The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 an
Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access c
A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without adminis
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authentic
In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO auth
The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform
Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow una
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can acces
The Windows Installation component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition
The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message S
The Windows Installation component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Editi
The Windows Installation component of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces -
The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Co
The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge -
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions pri
White Shark System (WSS) 1.3.2 has an unauthorized access vulnerability in default_user_edit.php, remote attackers can e
Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Contr
An issue exists within the SSH console of Akkadian Provisioning Manager 4.50.02 which allows a low-level privileged user
An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of t
HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API
In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user
Blacklist bypass issue exists in WUZHI CMS up to and including 4.1.0 in common.func.php, which when uploaded can cause r
Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_
The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber role
An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras tha
Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "
An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote att
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. A
An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon
Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to
Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to by
MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user wit
This issue was addressed by disabling execution of JavaScript when viewing a scripting dictionary. This issue is fixed i
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affe
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affe
Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization re
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across micr
Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 all
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due
NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply indi
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direc
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corres
BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2
a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow ed
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authe
Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenti
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started