VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 186 of 406
  • CVE-2026-67283MedAug 12, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on every file managed within the extension.

  • CVE-2026-21084MedAug 10, 2026
    risk 0.45cvss —epss 0.00

    Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information.

  • CVE-2026-54533MedJun 17, 2026
    risk 0.45cvss —epss 0.01

    vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms can potentially access other algorithms input and output files. Version 5.0.0 fixes the issue. As a workaround, verify and restrict the algorithm containers…

  • CVE-2026-45080MedJun 2, 2026
    risk 0.45cvss —epss 0.00

    Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access control allows disclosure of password hash. This issue has been patched in version 2.10.4.

  • CVE-2026-3111MedMar 16, 2026
    risk 0.45cvss —epss 0.00

    Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/archivos/usuarios/[ID]/[username]/thumb_AAxAA.jpg' (translated as 80x90 and 40x45). Successful exploitation of this vulnerability could allow an unauthenticated attacker to…

  • CVE-2025-29939MedFeb 10, 2026
    risk 0.45cvss —epss 0.00

    Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the reverse map page (RMP) during secure nested paging (SNP) initialization, potentially resulting in a loss of guest memory confidentiality and integrity.

  • CVE-2025-31125MedKEVMar 31, 2025
    risk 0.45cvss 5.3epss 0.65

    Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is…

  • CVE-2024-9692MedOct 24, 2024
    risk 0.45cvss —epss 0.00

    VIMESA VHF/FM Transmitter Blue Plus is suffering from a Denial-of-Service (DoS) vulnerability. An unauthenticated attacker can issue an unauthorized HTTP GET request to the unprotected endpoint 'doreboot' and restart the transmitter operations.

  • CVE-2024-42033MedAug 8, 2024
    risk 0.45cvss 6.9epss 0.00

    Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2024-21644HigJan 8, 2024
    risk 0.45cvss 7.5epss 0.42

    pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable. This issue has been patched in version 0.5.0b3.dev77.

  • CVE-2023-4169MedAug 5, 2023
    risk 0.45cvss 6.3epss 0.49

    A vulnerability was found in Ruijie RG-EW1200G 1.0(1)B1P5. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/sys/set_passwd of the component Administrator Password Handler. The manipulation leads to improper access…

  • CVE-2020-5244HigFeb 24, 2020
    risk 0.45cvss 8.0epss 0.02

    In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2.

  • CVE-2019-3895HigJun 3, 2019
    risk 0.45cvss 8.0epss 0.02

    An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant that a remote attacker could upload a new amphorae image…

  • CVE-2016-2167MedMay 5, 2016
    risk 0.45cvss 6.8epss 0.07

    The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of…

  • CVE-2026-87252MedSep 15, 2026
    risk 0.44cvss 6.8epss 0.00

    Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached…

  • CVE-2026-83491MedSep 15, 2026
    risk 0.44cvss 6.8epss 0.00

    Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication…

  • CVE-2026-83441MedSep 15, 2026
    risk 0.44cvss 6.8epss 0.00

    Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-83278MedSep 15, 2026
    risk 0.44cvss 6.8epss 0.00

    Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-integrations-neo4j). Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical…

  • CVE-2026-83076MedSep 15, 2026
    risk 0.44cvss 6.8epss 0.00

    Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-73965MedSep 15, 2026
    risk 0.44cvss 6.8epss 0.00

    Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Cloud Gateway). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM…