VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 254 of 406
  • CVE-2026-35067MedJun 17, 2026
    risk 0.37cvss 5.7epss 0.00

    Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges and Unauthorized access.

  • CVE-2026-35241MedApr 21, 2026
    risk 0.37cvss 5.7epss 0.00

    Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-34248MedApr 8, 2026
    risk 0.37cvss 5.7epss 0.00

    Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means they can see each other's tickets) could see fields which are not intended for customers - including fields not intended for them at all (e.g. priority,…

  • CVE-2026-32007MedMar 19, 2026
    risk 0.37cvss 6.8epss 0.00

    OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that allows attackers with sandbox access to modify files outside the workspace directory by exploiting inconsistent enforcement of workspace-only checks on mounted…

  • CVE-2025-69257MedDec 30, 2025
    risk 0.37cvss 6.7epss 0.00

    theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.1.1, the application loads custom Python rules and configuration files from user-writable locations (e.g., `~/.config/theshit/`) without validating…

  • CVE-2024-13106MedJan 2, 2025
    risk 0.37cvss 5.3epss 0.27

    A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/form2IPQoSTcAdd of the component IP QoS Handler. The manipulation leads to improper access controls. The…

  • CVE-2024-11358MedDec 16, 2024
    risk 0.37cvss 5.7epss 0.00

    Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files via file provider.

  • CVE-2024-20695MedFeb 13, 2024
    risk 0.37cvss 5.7epss 0.01

    Skype for Business Information Disclosure Vulnerability

  • CVE-2023-6073MedNov 10, 2023
    risk 0.37cvss 5.7epss 0.00

    Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.

  • CVE-2022-4331MedMar 9, 2023
    risk 0.37cvss 5.7epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group,…

  • CVE-2022-44643MedDec 20, 2022
    risk 0.37cvss 5.7epss 0.00

    A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an access policy which has label selector restrictions also has been granted access to all tenants in the system, the label selector…

  • CVE-2022-3027MedSep 13, 2022
    risk 0.37cvss 5.7epss 0.00

    The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malicious name, including non-standard characters that, when the device attempts connecting to the malicious SSID, the device can be…

  • CVE-2022-26091MedApr 11, 2022
    risk 0.37cvss 5.7epss 0.00

    Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a function key of hardware keyboard.

  • CVE-2021-25991MedDec 29, 2021
    risk 0.37cvss 5.7epss 0.01

    In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.

  • CVE-2021-25501MedNov 5, 2021
    risk 0.37cvss 5.7epss 0.00

    An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.

  • CVE-2021-24752MedOct 18, 2021
    risk 0.37cvss 5.7epss 0.00

    Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3,…

  • CVE-2020-16844MedOct 1, 2020
    risk 0.37cvss 6.8epss 0.01

    In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffixes (e.g. *-some-suffix) for source principals or namespace fields, callers will never be denied access, bypassing the intended…

  • CVE-2020-7253MedMar 12, 2020
    risk 0.37cvss 5.7epss 0.00

    Improper access control vulnerability in masvc.exe in McAfee Agent (MA) prior to 5.6.4 allows local users with administrator privileges to disable self-protection via a McAfee supplied command-line utility.

  • CVE-2019-11894MedMay 29, 2019
    risk 0.37cvss 5.7epss 0.01

    A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in unauthorized download of a backup. In order to exploit the vulnerability, the adversary needs to download the backup…

  • CVE-2016-7244MedNov 10, 2016
    risk 0.37cvss 5.5epss 0.16

    Microsoft Office 2007 SP3 allows remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Office Denial of Service Vulnerability."