VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 279 of 327
  • CVE-2026-14235HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.00

    The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can…

  • CVE-2026-17457MedJul 26, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. Such manipulation of the argument url leads to information…

  • CVE-2026-17432MedJul 26, 2026
    risk 0.00cvss 5.0epss 0.00

    A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId…

  • CVE-2026-9765HigJul 24, 2026
    risk 0.00cvss 7.1epss 0.00

    Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and…

  • CVE-2026-15704CriJul 24, 2026
    risk 0.00cvss 9.8epss 0.00

    In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's…

  • CVE-2026-12702MedJul 24, 2026
    risk 0.00cvss epss 0.00

    In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.

  • CVE-2026-14603HigJul 24, 2026
    risk 0.00cvss 7.5epss 0.00

    The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.

  • CVE-2026-12688MedJul 24, 2026
    risk 0.00cvss 6.5epss 0.00

    The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification and mark any user as a paid member of any group without any payment being made.

  • CVE-2026-35425HigJul 24, 2026
    risk 0.00cvss 8.0epss 0.00

    Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

  • CVE-2026-65760CriJul 23, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.

  • CVE-2026-65759HigJul 23, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order…

  • CVE-2026-65758HigJul 23, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.

  • CVE-2026-65757HigJul 23, 2026
    risk 0.00cvss 8.1epss 0.00

    Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens.

  • CVE-2026-64876HigJul 23, 2026
    risk 0.00cvss 8.8epss 0.00

    Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.

  • CVE-2026-64871MedJul 23, 2026
    risk 0.00cvss 5.4epss 0.00

    Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission.

  • CVE-2024-58330HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.

  • CVE-2026-60372CriJul 22, 2026
    risk 0.00cvss 9.8epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2026-60371HigJul 22, 2026
    risk 0.00cvss 8.0epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with…

  • CVE-2026-60369CriJul 22, 2026
    risk 0.00cvss 9.9epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2026-60366CriJul 22, 2026
    risk 0.00cvss 10.0epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…