CWE-863


Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.


We have discovered 1,606,566 live websites that are affected by CWE-863.

Contact us to get more info









CVEs

  • Count - 201



Website Distribution by Country

Number of websites using CWE-863
United States477,040 websites



British Virgin Islands248,689 websites
Russia182,679 websites
Germany99,313 websites
GB91,170 websites
France52,269 websites
Netherlands32,846 websites
Italy31,702 websites
China31,330 websites
Japan24,739 websites

Website Distribution by TLD

Number of websites using CWE-863
.com753,087 websites
.ru150,032 websites
.org86,149 websites
.net62,122 websites
.co.uk49,921 websites
.de48,348 websites
.nl27,542 websites
.it24,433 websites
.fr22,040 websites
.com.br15,371 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-863
DiscoveredCVEDescriptionWebsites
Apr, 2026CVE-2026-2712 WP-Optimize <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update and Image Manipulation16
Apr, 2026CVE-2026-33460 Incorrect Authorization in Kibana Fleet Leading to Information Disclosure42
Apr, 2026CVE-2026-33461 Incorrect Authorization in Kibana Fleet Leading to Information Disclosure42
Mar, 2026CVE-2026-33869 Mastodon has a denial of service for quote authorization849
Mar, 2026CVE-2026-33884 Statamic's live preview token bypasses content protection for unrelated entries1
Mar, 2026CVE-2025-15488 Responsive Plus < 3.4.3 - Unauthenticated Arbitrary Shortcode Execution1,834
Mar, 2026CVE-2026-3115 Guest users can view group member IDs without respecting view restrictions160
Mar, 2026CVE-2026-4274 Insufficient authorization in shared channel membership sync grants team-level access instead of channel-level access160
Mar, 2026CVE-2026-28755 NGINX ngx_stream_ssl_module vulnerability855,067
Mar, 2026CVE-2026-31805 Discourse has a poll authorization bypass via post_id array parameter884
List of the most common CVEs that are part of CWE-863
DiscoveredCVEDescriptionWebsites
Mar, 2026CVE-2026-28755 NGINX ngx_stream_ssl_module vulnerability855,067
Jan, 2024CVE-2022-0775 WooCommerce < 6.2.1 - Subscriber+ Arbitrary Comment Deletion178,701
Feb, 2025CVE-2025-23419 TLS Session Resumption Vulnerability152,495
Nov, 2024CVE-2024-9926 Jetpack < 13.9.1 - Subscriber+ Arbitrary Feedback Access124,742
Mar, 2025CVE-2025-31673 Drupal core - Moderately critical - Access bypass - SA-CORE-2025-002108,654
Sep, 2025CVE-2025-8944 OceanWP < 4.1.2 - Subscriber+ Limited Option Update64,818
Jan, 2023CVE-2022-45353 WordPress Betheme theme <= 26.6.1 is vulnerable to Broken Access Control36,378
Mar, 2024CVE-2024-1479 WP Show Posts <= 1.1.4 - Information Exposure33,428
Dec, 2025CVE-2025-14081 Ultimate Member <= 2.11.0 - Authenticated (Subscriber+) Profile Privacy Setting Bypass18,874
Jun, 2023CVE-2023-2877 Formidable Forms < 6.3.1 - Subscriber+ Remote Code Execution8,991

Websites affected by CWE-863

Top websites that are affected by CWE-863. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.org United States***
******.com British Virgin Islands***
****.*********.com British Virgin Islands***
*******.com United States***
****.******.org United States***
***.**.uk GB***
********.**************.com United States***
***.**.**.com China***
******.***.cc Germany***
**********.com United States***
See full domain list