VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 107 of 405
  • CVE-2026-0856HigMay 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables a normal user gaining access to the admin panel. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component:…

  • CVE-2026-40381HigMay 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

  • CVE-2026-33834HigMay 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-8069HigMay 8, 2026
    risk 0.51cvss 7.8epss 0.00

    PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user…

  • CVE-2026-37526HigMay 1, 2026
    risk 0.51cvss 7.8epss 0.00

    AGL app-framework-binder (afb-daemon) through v19.90.0 allows any local process to execute privileged supervision commands (Exit, Do, Sclose, Config, Trace, Debug, Token, slist) without authentication via the abstract Unix socket @urn:AGL:afs:supervision:socket. The…

  • CVE-2026-35243HigApr 21, 2026
    risk 0.51cvss 7.8epss 0.00

    Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the…

  • CVE-2026-27914HigApr 14, 2026
    risk 0.51cvss 7.8epss 0.02

    Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26183HigApr 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.

  • CVE-2026-25176HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24290HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally.

  • CVE-2026-23660HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.

  • CVE-2026-23856HigFeb 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell iDRAC Service Module (iSM) for Windows, versions prior to 6.0.3.1, and Dell iDRAC Service Module (iSM) for Linux, versions prior to 5.4.1.1, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this…

  • CVE-2026-21238HigFeb 10, 2026
    risk 0.51cvss 7.8epss 0.03

    Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60865HigFeb 3, 2026
    risk 0.51cvss 7.8epss 0.00

    Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service windows component.

  • CVE-2025-46691HigJan 28, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell PremierColor Panel Driver, versions prior to 1.0.0.1 A01, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

  • CVE-2026-20949HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2026-20843HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.04

    Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-64669HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.

  • CVE-2025-64673HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62474HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.