Brother MFC-9970CDW 1.10 firmware L devices contain a security bypass vulnerability which allows physically proximate at
A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoa
In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant
There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorizat
A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket c
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the se
An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval
In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations
IBM Security Identity Governance and Intelligence 5.2.6 could disclose highly sensitive information to other authenticat
A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed i
Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decis
In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass a
A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read
Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI
By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access t
SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected re
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can st
HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read th
An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On
Veritas APTARE versions prior to 10.4 did not perform adequate authorization checks. An authenticated user could gain un
An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later
An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of
Philips SureSigns VS4, A.07.107 and prior does not restrict or incorrectly restricts access to a resource from an unaut
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow a
OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the
A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could all
In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/gr
zrlog v2.1.0 has a vulnerability with the permission check. If admin account is logged in, other unauthorized users can
An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct
In getProcessPss of ActivityManagerService.java, there is a possible side channel information disclosure. This could lea
A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attac
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3
A vulnerability in the CLI parser of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local at
Improper authorization in DSP process could allow unauthorized users to downgrade the library versions in SD820, SD821,
An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of t
IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM
HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resu
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. It is intended to support restriction of availa
An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server al
A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated,
A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Ci
In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal we
The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control.
<p>An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.</p> <p>An unauthentic
BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface.
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Th
A logic issue was addressed with improved validation. This issue is fixed in Safari 13.0.5. A URL scheme may be incorrec
Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started