VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 305 of 327
  • CVE-2026-57088HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-56157MedJul 14, 2026
    risk 0.00cvss 5.4epss 0.00

    Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-50495MedJul 14, 2026
    risk 0.00cvss 6.1epss 0.00

    Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

  • CVE-2026-50465HigJul 14, 2026
    risk 0.00cvss 7.1epss 0.00

    Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

  • CVE-2026-50423HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.03

    Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50418MedJul 14, 2026
    risk 0.00cvss 5.1epss 0.00

    Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2026-50373HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50335HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55014HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50351HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.03

    Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50342HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50325HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50311HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50297HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49805HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.03

    Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

  • CVE-2026-15677HigJul 14, 2026
    risk 0.00cvss 7.3epss 0.00

    A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been…

  • CVE-2026-15627MedJul 14, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This vulnerability affects the function handleNavigate of the file pkg/browser/tool.go. Such manipulation of the argument args.targetUrl leads to information disclosure. The attack may be performed…

  • CVE-2026-57855HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.00

    Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, rename, createfolder) without performing any ACL or role…

  • CVE-2026-15539MedJul 13, 2026
    risk 0.00cvss 4.7epss 0.00

    A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. Such manipulation leads to unrestricted upload. The attack may be…

  • CVE-2026-15530MedJul 13, 2026
    risk 0.00cvss 5.3epss 0.00

    A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /index.php?m=attachment&f=index&v=upload of the component Attachment API. Executing a manipulation can lead to information disclosure. The attack can be…