An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requiremen
Windows AD FS Security Feature Bypass Vulnerability
The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX a
Pomerium is an open source identity-aware access proxy. In affected versions changes to the OIDC claims of a user after
Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. I
An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Repo
Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability.
Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL m
An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.
An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables whi
Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.
Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary ac
Unauthorized information security disclosure vulnerability on Micro Focus Directory and Resource Administrator (DRA) pro
A certain template role in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 710, 71
Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in Net
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can u
There is a logic error vulnerability in several smartphones. The software does not properly restrict certain operation w
A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application se
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidd
A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote atta
An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed t
In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.
A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to c
A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Leve
Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed an attacker who con
The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had per
M-System DL8 series (type A (DL8-A) versions prior to Ver3.0, type B (DL8-B) versions prior to Ver3.0, type C (DL8-C) ve
An incorrect permission check in Jenkins Role-based Authorization Strategy Plugin 3.1 and earlier allows attackers with
An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demote
By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to
Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an attacker who convinced a
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could
A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the na
Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass co
Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac
When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prev
When styling and rendering an oversized `<select>` element, Firefox did not apply correct clipping which allowed an atta
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthor
Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to a
Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD
A call termination issue with was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A lega
Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by que
Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the sev
An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14
A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications
The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and meta
bookstack is vulnerable to Improper Access Control
The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users
Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 1
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started