When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments p
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manil
NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using
@keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0
Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to
Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upl
A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user a
Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.
A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another i
Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to pri
Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim
ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is
Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=sy
An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked acc
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role wi
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp
An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a c
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorr
Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to version 0.1.3, a ServiceAccount deployed
Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The
SENS v1.0 is vulnerable to Incorrect Access Control vulnerability.
ZITADEL combines the ease of Auth0 and the versatility of Keycloak.**Actions**, introduced in ZITADEL **1.42.0** on the
Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed con
Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr
A user with user level permission can access graphics protected region due to improper access control in register config
Improper Authorization in GitHub repository webmin/webmin prior to 1.990.
CometD is a scalable comet implementation for web messaging. In any version prior to 5.0.11, 6.0.6, and 7.0.6, internal
Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any
Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The install
The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_
In executeRequest of OverlayManagerService.java, there is a possible way to control fabricated overlays from adb shell d
AX3600 router sensitive information leaked.There is an unauthorized interface through luci to obtain sensitive informati
VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user
In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local esca
In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could
In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regai
In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation.
In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass.
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before
RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code
The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Syste
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started