VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 262 of 327
  • CVE-2022-26308LowAug 1, 2022
    risk 0.24cvss 3.7epss 0.00

    Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role.

  • CVE-2021-25956MedAug 17, 2021
    risk 0.24cvss 4.7epss 0.01

    In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account takeover of…

  • CVE-2021-26909LowApr 23, 2021
    risk 0.24cvss 3.7epss 0.01

    Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which could be brute-forced by an attacker to subvert an organization's security program. The issue has since been fixed in version 31 of the Automox Agent.

  • CVE-2015-2687MedAug 9, 2017
    risk 0.24cvss 4.7epss 0.00

    OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes that they would normally not have permissions for.

  • CVE-2016-8330LowJan 27, 2017
    risk 0.24cvss 3.7epss 0.01

    Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise…

  • CVE-2016-0208LowMar 14, 2016
    risk 0.24cvss 3.7epss 0.01

    IBM WebSphere Commerce 6.x through 6.0.0.11, 7.x through 7.0.0.9, and 8.x before 8.0.0.3 allows remote attackers to cause a denial of service (order-processing outage) via unspecified vectors.

  • CVE-2026-60347LowJul 21, 2026
    risk 0.23cvss 3.6epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows low privileged attacker with logon to the…

  • CVE-2025-15619LowJun 23, 2026
    risk 0.23cvss 3.5epss 0.00

    HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.

  • CVE-2026-45284MedJun 1, 2026
    risk 0.23cvss 4.6epss 0.00

    Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authenticate towards user OIDC after they where deleted. This issue has been patched in version 8.4.0.

  • CVE-2026-41398MedApr 28, 2026
    risk 0.23cvss 4.6epss 0.00

    OpenClaw before 2026.4.2 contains an improper access control vulnerability in the iOS A2UI bridge that treats generic local-network pages as trusted origins. Attackers can inject unauthorized agent.request runs by loading attacker-controlled pages from local-network or tailnet…

  • CVE-2026-7021LowApr 26, 2026
    risk 0.23cvss 3.5epss 0.00

    A weakness has been identified in SmythOS sre up to 0.0.15. This impacts an unknown function of the file packages/sdk/src/LLM/utils.ts of the component Connector Service. This manipulation of the argument baseURL causes information disclosure. It is possible to initiate the…

  • CVE-2026-24509LowMar 11, 2026
    risk 0.23cvss 3.6epss 0.00

    Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.

  • CVE-2025-64746MedNov 13, 2025
    risk 0.23cvss 4.6epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does not properly clean up field-level permissions when a field is deleted. When a field is removed from a collection, its reference in the permissions table…

  • CVE-2025-55795LowSep 29, 2025
    risk 0.23cvss 3.5epss 0.00

    The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email update workflows. An authenticated attacker controlling a user account with a lower user ID can update their email address to that of…

  • CVE-2025-11026LowSep 26, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in givanz Vvveb up to 1.0.7.2. Affected by this vulnerability is an unknown functionality of the component Configuration File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-27238LowSep 12, 2025
    risk 0.23cvss 3.5epss 0.00

    Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.

  • CVE-2025-30731LowApr 15, 2025
    risk 0.23cvss 3.6epss 0.00

    Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration). Supported versions that are affected are 12.2.3-12.2.14. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure…

  • CVE-2025-30700LowApr 15, 2025
    risk 0.23cvss 3.5epss 0.00

    Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Solaris. …

  • CVE-2025-24429LowFeb 11, 2025
    risk 0.23cvss 3.5epss 0.00

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass allowing read only access. A low-privileged attacker could leverage this…

  • CVE-2024-36261LowSep 16, 2024
    risk 0.23cvss 3.5epss 0.00

    Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via adjacent access.