VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 304 of 327
  • CVE-2026-16324HigJul 20, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qnaire/upload.jsp. Such manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The…

  • CVE-2026-62414CriJul 20, 2026
    risk 0.00cvss 9.1epss 0.00

    Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.

  • CVE-2026-60030HigJul 20, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management…

  • CVE-2026-12972MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.

  • CVE-2026-16226MedJul 19, 2026
    risk 0.00cvss 4.7epss 0.00

    A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely.

  • CVE-2026-16201MedJul 19, 2026
    risk 0.00cvss 5.3epss 0.00

    A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of the component http_request. The manipulation results in information disclosure. The attack can be executed remotely. The exploit…

  • CVE-2026-51083MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords via the cloudinit/dump API.

  • CVE-2026-41993MedJul 17, 2026
    risk 0.00cvss 4.4epss 0.00

    Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a local attacker with administrator privileges to bypass the file lockdown mechanism, resulting in unauthorized file transfer to the victim device. The attacker…

  • CVE-2026-46353HigJul 16, 2026
    risk 0.00cvss 8.1epss 0.00

    BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUrl parameter was supplied to API request handling in CreateMeeting.java and ValidationService.java, allowing a user to send valid…

  • CVE-2026-55548MedJul 16, 2026
    risk 0.00cvss 4.3epss 0.00

    Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request omitted specific packet names: with an empty…

  • CVE-2026-35148MedJul 16, 2026
    risk 0.00cvss 6.3epss 0.00

    HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without…

  • CVE-2026-55234HigJul 15, 2026
    risk 0.00cvss 8.5epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored source boardId and do not validate a new boardId in the update…

  • CVE-2026-45313HigJul 15, 2026
    risk 0.00cvss 7.7epss 0.00

    Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a GUI_WND_HOOK_REGISTER request without validating that the…

  • CVE-2026-46485HigJul 15, 2026
    risk 0.00cvss 8.2epss 0.00

    Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing…

  • CVE-2026-14960CriJul 15, 2026
    risk 0.00cvss 9.8epss 0.00

    Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_READ` and `TDE_IOCTL_INDEXIO_WRITE` permit unprivileged user-mode callers to perform arbitrary hardware I/O…

  • CVE-2026-47164HigJul 15, 2026
    risk 0.00cvss 7.7epss 0.00

    Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation and not when SSO_SIGNUPS_MATCH_EMAIL=true linked an IdP identity to an existing local account, allowing an…

  • CVE-2026-36035MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.00

    Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (DoS) via removing the license from the webserver.

  • CVE-2026-47301HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-58617HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-58545MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.