File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymak
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS d
A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an
OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scop
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configur
Netmaker makes networks with WireGuard. Prior to version 1.5.0, the Authorize middleware in Netmaker incorrectly validat
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password res
Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, w
OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family re
OpenClaw before 2026.3.25 contains an improper access control vulnerability in the HTTP /sessions/:sessionKey/kill route
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSe
OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that all
An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restric
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an adminis
Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permission
OpenClaw before 2026.4.8 contains a security bypass vulnerability in node.invoke(browser.proxy) that allows mutation of
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t
Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related auth
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organiz
efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is int
Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST A
The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged
RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level
Budibase is an open-source low-code platform. Prior to 3.39.0, the single-datasource GET and PUT routes are guarded by g
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, when a PAM service is
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a sha
An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a
Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handli
OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict
Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under defaul
ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderCon
Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic
Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repos
Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any aut
FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows authenticated
OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A low
OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Fe
OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that a
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the con
OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created wit
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started