On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a craf
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strton
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Conn
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the
cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthe
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary fi
An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability."
An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows att
An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that
During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of secur
Banking services from SAP 9.0 (FSAPPL version 5) and SAP S/4HANA Financial Products Subledger (S4FPSL, version 1) perfor
Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers t
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to insufficient checking
A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote a
Linear eMerge E3-Series devices allow Privilege Escalation.
In FreeBSD 12.0-STABLE before r349628, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349629, 11.3-RC3 bef
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attack
A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default par
In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via sh
Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-F
Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-F
Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert sy
An issue was discovered in gsi-openssh-server 7.9p1 on Fedora 29. If PermitPAMUserChange is set to yes in the /etc/gsiss
The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if
Improper authorization involving a fuse in TrustZone in snapdragon automobile, snapdragon mobile and snapdragon wear in
Insufficient file permissions checking in install routine for Intel(R) Data Center Manager SDK before version 5.0.2 may
Check Point ZoneAlarm version 15.3.064.17729 and below expose a WCF service that can allow a local low privileged user t
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level
A vulnerability in the user account management interface of Cisco NX-OS Software could allow an authenticated, local att
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Wind
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properl
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not prop
In checkAccess of SliceManagerService.java in Android 9, there is a possible permissions check bypass due to incorrect o
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on
v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged user
xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH envir
The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remot
In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token
An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExt
An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintention
A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass beca
The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, witho
A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user w
asterisk allows calls on prohibited networks
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started