
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting fr
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python
The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17, watchOS 10, iOS 16.7 and iPad
An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 b
An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods
Mattermost fails to properly check the authorization of POST /api/v4/teams when passing a team override scheme ID in the
Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments.
IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insuffic
An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting fr
An issue has been discovered in GitLab affecting all versions starting from 12.1 before 16.4.3, all versions starting fr
An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting
Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker to craft a task
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that
Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manag
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be re
An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device ve
Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are
Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action,
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public field
Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JS
Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.
Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an a
After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user
aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to uplo
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can ea
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POS
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST reque
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST reque
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypas
Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applica
An access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a cra
Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove
An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client
An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created v
Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with spr
Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrit
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management fram
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=a
Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started