Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3
In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apach
RigoBlock Dragos through 2022-02-17 lacks the onlyOwner modifier for setMultipleAllowances. This enables token manipulat
The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-
Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.
An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password functi
On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which m
The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its end
On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of
ecjia-daojia 1.38.1-20210202629 is vulnerable to information leakage via content/apps/installer/classes/Helper.php. When
EOSIO batdappboomx v327c04cf has an Access-control vulnerability in the `transfer` function of the smart contract which
The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CS
Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in t
An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via vie
Zammad 5.2.0 suffers from Incorrect Access Control. Zammad did not correctly perform authorization on certain attachment
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and und
smart eVision has inadequate authorization for system information query function. An unauthenticated remote attacker, wh
An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups
socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffe
In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated a
D-Link – G integrated Access Device4 Information Disclosure & Authorization Bypass. *Information Disclosure – file con
D-Link DIR-869 DIR869Ax_FW102B15 is vulnerable to Authentication Bypass via phpcgi.
Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has
Windows Boot Manager Security Feature Bypass Vulnerability
A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing atta
A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather cred
ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privilege
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTT
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submit
A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an att
A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an att
On BIG-IQ Centralized Management 8.x before 8.1.0, an authenticated administrative role user on a BIG-IQ managed BIG-IP
controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb53830
Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vul
An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. The ScriptInvoke function
The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the s
Talos Linux is a Linux distribution built for Kubernetes deployments. Talos worker nodes use a join token to get accepte
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server
Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0.
An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients
Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3
An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information
An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive informatio
Improper Access Control vulnerability in the /Exago/WrImageResource.adx route as used in Device42 Asset Management Appli
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions p
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access priv
In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassi
A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow
Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a loca
Exposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13) allows local attack
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started