VYPR

CWE-1280

Access Control Check Implemented After Asset is Accessed

BaseIncomplete

Description

A product's hardware-based access control check occurs after the asset has been accessed.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-180

CVEs mapped to this weakness (3)

  • CVE-2026-86341MedSep 16, 2026
    risk 0.29cvss 4.4epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user with Owner or Maintainer permissions could have silently disabled protected environment…

  • CVE-2026-3607MedMay 14, 2026
    risk 0.28cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to bypass package protection rules due to improper access…

  • CVE-2026-7487LowAug 26, 2026
    risk 0.23cvss 3.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with reporter-role permissions who authored a merge request could have reset merge request…