VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 17 of 404
  • CVE-2026-31843CriApr 16, 2026
    risk 0.64cvss 9.8epss 0.01

    The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed via Route::any without authentication…

  • CVE-2026-22564CriApr 13, 2026
    risk 0.64cvss 9.8epss 0.00

    An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized changes to the system.
 Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version…

  • CVE-2026-31282CriApr 13, 2026
    risk 0.64cvss 9.8epss 0.00

    Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to reveal the login form. An attacker can chain that with missing rate-limit on the login form to launch a brute force attack. NOTE: this is disputed by the Supplier…

  • CVE-2026-31272CriApr 7, 2026
    risk 0.64cvss 9.8epss 0.01

    MRCMS 3.1.2 contains an access control vulnerability. The save() method in src/main/java/org/marker/mushroom/controller/UserController.java lacks proper authorization validation, enabling direct addition of super administrator accounts without authentication.

  • CVE-2026-21994CriMar 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop). The supported version that is affected is 0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network…

  • CVE-2026-21667CriMar 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

  • CVE-2026-21666CriMar 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

  • CVE-2025-66956CriMar 11, 2026
    risk 0.64cvss 9.9epss 0.00

    Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute attachments via a computable URL.

  • CVE-2026-27975CriFeb 26, 2026
    risk 0.64cvss 9.8epss 0.01

    Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbitrary code on this server. This is fixed in the version 2.2.13.

  • CVE-2026-2550CriFeb 16, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used.…

  • CVE-2025-8025CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Dinosoft ERP: from < 3.0.1 through 11022026. NOTE: The vendor was…

  • CVE-2026-24300CriFeb 5, 2026
    risk 0.64cvss 9.8epss 0.01

    Azure Front Door Elevation of Privilege Vulnerability

  • CVE-2025-70982CriJan 26, 2026
    risk 0.64cvss 9.9epss 0.00

    Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data.

  • CVE-2025-70983CriJan 23, 2026
    risk 0.64cvss 9.9epss 0.00

    Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.

  • CVE-2026-24304CriJan 23, 2026
    risk 0.64cvss 9.9epss 0.01

    Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-24306CriJan 22, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-63389CriDec 18, 2025
    risk 0.64cvss 9.8epss 0.01

    A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management…

  • CVE-2025-65276CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    An unauthenticated administrative access vulnerability exists in the open-source HashTech project (https://github.com/henzljw/hashtech) 1.0 thru commit 5919decaff2681dc250e934814fc3a35f6093ee5 (2021-07-02). Due to missing authentication checks on /admin_index.php, an attacker…

  • CVE-2025-55469CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend.

  • CVE-2025-63958CriNov 24, 2025
    risk 0.64cvss 9.8epss 0.01

    MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authentication. This page leaks plaintext database credentials, file share paths, internal license server configuration, and software update…