VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 200 of 406
  • CVE-2026-71574MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the…

  • CVE-2026-19711MedAug 16, 2026
    risk 0.42cvss 6.5epss 0.00

    The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which…

  • CVE-2026-58417HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    REST API exposes organization membership of private organizations to public

  • CVE-2026-73626HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct…

  • CVE-2026-72554MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations belonging to other customers via the v1 REST API. The API verifies the existence of the requested ticket but not ownership,…

  • CVE-2026-14816MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email…

  • CVE-2026-16563MedAug 3, 2026
    risk 0.42cvss 6.5epss 0.00

    The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons,…

  • CVE-2026-14315MedAug 1, 2026
    risk 0.42cvss 6.5epss 0.00

    The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs…

  • CVE-2026-13329MedAug 1, 2026
    risk 0.42cvss 6.5epss 0.00

    The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured…

  • CVE-2026-14834MedJul 31, 2026
    risk 0.42cvss 6.5epss 0.00

    The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses…

  • CVE-2026-17986MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Insufficient policy enforcement in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-17917MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-17873MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17830MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17825MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Insufficient policy enforcement in Passwords in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17824MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-43821MedJul 27, 2026
    risk 0.42cvss 6.5epss 0.00

    An access issue was addressed with improved access restrictions. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read files outside of its sandbox.

  • CVE-2026-62480MedJul 21, 2026
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-61323MedJul 21, 2026
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations). The supported version that is affected is 12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-61262MedJul 21, 2026
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts). Supported versions that are affected are 12.2.3-12.215. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…