VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 283 of 406
  • CVE-2026-90976MedSep 18, 2026
    risk 0.34cvss 5.3epss 0.00

    The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an account in its registration handler, allowing unauthenticated users to create accounts even when the site has registration disabled.

  • CVE-2026-85123MedSep 18, 2026
    risk 0.34cvss 5.3epss 0.00

    The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to create WordPress accounts on a site whose owner has disabled registration.

  • CVE-2026-92927MedSep 17, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendor.sql. Performing a manipulation results in information disclosure. The attack is possible to be carried out remotely. The…

  • CVE-2026-90922MedSep 17, 2026
    risk 0.34cvss 5.3epss 0.00

    The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower…

  • CVE-2026-20121MedSep 16, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass…

  • CVE-2026-87267MedSep 15, 2026
    risk 0.34cvss 5.3epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with network access via RDP to compromise Oracle VM VirtualBox. …

  • CVE-2026-83109MedSep 15, 2026
    risk 0.34cvss 5.3epss 0.00

    Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP…

  • CVE-2026-90881MedSep 15, 2026
    risk 0.34cvss 5.3epss 0.01

    A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit has been made…

  • CVE-2026-90565MedSep 13, 2026
    risk 0.34cvss 5.3epss 0.01

    A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid results in improper access controls. It is…

  • CVE-2026-87918MedSep 12, 2026
    risk 0.34cvss 5.3epss 0.00

    The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, and consume the associated cost, using…

  • CVE-2026-87892MedSep 12, 2026
    risk 0.34cvss 5.3epss 0.00

    The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to…

  • CVE-2026-77689MedSep 12, 2026
    risk 0.34cvss 5.3epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never…

  • CVE-2026-73789MedSep 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthenticated remote attacker to manipulate account settings. Successful exploitation could allow an attacker to extend network access beyond policy limits, leading…

  • CVE-2026-86774MedSep 9, 2026
    risk 0.34cvss 6.3epss 0.00

    Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset Model records without the required…

  • CVE-2026-19625MedSep 8, 2026
    risk 0.34cvss 5.3epss 0.00

    When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also…

  • CVE-2026-86672MedSep 8, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component Backup Handler. The manipulation leads to information disclosure. The attack can be…

  • CVE-2026-86519MedSep 8, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has…

  • CVE-2026-86308MedSep 7, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unknown processing of the file App/Common/Conf/config.php of the component Debug Mode. The manipulation of the argument…

  • CVE-2026-86302MedSep 7, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /HIS/his.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. Remote…

  • CVE-2026-86239MedSep 7, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The manipulation leads to unrestricted upload. Remote exploitation of…