VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 136 of 405
  • CVE-2026-30140HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.00

    An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/RouterCfm.jpg endpoint to download the configuration file containing plaintext administrator credentials, leading to sensitive…

  • CVE-2025-70363HigMar 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs.

  • CVE-2026-26418HigMar 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows remote attackers to access application functionality without restriction via the network.

  • CVE-2024-55019HigMar 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files.

  • CVE-2026-28276HigFeb 26, 2026
    risk 0.49cvss 7.5epss 0.00

    Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions prior to 0.32.2 where uploaded documents are served from a publicly accessible /uploads/ directory without any authentication or authorization checks. Any…

  • CVE-2026-27449HigFeb 26, 2026
    risk 0.49cvss 7.5epss 0.00

    Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where certain API endpoints are exposed without enforcing authentication or authorization checks. The affected endpoints can be accessed…

  • CVE-2026-2250HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensitive operational data. Additionally, the application is configured with debug mode enabled, causing…

  • CVE-2026-25231HigFeb 9, 2026
    risk 0.49cvss 7.5epss 0.01

    FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthenticated file read vulnerability due to the lack of access control on the /uploads directory. Files uploaded to this directory can be accessed directly by any…

  • CVE-2025-70963HigFeb 6, 2026
    risk 0.49cvss 7.6epss 0.00

    Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials accessible to any script running in the…

  • CVE-2025-70986HigJan 23, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access sensitive department data.

  • CVE-2025-69908HigJan 23, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a publicly accessible client-side JavaScript resource.

  • CVE-2025-69907HigJan 23, 2026
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and access control on the /omnidocs/GetListofCabinet API endpoint. A remote attacker can access this endpoint without valid credentials to retrieve sensitive internal…

  • CVE-2026-21984HigJan 20, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM…

  • CVE-2026-21982HigJan 20, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment…

  • CVE-2026-22909HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.01

    Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations.

  • CVE-2026-20929HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.03

    Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-0386HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2025-67015HigDec 26, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows attackers to change the Administrator password and escalate privileges via sending a crafted POST request to /Forms/admin_access_1.

  • CVE-2025-67014HigDec 26, 2025
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauthenticated attackers to access an administrative endpoint.

  • CVE-2025-66735HigDec 22, 2025
    risk 0.49cvss 7.5epss 0.00

    youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks, which may allow non-root users to directly access root roles.