VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 248 of 406
  • CVE-2026-28459HigMar 5, 2026
    risk 0.39cvss 7.1epss 0.01

    OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway clients to write transcript data to arbitrary locations on the host filesystem. Attackers can supply a sessionFile path outside the sessions directory to create…

  • CVE-2026-21447HigJan 2, 2026
    risk 0.39cvss 7.1epss 0.00

    Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer order reorder function allows any authenticated customer to add items from another customer's order to their own shopping cart by…

  • CVE-2025-0033MedOct 14, 2025
    risk 0.39cvss 6.0epss 0.00

    Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initialization, potentially resulting in a loss of SEV-SNP guest memory integrity.

  • CVE-2025-57197MedSep 29, 2025
    risk 0.39cvss 6.0epss 0.00

    In the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for the PIN change feature. A local attacker with root access to the device can dynamically instrument the app to bypass the current PIN verification check and…

  • CVE-2025-55196HigAug 13, 2025
    risk 0.39cvss —epss 0.00

    External Secrets Operator is a Kubernetes operator that integrates external secret management systems. From version 0.15.0 to before 0.19.2, a vulnerability was discovered where the List() calls for Kubernetes Secret and SecretStore resources performed by the PushSecret…

  • CVE-2025-21573MedApr 15, 2025
    risk 0.39cvss 6.0epss 0.00

    Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Chatbot). Supported versions that are affected are 5.1.0.0.0, 6.1.0.0.0 and 7.0.0.0.0. Difficult to exploit vulnerability allows high…

  • CVE-2025-25968MedFeb 20, 2025
    risk 0.39cvss 6.0epss 0.01

    DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive information, such as system administrator credentials, by force browsing the endpoint and exploiting the 'file' parameter. By…

  • CVE-2024-30211MedFeb 12, 2025
    risk 0.39cvss 6.0epss 0.00

    Improper access control in some Intel(R) ME driver pack installer engines before version 2422.6.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-25768HigSep 18, 2024
    risk 0.39cvss 7.0epss 0.00

    The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of…

  • CVE-2024-42497MedAug 22, 2024
    risk 0.39cvss 6.0epss 0.00

    Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permissions which allows a user with systems manager role with read-only access to teams to perform write operations on teams.

  • CVE-2024-28016MedMar 28, 2024
    risk 0.39cvss 6.0epss 0.00

    Improper Access Controlvulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP,…

  • CVE-2024-25121HigFeb 13, 2024
    risk 0.39cvss 7.1epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File Abstraction Layer (FAL) could be persisted directly via `DataHandler`. This allowed attackers to reference files in the fallback storage…

  • CVE-2023-31346MedFeb 13, 2024
    risk 0.39cvss 6.0epss 0.00

    Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

  • CVE-2023-20579MedFeb 13, 2024
    risk 0.39cvss 6.0epss 0.00

    Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.

  • CVE-2023-20260MedJan 17, 2024
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper processing of command line arguments to…

  • CVE-2023-2861MedDec 6, 2023
    risk 0.39cvss 6.0epss 0.00

    A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creating and opening a device file in the…

  • CVE-2023-32285MedAug 11, 2023
    risk 0.39cvss 6.0epss 0.00

    Improper access control in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2023-23908MedAug 11, 2023
    risk 0.39cvss 6.0epss 0.00

    Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2022-41261MedDec 12, 2022
    risk 0.39cvss 6.0epss 0.00

    SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data which can be used to access a configuration file which contains credentials to access other system files. Successful exploitation…

  • CVE-2022-2995HigSep 19, 2022
    risk 0.39cvss 7.1epss 0.00

    Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and…