bookstack is vulnerable to Improper Access Control
Improper Access Control in Pypi calibreweb prior to 0.6.16.
The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publi
In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the auth
Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 all
The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_r
The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclo
Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a
Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navi
The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "
The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the re
Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redi
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it whe
Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with t
Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1
fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams featu
HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password b
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be
A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote att
Incorrect access control in Yubico OTP functionality of the YubiKey hardware tokens along with the Yubico OTP validation
Improper Access Control in GitHub repository publify/publify prior to 9.2.8.
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 be
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 be
Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime
Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 p
Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administr
OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK
IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 thro
Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that custo
Smart eVision has inadequate authorization for the database query function. A remote attacker with general user privileg
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and We
Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a
An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Supp
The user_token authorization header on the Ourphoto App version 1.4.1 /apiv1/* end-points is not implemented properly. R
The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authori
The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4
The Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin WordPress plugin before 2.46 does not
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 7.24 does not
SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensi
If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so,
An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was ze
Sourcegraph is an opensource code search and navigation engine. It is possible for an authenticated Sourcegraph user to
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 befor
Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Informati
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started