On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) o
Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on
Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider
Agents are able to list appointments in the calendars without required permissions. This issue affects: OTRS AG ((OTRS))
Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting f
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under c
Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorise
Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorise
PI Vision could disclose information to a user with insufficient privileges for an AF attribute that is the child of ano
Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from
Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions sta
Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybri
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP addre
The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows attackers to bypass intend
In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation
A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Softw
In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoi
A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthentic
Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix Xe
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (whic
Veritas APTARE versions prior to 10.5 did not perform adequate authorization checks. This vulnerability could allow for
Verax NMS prior to 2.1.0 has multiple security bypass vulnerabilities
obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation.
A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. Thi
Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing at
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.130 allowed a remote attacker who had
Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor
Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls
An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows acc
Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escala
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlin
A security feature bypass vulnerability exists when Windows fails to properly handle token relationships.An attacker who
An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user wi
A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary co
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 creden
A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a
Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in
A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remot
IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due t
REDDOXX MailDepot 2032 2.2.1242 allows authenticated users to access the mailboxes of other users.
In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated bu
In Mailu before version 1.7, an authenticated user can exploit a vulnerability in Mailu fetchmail script and gain full a
Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously do
Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to externa
An issue was discovered on Samsung mobile devices with N(7.x) software. Dex Station allows App Pinning bypass and lock-s
A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticate
MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to
btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which al
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started