VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 255 of 327
  • CVE-2026-31950MedMar 27, 2026
    risk 0.27cvss 5.3epss 0.00

    LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoint `/api/agents/chat/stream/:streamId` does not verify that the requesting user owns the stream. Any authenticated user who obtains or guesses a valid stream…

  • CVE-2026-32002MedMar 19, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails to enforce tools.fs.workspaceOnly restrictions on mounted sandbox paths, allowing attackers to read out-of-workspace files. Attackers can load restricted mounted…

  • CVE-2026-31815MedMar 10, 2026
    risk 0.27cvss 5.3epss 0.00

    Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipulation is possible in django-unicorn due to missing access control checks during property updates and method calls. An attacker can bypass the intended…

  • CVE-2026-2742MedMar 10, 2026
    risk 0.27cvss 5.3epss 0.00

    An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24.9.7 and 25.0.0 through 25.0.1, applications using Spring Security due to inconsistent path pattern matching of reserved framework paths. Accessing the…

  • CVE-2026-26977MedFeb 20, 2026
    risk 0.27cvss 5.3epss 0.00

    Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized users are able to access the details of unpublished courses via API endpoints. A fix for this issue is planned for the 2.45.0 release.

  • CVE-2026-24473MedJan 27, 2026
    risk 0.27cvss 5.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve static Middleware for the Cloudflare Workers adapter contains an information disclosure vulnerability that may allow attackers to read arbitrary keys from the…

  • CVE-2025-68949MedJan 13, 2026
    risk 0.27cvss 5.3epss 0.00

    n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string matching instead of exact IP comparison. As a result, an incoming request could be accepted if the source IP address merely…

  • CVE-2025-64400MedDec 18, 2025
    risk 0.27cvss 4.1epss 0.00

    Control Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. The API for creating users checks that the account requesting a user creation has `edit` on the enrollment-level user directory, but is missing a separate check…

  • CVE-2025-64483MedNov 21, 2025
    risk 0.27cvss epss 0.00

    Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configuration in certain configurations allows authenticated users with read-only API roles to retrieve agent enrollment credentials…

  • CVE-2025-58752MedSep 8, 2025
    risk 0.27cvss 5.3epss 0.01

    Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or…

  • CVE-2025-48202MedMay 21, 2025
    risk 0.27cvss 5.3epss 0.00

    The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference.

  • CVE-2024-30146MedApr 30, 2025
    risk 0.27cvss 4.1epss 0.00

    Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.

  • CVE-2024-30148MedApr 24, 2025
    risk 0.27cvss 4.1epss 0.00

    Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.

  • CVE-2025-0968MedFeb 19, 2025
    risk 0.27cvss 5.3epss 0.00

    The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content() function. This makes it possible for unauthenticated attackers to…

  • CVE-2024-12294MedDec 11, 2024
    risk 0.27cvss 5.3epss 0.00

    The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the 'get_legacy_cookies' function. This makes it possible for unauthenticated attackers to extract sensitive data including…

  • CVE-2024-10393MedNov 21, 2024
    risk 0.27cvss 5.3epss 0.01

    The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes it possible for unauthenticated attackers…

  • CVE-2024-50353MedOct 30, 2024
    risk 0.27cvss 5.3epss 0.00

    ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files for cloud upload. Users of this library that set a duration for a SAS Uri with a value other than 1 hour may have generated a URL with a duration that is…

  • CVE-2024-42795MedSep 16, 2024
    risk 0.27cvss 4.2epss 0.00

    An Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_user&id=3 in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to view valid user details.

  • CVE-2024-0104MedAug 8, 2024
    risk 0.27cvss 4.2epss 0.00

    NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.

  • CVE-2024-42354MedAug 8, 2024
    risk 0.27cvss 5.3epss 0.00

    Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be marked as ApiAware in the EntityDefinition. So only ApiAware fields of the EntityDefinition will be encoded to the final JSON. Prior…