CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,082)
page 107 of 405| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-0856 | Hig | 0.51 | 7.8 | 0.00 | May 20, 2026 | Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables a normal user gaining access to the admin panel. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component:… | ||
| CVE-2026-40381 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2026 | Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-33834 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2026 | Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-8069 | Hig | 0.51 | 7.8 | 0.00 | May 8, 2026 | PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user… | ||
| CVE-2026-37526 | Hig | 0.51 | 7.8 | 0.00 | May 1, 2026 | AGL app-framework-binder (afb-daemon) through v19.90.0 allows any local process to execute privileged supervision commands (Exit, Do, Sclose, Config, Trace, Debug, Token, slist) without authentication via the abstract Unix socket @urn:AGL:afs:supervision:socket. The… | ||
| CVE-2026-35243 | Hig | 0.51 | 7.8 | 0.00 | Apr 21, 2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the… | ||
| CVE-2026-27914 | Hig | 0.51 | 7.8 | 0.02 | Apr 14, 2026 | Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-26183 | Hig | 0.51 | 7.8 | 0.00 | Apr 14, 2026 | Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-25176 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-24290 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-23660 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-23856 | Hig | 0.51 | 7.8 | 0.00 | Feb 12, 2026 | Dell iDRAC Service Module (iSM) for Windows, versions prior to 6.0.3.1, and Dell iDRAC Service Module (iSM) for Linux, versions prior to 5.4.1.1, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this… | ||
| CVE-2026-21238 | Hig | 0.51 | 7.8 | 0.03 | Feb 10, 2026 | Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-60865 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2026 | Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service windows component. | ||
| CVE-2025-46691 | Hig | 0.51 | 7.8 | 0.00 | Jan 28, 2026 | Dell PremierColor Panel Driver, versions prior to 1.0.0.1 A01, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | ||
| CVE-2026-20949 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2026-20843 | Hig | 0.51 | 7.8 | 0.04 | Jan 13, 2026 | Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-64669 | Hig | 0.51 | 7.8 | 0.00 | Dec 11, 2025 | Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-64673 | Hig | 0.51 | 7.8 | 0.00 | Dec 9, 2025 | Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-62474 | Hig | 0.51 | 7.8 | 0.00 | Dec 9, 2025 | Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. |
- risk 0.51cvss 7.8epss 0.00
Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables a normal user gaining access to the admin panel. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component:…
- risk 0.51cvss 7.8epss 0.00
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user…
- risk 0.51cvss 7.8epss 0.00
AGL app-framework-binder (afb-daemon) through v19.90.0 allows any local process to execute privileged supervision commands (Exit, Do, Sclose, Config, Trace, Debug, Token, slist) without authentication via the abstract Unix socket @urn:AGL:afs:supervision:socket. The…
- risk 0.51cvss 7.8epss 0.00
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the…
- risk 0.51cvss 7.8epss 0.02
Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Dell iDRAC Service Module (iSM) for Windows, versions prior to 6.0.3.1, and Dell iDRAC Service Module (iSM) for Linux, versions prior to 5.4.1.1, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this…
- risk 0.51cvss 7.8epss 0.03
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service windows component.
- risk 0.51cvss 7.8epss 0.00
Dell PremierColor Panel Driver, versions prior to 1.0.0.1 A01, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
- risk 0.51cvss 7.8epss 0.00
Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.
- risk 0.51cvss 7.8epss 0.04
Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.