On this page

CWE-863: Incorrect Authorization

Weakness Summary

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

  • Canonical source: MITRE CWE-863 (opens in a new tab)
  • Published Atomicorp CVE observations: 14
  • Distinct affected products in those observations: 14
  • Active Atomicorp rules associated with this weakness: 35

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2026-19598Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX RouterpodsDetected by Atomicorp377360
CVE-2026-43945FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration InjectionFUXAAttack Blocked by Atomicorp340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2021-3577Motorola Baby Monitors - Remote Command Executionhalo+ camera firmwareAttack Blocked by Atomicorp340014 , 340193 , 344364 , 344370 , 393655
CVE-2023-32749Pydio Cells 4.1.2 - Unauthorised Role AssignmentscellsAttack Blocked by Atomicorp330791 , 340152
CVE-2026-35029LiteLLM - Arbitrary File ReadlitellmAttack Blocked by Atomicorp344360 , 390709
CVE-2026-76836AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group BypassAzuraCastAttack Blocked by Atomicorp340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-86437Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive UploadlaradashboardAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2013-4862MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilitiesveralite firmwareAttack Blocked by Atomicorp330791 , 340121 , 340152 , 344360 , 344370 , 390636 , 390726 , 392647
CVE-2021-24405WordPress Plugin Easy Cookie Policy 1.6.2 - Broken Access Control to Stored XSSeasy cookies policyAttack Blocked by Atomicorp346755 , 390585 , 390726 , 392647
CVE-2021-24947WordPress Responsive Vector Maps < 6.4.2 - Arbitrary File Readresponsive vector mapsAttack Blocked by Atomicorp344360 , 347009 , 390709
CVE-2021-36749Apache Druid - Local File InclusiondruidAttack Blocked by Atomicorp340029 , 344360
CVE-2026-85512SourceCodester Class and Exam Timetabling System session.php authorizationClass and Exam Timetabling SystemAttack Blocked by Atomicorp340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-8446Jira Improper Authorizationjira serverAttack Blocked by Atomicorp392301
CVE-2024-2473WPS Hide Login <= 1.9.15.2 - Login Page Disclosurewps hide loginDetected by Atomicorp377360

Associated Atomicorp WAF Rules

RuleStatusBehavior
330791Activedisruptive (deny)
340014Activedisruptive (deny)
340016Activedisruptive (deny)
340017Activedisruptive (deny)
340023Activedisruptive (deny)
340029Activedisruptive (deny)
340121Activedisruptive (deny)
340144Activedisruptive (deny)
340145Activedisruptive (deny)
340152Activedisruptive (deny)
340156Activedisruptive (deny)
340157Activedisruptive (deny)
340193Activedisruptive (deny)
341245Activedisruptive (deny)
344360Activedisruptive (deny)
344361Activedisruptive (deny)
344363Activedisruptive (deny)
344364Activedisruptive (deny)
344366Activedisruptive (deny)
344370Activedisruptive (deny)
346755Activedisruptive (deny)
347009Activedisruptive (deny)
360147Activedisruptive (deny)
360148Activedisruptive (deny)
377360Activenon-disruptive (pass)
380026Activedisruptive (deny)
380122Activedisruptive (deny)
390572Activedisruptive (deny)
390585Activedisruptive (deny)
390636Activedisruptive (deny)
390709Activedisruptive (deny)
390726Activedisruptive (deny)
392301Activedisruptive (deny)
392647Activedisruptive (deny)
393655Activedisruptive (deny)