VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 188 of 406
  • CVE-2026-60775MedJul 21, 2026
    risk 0.44cvss 6.7epss 0.00

    Vulnerability in the Pasta product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Pasta executes to…

  • CVE-2026-60687MedJul 21, 2026
    risk 0.44cvss 6.8epss 0.00

    Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to…

  • CVE-2026-60612MedJul 21, 2026
    risk 0.44cvss 6.8epss 0.00

    Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Commonline Loans). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-60181MedJul 21, 2026
    risk 0.44cvss 6.7epss 0.00

    Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Configurator). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with…

  • CVE-2026-36933MedJun 15, 2026
    risk 0.44cvss 6.8epss 0.00

    An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code via the factory test feature.

  • CVE-2026-36738MedMay 13, 2026
    risk 0.44cvss 6.8epss 0.00

    U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes a UART interface that lacks authentication, authorization, or access control mechanisms. An attacker with physical access to the UART pins can connect to the…

  • CVE-2026-1749MedMay 9, 2026
    risk 0.44cvss 6.8epss 0.00

    There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission.

  • CVE-2026-44118HigMay 6, 2026
    risk 0.44cvss 7.8epss 0.00

    OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. Non-owner loopback clients can present themselves as owner to bypass owner-gated operations by manipulating the sender-owner header metadata.

  • CVE-2026-34325MedApr 21, 2026
    risk 0.44cvss 6.8epss 0.00

    Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows…

  • CVE-2026-34314MedApr 21, 2026
    risk 0.44cvss 6.8epss 0.00

    Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Difficult to exploit vulnerability allows low…

  • CVE-2025-43534MedMar 25, 2026
    risk 0.44cvss 6.8epss 0.00

    A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.2 and iPadOS 26.2. A user with physical access to an iOS device may be able to bypass Activation Lock.

  • CVE-2026-4105MedMar 13, 2026
    risk 0.44cvss 6.7epss 0.00

    A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to…

  • CVE-2025-14095MedDec 17, 2025
    risk 0.44cvss 6.8epss 0.00

    A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of this vulnerability gives a user with physical access to the analyzer, the possibility to gain unauthorized access to functionalities outside the restricted…

  • CVE-2025-47179MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2025-22391MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Improper access control for some SigTest before version 6.1.10 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result…

  • CVE-2025-57438MedSep 22, 2025
    risk 0.44cvss 6.8epss 0.00

    The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intended to be accessible only after the admin explicitly grants access to a manager-level account. However, a manager-level user can bypass these controls by…

  • CVE-2025-21031MedSep 3, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.

  • CVE-2025-25734MedAug 26, 2025
    risk 0.44cvss 6.8epss 0.00

    Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discovered to contain an unauthenticated EFI shell which allows attackers to execute arbitrary code or escalate privileges during the boot process.

  • CVE-2025-8762MedAug 13, 2025
    risk 0.44cvss 6.8epss 0.00

    A vulnerability was found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This issue affects some unknown processing of the component UART Interface. The manipulation leads to improper physical access control. It is possible to launch the attack on the physical device. The exploit has…

  • CVE-2025-20099MedAug 12, 2025
    risk 0.44cvss 6.7epss 0.00

    Improper access control for some Intel(R) Rapid Storage Technology installation software may allow an authenticated user to potentially enable escalation of privilege via local access.