Incorrect Authorization (CWE-863)
CWE-863 applies when a product performs an authorization check but performs it incorrectly. The check exists, so this is distinct from missing authorization. Assuming a known identity, authorization decides whether that user may access a resource given its privileges and permissions.
About CWE-863
A flawed check can let an attacker read or modify sensitive data, gain privileges, or use privileged functions. Elevated access can then lead to command execution or denial of service.
Mitigations
- +Divide the product into anonymous, normal, privileged and administrative areas and enforce roles with RBAC at the correct boundaries.
- +Base access checks on business logic in addition to generic resource permissions.
- +Enforce access control on the server for every page, so direct requests cannot reach unauthorized functions.
- +Use operating system and server access control features with a default-deny policy.
Detection
Manual analysis such as penetration testing is useful for custom authorization schemes. MITRE rates automated static analysis as limited and notes automated dynamic analysis may miss flawed checks.
CWE-863 Vulnerabilities
7 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-71362 | Adobe Commerce | Incorrect Authorization (CWE-863) | Adobe | 9.1 | 87.5% | KEV | 2026-08-11 |
| CVE-2026-42016 | Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation | jfrog | 8.1 | 8.6% | KEV | 2026-07-27 |
| CVE-2025-54253 | Adobe Experience Manager | Incorrect Authorization (CWE-863) | Adobe | 10.0 | 88.3% | KEV | 2025-08-05 |
| CVE-2025-21479 | Incorrect Authorization in Graphics | Qualcomm, Inc. | 8.6 | 0.8% | KEV | 2025-06-03 |
| CVE-2025-21480 | Incorrect Authorization in Graphics Windows | Qualcomm, Inc. | 8.6 | 0.5% | KEV | 2025-06-03 |
| CVE-2024-38856 | Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code | Apache Software Foundation | 8.1 | 99.4% | KEV | 2024-08-05 |
| CVE-2021-3560 | Red Hat Polkit Incorrect Authorization Vulnerability | - | 7.8 | 23.7% | KEV | 2022-02-16 |
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-863?→
CWE-863 is incorrect authorization: the product checks whether an actor may do something, but the check gives the wrong answer.
Does role-based access control prevent all CWE-863 cases?→
MITRE notes RBAC may not stop horizontal authorization problems, where a user acts against others who hold the same role.
How many exploited vulnerabilities are classified as CWE-863?→
This database lists 7 CVE records mapped to CWE-863 by their CVE Numbering Authority. 7 of them are in the CISA Known Exploited Vulnerabilities catalog. Examples include CVE-2026-71362, CVE-2026-42016, CVE-2025-54253.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.