A vulnerability, which was classified as problematic, was found in phpRedisAdmin up to 1.17.3. This affects an unknown p
A vulnerability, which was classified as problematic, was found in katlings pyambic-pentameter. Affected is an unknown f
A vulnerability was found in destiny.gg chat. It has been rated as problematic. This issue affects the function websocke
Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS i
Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to And
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. T
fof/byobu is a private discussions extension for Flarum forum. Affected versions were found to not respect private discu
An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4,
Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions pr
A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly n
Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched
IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could all
In registerReceivers of DeviceCapabilityListener.java, there is a possible way to change preferred TTY mode due to a per
Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting f
An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6, and 2.5-alpha-1 contain Incorrect A
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows auth
Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares
OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incompl
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated atta
NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php
The REST/JSON project 7.x-1.x for Drupal allows node access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not c
The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is no
The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not
The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033. NOTE: This project is
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to bypass authentication by sending
LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured
Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. T
An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows a
vscode-restructuredtext before 146.0.0 contains an incorrect access control vulnerability, where a crafted project folde
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, mod
White Shark System (WSS) 1.3.2 is vulnerable to unauthorized access via user_edit_password.php, remote attackers can mod
Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise
There is a Permission Control Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause
A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a
Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain pri
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains s
UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page.
When creating temporary files, agent-to-controller access to create those files is only checked after they've been creat
This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the securit
Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default i
Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a
ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of c
Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attacker
Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI
When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/p
IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform acti
An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before execu
This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions.
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started