n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based cr
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a valida
Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELE
SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes auth
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag
An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileg
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-c
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds a
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues:
rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses co
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix o
A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role a
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H
Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromise
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that al
Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in
Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerabil
SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evalu
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable f
Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with
This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assi
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio
An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connectio
An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-suppl
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vuln
Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result
The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege esca
Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC)
The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory.
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file a
OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect wit
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9
In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead
Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. U
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Studio). Supported versions
A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization chec
is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged atta
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. From 1.3.0
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started