VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 106 of 405
  • CVE-2026-43945HigJul 21, 2026
    risk 0.51cvss —epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state…

  • CVE-2026-13800HigJun 30, 2026
    risk 0.51cvss 7.8epss 0.00

    Inappropriate implementation in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

  • CVE-2026-12786HigJun 21, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been found in Ezbsystems UltraISO Premium Edition up to 9.76. Affected by this issue is some unknown functionality in the library bootpt64.sys of the component Kernel Driver. The manipulation leads to improper access controls. Local access is required to…

  • CVE-2026-12784HigJun 21, 2026
    risk 0.51cvss 7.8epss 0.00

    A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the component Kernel Driver. This manipulation causes improper access controls. The attack requires local access. The exploit has been made…

  • CVE-2026-12782HigJun 21, 2026
    risk 0.51cvss 7.8epss 0.00

    A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function in the library EUEDKEPM.sys of the component Kernel Driver. The manipulation results in improper access controls. The attack requires a local approach. The…

  • CVE-2026-12781HigJun 21, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library epmntdrv.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit…

  • CVE-2026-12780HigJun 21, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the component Kernel Driver. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been…

  • CVE-2026-12779HigJun 21, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the library ddmdrv.sys of the component Kernel Driver. Performing a manipulation results in improper access controls. The attack must be initiated from a local…

  • CVE-2026-12778HigJun 21, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in the library ampa10.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack must be carried out locally. The exploit…

  • CVE-2026-46461HigJun 19, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2026-46888HigJun 17, 2026
    risk 0.51cvss 7.8epss 0.00

    Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Database Upgrade). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM…

  • CVE-2026-46848HigJun 17, 2026
    risk 0.51cvss 7.9epss 0.00

    Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where WebLogic…

  • CVE-2026-49161HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-48578HigJun 9, 2026
    risk 0.51cvss 7.9epss 0.00

    Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-45658HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2026-45654HigJun 9, 2026
    risk 0.51cvss 7.9epss 0.00

    Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-42829HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-41092HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.

  • CVE-2026-40715HigJun 2, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.

  • CVE-2025-22426HigJun 1, 2026
    risk 0.51cvss 7.8epss 0.00

    In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.