CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (6,523)
page 305 of 327| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-57088 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-56157 | Med | 0.00 | 5.4 | 0.00 | Jul 14, 2026 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-50495 | Med | 0.00 | 6.1 | 0.00 | Jul 14, 2026 | Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | ||
| CVE-2026-50465 | Hig | 0.00 | 7.1 | 0.00 | Jul 14, 2026 | Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | ||
| CVE-2026-50423 | Hig | 0.00 | 7.8 | 0.03 | Jul 14, 2026 | Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50418 | Med | 0.00 | 5.1 | 0.00 | Jul 14, 2026 | Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2026-50373 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50335 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-55014 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50351 | Hig | 0.00 | 7.8 | 0.03 | Jul 14, 2026 | Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50342 | Hig | 0.00 | 8.8 | 0.00 | Jul 14, 2026 | Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50325 | Hig | 0.00 | 7.0 | 0.00 | Jul 14, 2026 | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50311 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50297 | Hig | 0.00 | 7.0 | 0.00 | Jul 14, 2026 | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-49805 | Hig | 0.00 | 7.0 | 0.03 | Jul 14, 2026 | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-15677 | Hig | 0.00 | 7.3 | 0.00 | Jul 14, 2026 | A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been… | ||
| CVE-2026-15627 | Med | 0.00 | 4.3 | 0.00 | Jul 14, 2026 | A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This vulnerability affects the function handleNavigate of the file pkg/browser/tool.go. Such manipulation of the argument args.targetUrl leads to information disclosure. The attack may be performed… | ||
| CVE-2026-57855 | Hig | 0.00 | 8.8 | 0.00 | Jul 13, 2026 | Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, rename, createfolder) without performing any ACL or role… | ||
| CVE-2026-15539 | Med | 0.00 | 4.7 | 0.00 | Jul 13, 2026 | A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. Such manipulation leads to unrestricted upload. The attack may be… | ||
| CVE-2026-15530 | Med | 0.00 | 5.3 | 0.00 | Jul 13, 2026 | A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /index.php?m=attachment&f=index&v=upload of the component Attachment API. Executing a manipulation can lead to information disclosure. The attack can be… |
- risk 0.00cvss 7.8epss 0.00
Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 5.4epss 0.00
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.00cvss 6.1epss 0.00
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
- risk 0.00cvss 7.1epss 0.00
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
- risk 0.00cvss 7.8epss 0.03
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 5.1epss 0.00
Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.
- risk 0.00cvss 7.8epss 0.00
Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.03
Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 8.8epss 0.00
Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.0epss 0.00
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.0epss 0.00
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.0epss 0.03
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.3epss 0.00
A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been…
- risk 0.00cvss 4.3epss 0.00
A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This vulnerability affects the function handleNavigate of the file pkg/browser/tool.go. Such manipulation of the argument args.targetUrl leads to information disclosure. The attack may be performed…
- risk 0.00cvss 8.8epss 0.00
Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, rename, createfolder) without performing any ACL or role…
- risk 0.00cvss 4.7epss 0.00
A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. Such manipulation leads to unrestricted upload. The attack may be…
- risk 0.00cvss 5.3epss 0.00
A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /index.php?m=attachment&f=index&v=upload of the component Attachment API. Executing a manipulation can lead to information disclosure. The attack can be…