If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabl
Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 Feb
A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a leg
In "I hate money" before version 4.1.5, an authenticated member of one project can modify and delete members of another
An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets.
SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in some reports. Althoug
A vulnerability in the 802.1X feature of Cisco Catalyst 2960-L Series Switches and Cisco Catalyst CDB-8P Switches could
Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem perm
Improper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authentic
In updateIncomingFileConfirmNotification of BluetoothOppNotification.java, there is a possible permissions bypass. This
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient
A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which co
Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) doe
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage cha
Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is op
The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal
IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated
A missing permission check in Jenkins Mac Plugin 1.1.0 and earlier allows attackers with Overall/Read permission to conn
An issue was discovered in GitLab Community and Enterprise Edition 11.9 and later through 12.0.2. GitLab Snippets were v
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any gi
RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote
A missing permission check in Jenkins Amazon EC2 Plugin 1.50.1 and earlier in form-related methods allowed users with Ov
IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote a
The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before v
A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote a
A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote a
The l10nmgr (aka Localization Manager) extension before 7.4.0, 8.x before 8.7.0, and 9.x before 9.2.0 for TYPO3 allows I
Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controll
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer
Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP en
Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote a
Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account w
An Authorization Bypass vulnerability in the Marmind web application with version 4.1.141.0 allows users with lower priv
Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Ap
In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for
In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is
"In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The p
The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version
In OMERO before 5.6.1, group owners can access members' data in other groups.
An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (
An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a mis
In AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege allowin
HUAWEI Mate 20 smartphones with versions earlier than 10.0.0.195(SP31C00E74R3P8) have an improper authorization vulnerab
The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition
In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator. However,
Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitra
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly se
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted databas
On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protec
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started