An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman c
An issue was discovered in rcp in MIT krb5-appl through 1.0.3. Due to the rcp implementation being derived from 1983 rcp
Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay netwo
A ZTE product has an information leak vulnerability. An attacker with higher authority can go beyond their authority to
A vulnerability was found in OVN Kubernetes in versions up to and including 0.3.0 where the Egress Firewall does not rel
NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) ha
In checkSlicePermission of SliceManagerService.java, there is a possible resource exposure due to an incorrect permissio
OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers. The `-
KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus p
The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi
kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure o
This issue was addressed with improved checks. This issue is fixed in Security Update 2022-001 Catalina, macOS Big Sur 1
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monterey 12.1. A device ma
Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client appl
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changi
Opencast is a free, open-source platform to support the management of educational audio and video content. In Opencast b
In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have cod
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It improperly handled account blocks
Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated
Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated
Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac
1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access t
The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node
Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry
Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before
Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authentica
The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contrib
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessi
IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS poli
In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.
Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vul
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the cat
It was possible for some users without permission to view other users' full names to do so via the online users block in
When creating a user account, it was possible to verify the account without having access to the verification email link
Pion WebRTC before 3.0.15 didn't properly tear down the DTLS Connection when certificate verification failed. The PeerCo
GistPad before 0.2.7 allows a crafted workspace folder to change the URL for the Gist API, which leads to leakage of Git
The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before versio
The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center befor
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cro
The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not p
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.22), Mendix Applications
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Co
ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and af
WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make
Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving u
The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upl
An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have in
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started