Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-863

MITRE ↗

Incorrect Authorization

351
CRITICAL
1,194
HIGH
1,775
MEDIUM
193
LOW
3,657 CVEs · Page 9/74
7.5
CVE-2026-46366

phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks pe

7.5
CVE-2026-3514

In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of UR

7.5
CVE-2026-53834

OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allow

7.5
CVE-2026-47777

Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in

7.5
CVE-2026-50559

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3,

7.5
CVE-2026-54091

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec

7.5
CVE-2026-56842

A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulne

7.5
CVE-2026-40452

Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLas

7.5
CVE-2026-9127

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a con

7.5
CVE-2026-48489

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.4

7.5
CVE-2026-48808

Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but

7.5
CVE-2026-43977

wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read anoth

7.5
CVE-2026-60320

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Suppor

7.5
CVE-2026-54719

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.

7.5
CVE-2026-16540

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operati

7.5
CVE-2026-62927

In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space hand

7.5
CVE-2026-71234

Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPubl

7.5
CVE-2026-48416

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A

7.5
CVE-2026-73285

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA a

7.5
CVE-2026-58427

Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

7.5
CVE-2026-71518

Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unaut

7.5
CVE-2026-74906

SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints tha

7.5
CVE-2026-77438

Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public shar

7.5
CVE-2026-56854

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the P

7.4
CVE-2026-40213

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This un

7.4
CVE-2026-48501

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization h

7.4
CVE-2025-14774

Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

7.4
CVE-2026-56776

n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/n

7.4
CVE-2026-55672

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchan

7.4
CVE-2026-18394

Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to ob

7.4
CVE-2026-70452

rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent host

7.3
CVE-2025-10908

Due to a lack of user account state validation during authentication, locked user accounts can be successfully authentic

7.3
CVE-2026-44567

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, the

7.3
CVE-2026-9350

A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This affects the function check_all_command

7.3
CVE-2026-8079

In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged

7.3
CVE-2026-15541

A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file a

7.3
CVE-2026-15752

A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is a

7.3
CVE-2026-62290

cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the proc

7.3
CVE-2026-16126

A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of

7.3
CVE-2026-16200

A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file cla

7.3
CVE-2026-19010

A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packag

7.3
CVE-2026-71383

is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker coul

7.2
CVE-2026-24748

Kargo manages and automates the promotion of software artifacts. Prior to versions 1.8.7, 1.7.7, and 1.6.3, a bug was fo

7.2
CVE-2026-23572

Improper access control in the TeamViewer Full and Host clients (Windows, macOS, Linux) prior version 15.74.5 allows an

7.2
CVE-2026-29182

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version

7.2
CVE-2026-30229

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version

7.2
CVE-2026-1497

Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.

7.2
CVE-2026-44380

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerabili

7.2
CVE-2026-0272

A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with a

7.2
CVE-2026-9640

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 reg

Frequently Asked Questions

What is CWE-863?

CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-863?

There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.

How can I protect against CWE-863 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.

Detect CWE-863 Vulnerabilities

CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.

Get Started