VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 284 of 406
  • CVE-2026-86217MedSep 6, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched…

  • CVE-2026-86179MedSep 6, 2026
    risk 0.34cvss 5.3epss 0.01

    A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the…

  • CVE-2026-84936MedSep 5, 2026
    risk 0.34cvss 5.3epss 0.00

    The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests using the site's own configured API key, and to create an…

  • CVE-2026-85517MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.01

    A flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown function of the file /vehicle_management.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. It is possible to…

  • CVE-2026-85401MedSep 4, 2026
    risk 0.34cvss 6.3epss 0.00

    A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy File Manager. Executing a manipulation can lead to improper…

  • CVE-2026-85135MedSep 3, 2026
    risk 0.34cvss 6.3epss 0.00

    A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This affects the function ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject of the file Services/Repository/Service/Resources/ZipAdapter.php of the component MediaPool. The manipulation results in…

  • CVE-2026-51761MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51752MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-53682MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal,…

  • CVE-2026-51745MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51737MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase traceroute logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51732MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51727MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the SystemSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve administrative import and export endpoint information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-82624MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.01

    A flaw has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file inventorymanagement.sql of the component Database Backup File Handler. This manipulation causes information disclosure. The attack may be…

  • CVE-2026-82548MedAug 30, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the component InitialUEMessage Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been publicly disclosed…

  • CVE-2026-37067MedAug 27, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request.

  • CVE-2026-64896MedAug 27, 2026
    risk 0.34cvss —epss 0.00

    Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: before 31.6.

  • CVE-2026-16986MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied request values instead, so an unauthenticated attacker can pay an arbitrary fraction of a…

  • CVE-2026-16738MedAug 22, 2026
    risk 0.34cvss 5.3epss 0.00

    The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as…

  • CVE-2026-13736MedAug 21, 2026
    risk 0.34cvss 5.3epss 0.00

    The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.