Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different
OpenFGA is a high-performance authorization/permission engine inspired by Google Zanzibar. Versions prior to 0.2.5 are v
Incorrect authorization vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C55
Secure Boot Security Feature Bypass Vulnerability
A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE
Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8
The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view othe
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. I
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API en
An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 bef
An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit an
The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated use
Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Next
In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of p
Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 al
Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without ha
Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course b
Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting f
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions
A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Contro
Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any
An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read pe
Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing att
Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier does not correctly perform a permission check in an HTTP endpo
The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivi
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allo
Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible fo
eLabFTW is an electronic lab notebook manager for research teams. A vulnerability was discovered which allows a logged i
An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions s
A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access so
Insufficient capability checks made it possible for teachers to download users outside of their courses.
app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information t
A vulnerability has been found in SourceCodester Simple Cold Storage Management System 1.0 and classified as problematic
A vulnerability classified as problematic has been found in SourceCodester Simple Cold Storage Management System 1.0. Af
A vulnerability, which was classified as problematic, was found in NodeBB up to 2.5.7. This affects an unknown part of t
A vulnerability classified as problematic was found in Hospital Management Center. Affected by this vulnerability is an
A vulnerability, which was classified as problematic, has been found in FeehiCMS. Affected by this issue is some unknown
A vulnerability was found in rickxy Stock Management System and classified as problematic. This issue affects some unkno
A vulnerability classified as problematic has been found in CTF-hacker pwn. This affects an unknown part of the file del
A vulnerability was found in annyshow DuxCMS 2.1. It has been declared as problematic. This vulnerability affects unknow
A vulnerability was found in morontt zend-blog-number-2. It has been classified as problematic. Affected is an unknown f
Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14
Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14
Adobe Experience Manager version 6.5.14 (and earlier) is affected by an Incorrect Authorization vulnerability that could
BigBlueButton is an open source web conferencing system. Versions prior to 2.4.0 expose sensitive information to Unautho
A vulnerability was found in sah-comp bienlein and classified as problematic. This issue affects some unknown processing
A vulnerability was found in Pengu. It has been declared as problematic. Affected by this vulnerability is the function
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started