VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 101 of 405
  • CVE-2026-50006CriSep 14, 2026
    risk 0.52cvss 9.1epss 0.01

    Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacker can select any path writable by the…

  • CVE-2026-88864CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassing the intended backend SSO provisioning…

  • CVE-2026-84200CriSep 1, 2026
    risk 0.52cvss 9.0epss 0.00

    Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive exception takes precedence, allowing an attacker to bypass the policy by crafting a resource name that…

  • CVE-2026-65182CriAug 25, 2026
    risk 0.52cvss 9.1epss 0.01

    Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1…

  • CVE-2026-55536CriAug 25, 2026
    risk 0.52cvss 9.1epss 0.00

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome extension origins with re.match() and the unanchored expression chrome-extension://[a-z0-9]{32}. Extra trailing characters pass before websocket.accept(),…

  • CVE-2026-71122HigAug 18, 2026
    risk 0.52cvss 8.0epss 0.00

    Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via…

  • CVE-2026-70802HigAug 18, 2026
    risk 0.52cvss 8.0epss 0.00

    Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP…

  • CVE-2026-70690HigAug 18, 2026
    risk 0.52cvss 8.0epss 0.00

    Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise…

  • CVE-2026-62602HigAug 18, 2026
    risk 0.52cvss 8.0epss 0.00

    Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication…

  • CVE-2026-60998HigAug 18, 2026
    risk 0.52cvss 8.0epss 0.00

    Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active Directory). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows high privileged attacker with…

  • CVE-2026-60961HigAug 18, 2026
    risk 0.52cvss 8.0epss 0.00

    Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical…

  • CVE-2026-56750CriAug 13, 2026
    risk 0.52cvss 9.1epss 0.00

    Gitea Remember-Me Token Theft Not Invalidating Attacker Session

  • CVE-2025-14561CriAug 6, 2026
    risk 0.52cvss 9.0epss 0.00

    In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user…

  • CVE-2026-64863CriJul 28, 2026
    risk 0.52cvss 9.1epss 0.00

    goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-delete, allowing WebDAV clients to delete or overwrite files via MOVE with…

  • CVE-2026-35425HigJul 24, 2026
    risk 0.52cvss 8.0epss 0.01

    Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

  • CVE-2026-61224HigJul 21, 2026
    risk 0.52cvss 8.0epss 0.00

    Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with network access via TLS to…

  • CVE-2026-46923HigJul 21, 2026
    risk 0.52cvss 8.0epss 0.00

    Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access…

  • CVE-2026-26247CriJul 3, 2026
    risk 0.52cvss 9.1epss 0.01

    Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.

  • CVE-2026-20706CriJul 3, 2026
    risk 0.52cvss 9.1epss 0.01

    Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.

  • CVE-2026-44007CriMay 13, 2026
    risk 0.52cvss 9.1epss 0.01

    vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require configuration — including require: false. With access to vm2, the sandbox constructs…