wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and
Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to b
OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementatio
Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(1
An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications
An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart-proxy allows foreman cli
An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting fro
Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS prior to 100.0.4896.60 allowed a local at
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering
UnsafeAccessor (UA) is a bridge to access jdk.internal.misc.Unsafe & sun.misc.Unsafe. Normally, if UA is loaded as a nam
An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, an
A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive Security Appliance (
The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Lo
Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3.
A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of th
Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted.
The issue was addressed with additional permissions checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11
Ree6 is a moderation bot. This vulnerability would allow other server owners to create configurations such as "Better-Au
A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in macOS
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver
Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.
The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any cu
The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any cu
A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is re
When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all ver
Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a membe
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks
The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, al
Windows Mark of the Web Security Feature Bypass Vulnerability
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2
Jenkins Pipeline: Shared Groovy Libraries Plugin 564.ve62a_4eb_b_e039 and earlier, except 2.21.3, allows attackers able
This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an
A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown
The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper author
DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui
HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker En
Smart eVision has insufficient authorization for task acquisition function. An unauthorized remote attacker can exploit
Saleor is a headless, GraphQL commerce platform. In affected versions some GraphQL mutations were not properly checking
Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addre
Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method
IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows g
aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PH
Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerabl
ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneousl
gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alte
OSIsoft PI Vision 2020 versions prior to 3.5.0 could disclose information to a user with insufficient privileges for an
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started