VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 299 of 406
  • CVE-2026-82486MedAug 30, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument SecurityKey results in improper access controls. Remote exploitation of the attack is…

  • CVE-2026-77997MedAug 25, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about arbitrary modules without the respective com_modules…

  • CVE-2026-62460MedAug 18, 2026
    risk 0.33cvss 5.0epss 0.00

    Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2026-71570MedAug 14, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_icagenda` only could enumerate Joomla user profiles.

  • CVE-2026-56755MedAug 13, 2026
    risk 0.33cvss 6.2epss 0.00

    Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload

  • CVE-2026-56657MedAug 13, 2026
    risk 0.33cvss 6.2epss 0.00

    Gitea SSH Key Parser Denial of Service

  • CVE-2026-60907MedJul 21, 2026
    risk 0.33cvss 5.0epss 0.00

    Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.4-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-41985MedJun 9, 2026
    risk 0.33cvss 5.1epss 0.00

    UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2026-41704MedMay 27, 2026
    risk 0.33cvss 5.0epss 0.00

    AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every response, which reads response['value']['result']['compile_log_id'] (line 332-338) and passes it to download_and_delete_blob. Separately, any response containing…

  • CVE-2026-35248MedApr 21, 2026
    risk 0.33cvss 5.0epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…

  • CVE-2026-27646MedMar 23, 2026
    risk 0.33cvss 6.1epss 0.00

    OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authorized sandboxed sessions to initialize host-side ACP runtime. Attackers can bypass sandbox restrictions by invoking the /acp spawn slash-command to cross from…

  • CVE-2026-0977MedMar 16, 2026
    risk 0.33cvss 5.1epss 0.00

    IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to improper access controls.

  • CVE-2026-29060MedMar 6, 2026
    risk 0.33cvss 5.0epss 0.00

    Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a registered user without privileges to create or modify file requests is able to create a short-lived API key that has the permission to do so. The user must be…

  • CVE-2025-64706MedNov 13, 2025
    risk 0.33cvss 5.0epss 0.00

    Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Object Reference (IDOR) vulnerability exists in the API token management endpoint. An authenticated attacker can delete any user's API token and retrieve its value…

  • CVE-2025-11281MedOct 5, 2025
    risk 0.33cvss 5.0epss 0.00

    A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished Course Handler. Such manipulation leads to improper access controls. The attack may be launched remotely. This attack is…

  • CVE-2023-50300MedOct 1, 2025
    risk 0.33cvss 5.1epss 0.00

    IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper access controls.

  • CVE-2025-3768MedJun 5, 2025
    risk 0.33cvss 5.0epss 0.00

    Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor blocking feature when the Devolutions hosted endpoint is not reachable.

  • CVE-2025-0691MedJun 5, 2025
    risk 0.33cvss 5.0epss 0.00

    Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permission" permission by bypassing the client side validation.

  • CVE-2025-4901MedMay 19, 2025
    risk 0.33cvss 4.3epss 0.77

    A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub_41E304 of the file /H5/state_view.data of the component HTTP Endpoint. The manipulation leads to information disclosure. The attack…

  • CVE-2025-20076MedMay 13, 2025
    risk 0.33cvss 5.0epss 0.00

    Improper access control for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.