Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-863

MITRE ↗

Incorrect Authorization

351
CRITICAL
1,194
HIGH
1,775
MEDIUM
193
LOW
3,657 CVEs · Page 7/74
8.1
CVE-2026-65596

n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based cr

8.1
CVE-2026-8789

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit

8.1
CVE-2026-42016

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a valida

8.1
CVE-2026-68581

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and

8.1
CVE-2026-70494

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELE

8.1
CVE-2026-72921

SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes auth

8.1
CVE-2026-18690

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag

8.1
CVE-2026-18712

An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileg

8.1
CVE-2026-47231

Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-c

8.1
CVE-2026-73286

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds a

8.1
CVE-2026-73289

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues:

8.1
CVE-2026-70463

rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses co

8.1
CVE-2026-24791

Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

8.1
CVE-2026-55987

OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix o

8.1
CVE-2026-19629

A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role a

8.1
CVE-2026-17429

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H

8.1
CVE-2026-76019

Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromise

8.1
CVE-2026-71506

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that al

8.1
CVE-2026-18985

Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in

8.1
CVE-2026-43621

Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerabil

8.1
CVE-2026-77317

SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evalu

8.1
CVE-2026-82463

pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the

8.0
CVE-2025-64421

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions

8.0
CVE-2026-20960

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

8.0
CVE-2026-32978

OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable f

8.0
CVE-2026-6290

Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with

8.0
CVE-2026-5712

This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assi

8.0
CVE-2026-35482

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio

8.0
CVE-2026-59689

An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connectio

7.9
CVE-2026-43001

An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-suppl

7.9
CVE-2026-17063

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vuln

7.8
CVE-2026-21274

Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result

7.8
CVE-2025-4960

The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege esca

7.8
CVE-2026-29126

Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC)

7.8
CVE-2026-29127

The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory.

7.8
CVE-2026-26141

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-39454

SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file a

7.8
CVE-2026-42432

OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect wit

7.8
CVE-2026-28951

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9

7.8
CVE-2025-32348

In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead

7.8
CVE-2026-21031

Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. U

7.8
CVE-2026-45490

Improper authorization in .NET allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-54555

rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter

7.8
CVE-2026-60625

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Studio). Supported versions

7.8
CVE-2026-7867

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization chec

7.8
CVE-2026-25652

is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged atta

7.8
CVE-2026-61925

Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-69278

Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

7.7
CVE-2026-31801

zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. From 1.3.0

7.7
CVE-2026-32123

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.

Frequently Asked Questions

What is CWE-863?

CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-863?

There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.

How can I protect against CWE-863 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.

Detect CWE-863 Vulnerabilities

CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.

Get Started