Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. Afte
GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in
A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an
In hasPermissions of PermissionMonitor.java, there is a possible access to restricted permissions due to a permissions b
In various methods of PackageManagerService.java, there is a possible permission bypass due to a missing condition for s
In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to bec
Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechan
A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All ve
OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories.
A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticate
A vulnerability in the persistent Telnet/Secure Shell (SSH) CLI of Cisco IOS XE Software could allow an authenticated, l
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on t
A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro)
In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead to local escalation
openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation servic
In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the
In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration i
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version 1.0.3, malicious users are able to op/voice and t
Red Discord Bot before version 3.4.1 has an unauthorized privilege escalation exploit in the Mod module. This exploit al
Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versi
In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the
In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a v
Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attacke
An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /lo
Dell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations. An a
controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/w
An issue was discovered on Samsung mobile devices with N(7.0) software. With the Location permission for the compass fea
The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restri
There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create speci
Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulner
qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed t
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (with TEEGRIS) software. Secure Folde
An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13
A security misconfiguration exists in Combodo iTop, which can expose sensitive information.
An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some sit
A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 through 2.3+ allows remote attackers to by
An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of acto
An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even wh
In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capab
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version
If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-d
PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the a
Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity P
Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecu
A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthoriz
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv
A security bypass vulnerability exists in Symantec Norton App Lock 1.0.3.186 and earlier if application pinning is enabl
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started