CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,082)
page 139 of 405| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-37125 | Hig | 0.49 | 7.5 | 0.00 | Sep 16, 2025 | A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly | ||
| CVE-2025-24088 | Hig | 0.49 | 7.5 | 0.00 | Sep 15, 2025 | The issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26. An app may be able to override MDM-enforced settings from profiles. | ||
| CVE-2025-45584 | Hig | 0.49 | 7.5 | 0.00 | Sep 12, 2025 | Incorrect access control in the web service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to download car information without authentication. | ||
| CVE-2024-45432 | Hig | 0.49 | 7.5 | 0.01 | Sep 12, 2025 | OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from an incorrect variable used as a function argument. An attacker can leverage this to cause unexpected behavior or obtain… | ||
| CVE-2025-56406 | Hig | 0.49 | 7.5 | 0.00 | Sep 10, 2025 | An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE: the Supplier's position is that authentication is not mandatory for MCP servers, and the mcp-neo4j MCP server is only intended… | ||
| CVE-2025-56405 | Hig | 0.49 | 7.5 | 0.00 | Sep 10, 2025 | An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP service through the SSE protocol. | ||
| CVE-2025-55238 | Hig | 0.49 | 7.5 | 0.01 | Sep 4, 2025 | Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability | ||
| CVE-2025-54599 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2025 | The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover, if SSO is used, when a victim changes the email address that they have configured. To exploit this, an attacker would create their own account and perform an… | ||
| CVE-2025-29421 | Hig | 0.49 | 7.5 | 0.00 | Aug 25, 2025 | PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function. | ||
| CVE-2024-53494 | Hig | 0.49 | 7.5 | 0.00 | Aug 22, 2025 | Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive components without authentication. | ||
| CVE-2024-57152 | Hig | 0.49 | 7.5 | 0.00 | Aug 20, 2025 | Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication via the cn.luischen.interceptor.BaseInterceptor class | ||
| CVE-2024-53495 | Hig | 0.49 | 7.5 | 0.00 | Aug 20, 2025 | Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication. | ||
| CVE-2025-51532 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Database Monitor via a crafted request. The vendor has stated that the issue is fixed in 2025_06_000, released in June 2025. | ||
| CVE-2025-33056 | Hig | 0.49 | 7.5 | 0.02 | Jun 10, 2025 | Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-20100 | Hig | 0.49 | 7.5 | 0.00 | May 13, 2025 | Improper access control in the memory controller configurations for some Intel(R) Xeon(R) 6 processor with E-cores may allow a privileged user to potentially enable escalation of privilege via local access. | ||
| CVE-2025-31247 | Hig | 0.49 | 7.5 | 0.00 | May 12, 2025 | A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An attacker may gain access to protected parts of the file system. | ||
| CVE-2025-45617 | Hig | 0.49 | 7.5 | 0.00 | May 5, 2025 | Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload. | ||
| CVE-2025-45614 | Hig | 0.49 | 7.5 | 0.00 | May 5, 2025 | Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information via a crafted payload. | ||
| CVE-2025-45613 | Hig | 0.49 | 7.5 | 0.00 | May 5, 2025 | Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive information via a crafted payload. | ||
| CVE-2025-45610 | Hig | 0.49 | 7.5 | 0.00 | May 5, 2025 | Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sensitive information via a crafted payload. |
- risk 0.49cvss 7.5epss 0.00
A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly
- risk 0.49cvss 7.5epss 0.00
The issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26. An app may be able to override MDM-enforced settings from profiles.
- risk 0.49cvss 7.5epss 0.00
Incorrect access control in the web service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to download car information without authentication.
- risk 0.49cvss 7.5epss 0.01
OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from an incorrect variable used as a function argument. An attacker can leverage this to cause unexpected behavior or obtain…
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE: the Supplier's position is that authentication is not mandatory for MCP servers, and the mcp-neo4j MCP server is only intended…
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP service through the SSE protocol.
- risk 0.49cvss 7.5epss 0.01
Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.00
The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover, if SSO is used, when a victim changes the email address that they have configured. To exploit this, an attacker would create their own account and perform an…
- risk 0.49cvss 7.5epss 0.00
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.
- risk 0.49cvss 7.5epss 0.00
Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive components without authentication.
- risk 0.49cvss 7.5epss 0.00
Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication via the cn.luischen.interceptor.BaseInterceptor class
- risk 0.49cvss 7.5epss 0.00
Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.
- risk 0.49cvss 7.5epss 0.00
Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Database Monitor via a crafted request. The vendor has stated that the issue is fixed in 2025_06_000, released in June 2025.
- risk 0.49cvss 7.5epss 0.02
Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.00
Improper access control in the memory controller configurations for some Intel(R) Xeon(R) 6 processor with E-cores may allow a privileged user to potentially enable escalation of privilege via local access.
- risk 0.49cvss 7.5epss 0.00
A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An attacker may gain access to protected parts of the file system.
- risk 0.49cvss 7.5epss 0.00
Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload.
- risk 0.49cvss 7.5epss 0.00
Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information via a crafted payload.
- risk 0.49cvss 7.5epss 0.00
Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive information via a crafted payload.
- risk 0.49cvss 7.5epss 0.00
Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sensitive information via a crafted payload.