On this page
CWE-863: Incorrect Authorization
Weakness Summary
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
- Canonical source: MITRE CWE-863 (opens in a new tab)
- Published Atomicorp CVE observations: 14
- Distinct affected products in those observations: 14
- Active Atomicorp rules associated with this weakness: 35
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2026-19598 | Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX Router | pods | Detected by Atomicorp | 377360 |
| CVE-2026-43945 | FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection | FUXA | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2021-3577 | Motorola Baby Monitors - Remote Command Execution | halo+ camera firmware | Attack Blocked by Atomicorp | 340014 , 340193 , 344364 , 344370 , 393655 |
| CVE-2023-32749 | Pydio Cells 4.1.2 - Unauthorised Role Assignments | cells | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2026-35029 | LiteLLM - Arbitrary File Read | litellm | Attack Blocked by Atomicorp | 344360 , 390709 |
| CVE-2026-76836 | AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group Bypass | AzuraCast | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-86437 | Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload | laradashboard | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2013-4862 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | Attack Blocked by Atomicorp | 330791 , 340121 , 340152 , 344360 , 344370 , 390636 , 390726 , 392647 |
| CVE-2021-24405 | WordPress Plugin Easy Cookie Policy 1.6.2 - Broken Access Control to Stored XSS | easy cookies policy | Attack Blocked by Atomicorp | 346755 , 390585 , 390726 , 392647 |
| CVE-2021-24947 | WordPress Responsive Vector Maps < 6.4.2 - Arbitrary File Read | responsive vector maps | Attack Blocked by Atomicorp | 344360 , 347009 , 390709 |
| CVE-2021-36749 | Apache Druid - Local File Inclusion | druid | Attack Blocked by Atomicorp | 340029 , 344360 |
| CVE-2026-85512 | SourceCodester Class and Exam Timetabling System session.php authorization | Class and Exam Timetabling System | Attack Blocked by Atomicorp | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-8446 | Jira Improper Authorization | jira server | Attack Blocked by Atomicorp | 392301 |
| CVE-2024-2473 | WPS Hide Login <= 1.9.15.2 - Login Page Disclosure | wps hide login | Detected by Atomicorp | 377360 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 330791 | Active | disruptive (deny) |
| 340014 | Active | disruptive (deny) |
| 340016 | Active | disruptive (deny) |
| 340017 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340121 | Active | disruptive (deny) |
| 340144 | Active | disruptive (deny) |
| 340145 | Active | disruptive (deny) |
| 340152 | Active | disruptive (deny) |
| 340156 | Active | disruptive (deny) |
| 340157 | Active | disruptive (deny) |
| 340193 | Active | disruptive (deny) |
| 341245 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344364 | Active | disruptive (deny) |
| 344366 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 346755 | Active | disruptive (deny) |
| 347009 | Active | disruptive (deny) |
| 360147 | Active | disruptive (deny) |
| 360148 | Active | disruptive (deny) |
| 377360 | Active | non-disruptive (pass) |
| 380026 | Active | disruptive (deny) |
| 380122 | Active | disruptive (deny) |
| 390572 | Active | disruptive (deny) |
| 390585 | Active | disruptive (deny) |
| 390636 | Active | disruptive (deny) |
| 390709 | Active | disruptive (deny) |
| 390726 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 392647 | Active | disruptive (deny) |
| 393655 | Active | disruptive (deny) |