phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks pe
In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of UR
OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allow
Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in
Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3,
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulne
Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLas
A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a con
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.4
Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but
wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read anoth
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Suppor
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operati
In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space hand
Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPubl
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA a
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unaut
SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints tha
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public shar
The source-address critical option in the Permissions returned by an authentication callback was only enforced for the P
OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This un
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization h
Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/n
ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchan
Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to ob
rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent host
Due to a lack of user account state validation during authentication, locked user accounts can be successfully authentic
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, the
A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This affects the function check_all_command
In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged
A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file a
A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is a
cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the proc
A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of
A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file cla
A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packag
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker coul
Kargo manages and automates the promotion of software artifacts. Prior to versions 1.8.7, 1.7.7, and 1.6.3, a bug was fo
Improper access control in the TeamViewer Full and Host clients (Windows, macOS, Linux) prior version 15.74.5 allows an
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerabili
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with a
A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 reg
Frequently Asked Questions
What is CWE-863?
CWE-863 (Incorrect Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-863?
There are 4,076 CVE records associated with CWE-863 in our database. Of these, 351 are critical severity, 1194 are high severity, and 1775 are medium severity.
How can I protect against CWE-863 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-863 using AI-powered security agents.
Detect CWE-863 Vulnerabilities
CyberStrike's AI agents automatically detect incorrect authorization vulnerabilities across your infrastructure.
Get Started