Skip to main content

About CWE-863

A flawed check can let an attacker read or modify sensitive data, gain privileges, or use privileged functions. Elevated access can then lead to command execution or denial of service.

MITRE name
Incorrect Authorization
Abstraction
Class: a very abstract weakness, typically independent of language or technology
Status
Incomplete
Also known as
AuthZ

Mitigations

  • +Divide the product into anonymous, normal, privileged and administrative areas and enforce roles with RBAC at the correct boundaries.
  • +Base access checks on business logic in addition to generic resource permissions.
  • +Enforce access control on the server for every page, so direct requests cannot reach unauthorized functions.
  • +Use operating system and server access control features with a default-deny policy.

Detection
Manual analysis such as penetration testing is useful for custom authorization schemes. MITRE rates automated static analysis as limited and notes automated dynamic analysis may miss flawed checks.

CWE-863 Vulnerabilities

7 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-71362
Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe9.187.5%KEV2026-08-11
CVE-2026-42016
Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation
jfrog8.18.6%KEV2026-07-27
CVE-2025-54253
Adobe Experience Manager | Incorrect Authorization (CWE-863)
Adobe10.088.3%KEV2025-08-05
CVE-2025-21479
Incorrect Authorization in Graphics
Qualcomm, Inc.8.60.8%KEV2025-06-03
CVE-2025-21480
Incorrect Authorization in Graphics Windows
Qualcomm, Inc.8.60.5%KEV2025-06-03
CVE-2024-38856
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
Apache Software Foundation8.199.4%KEV2024-08-05
CVE-2021-3560
Red Hat Polkit Incorrect Authorization Vulnerability
-7.823.7%KEV2022-02-16

Most Affected Vendors

Frequently Asked Questions

What is CWE-863?→

CWE-863 is incorrect authorization: the product checks whether an actor may do something, but the check gives the wrong answer.

Does role-based access control prevent all CWE-863 cases?→

MITRE notes RBAC may not stop horizontal authorization problems, where a user acts against others who hold the same role.

How many exploited vulnerabilities are classified as CWE-863?→

This database lists 7 CVE records mapped to CWE-863 by their CVE Numbering Authority. 7 of them are in the CISA Known Exploited Vulnerabilities catalog. Examples include CVE-2026-71362, CVE-2026-42016, CVE-2025-54253.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.