CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (6,523)
page 306 of 327| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-15518 | Med | 0.00 | 4.7 | 0.00 | Jul 13, 2026 | A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryController::storeFile of the file src/Http/Controllers/Admin/FileLibraryController.php of the component Media Library Insert Page. Such manipulation of the argument… | ||
| CVE-2026-15488 | — | Hig | 0.00 | 7.3 | 0.00 | Jul 12, 2026 | A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileController::upload of the file app/common/controller/FileController.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched… | |
| CVE-2026-15476 | Med | 0.00 | 5.3 | 0.00 | Jul 12, 2026 | A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack can only be performed from a local… | ||
| CVE-2026-15475 | Med | 0.00 | 5.3 | 0.00 | Jul 12, 2026 | A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. This manipulation causes improper access controls. The attack can only be executed locally. The… | ||
| CVE-2026-56335 | Med | 0.00 | 6.5 | 0.00 | Jul 10, 2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration fields through PostgREST by exploiting a null authentication check in the immutability trigger. Attackers with write API keys can… | ||
| CVE-2026-40452 | Hig | 0.00 | 7.5 | 0.00 | Jul 10, 2026 | Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users. This issue affects Apache IoTDB: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10. … | ||
| CVE-2026-40009 | Med | 0.00 | 6.5 | 0.00 | Jul 10, 2026 | Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor. This issue affects Apache IoTDB: from 2.0.8 before 2.0.10. Users are recommended to… | ||
| CVE-2026-15329 | Med | 0.00 | 4.3 | 0.00 | Jul 10, 2026 | A vulnerability was found in zhayujie CowAgent up to 2.1.0. This issue affects the function BrowserTool._do_navigate of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in information disclosure. The attack can be… | ||
| CVE-2026-15319 | Hig | 0.00 | 7.3 | 0.00 | Jul 10, 2026 | A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the file web/backend/middleware/access_control.go of the component Launcher. Such manipulation leads to improper access controls. The attack may be performed from… | ||
| CVE-2025-45422 | Hig | 0.00 | 8.1 | 0.00 | Jul 9, 2026 | Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes to port forwarding rules. | ||
| CVE-2025-63579 | Hig | 0.00 | 7.5 | 0.00 | Jul 9, 2026 | Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypted. Passwords and other sensitive… | ||
| CVE-2026-59720 | Hig | 0.00 | 7.5 | 0.00 | Jul 9, 2026 | Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPublic input field while schema.prisma defaults isPublic to true, causing mock servers linked to private collections to be publicly… | ||
| CVE-2026-15188 | Med | 0.00 | 6.3 | 0.00 | Jul 9, 2026 | A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affected by this vulnerability is the function EditEmployeeProfileAPIView of the file accounts/api/views.py of the component Employee Dashboard Endpoint. This… | ||
| CVE-2026-58525 | Hig | 0.00 | 8.2 | 0.00 | Jul 8, 2026 | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-56217 | Med | 0.00 | 4.3 | 0.00 | Jul 8, 2026 | Capgo before 12.128.2 contains a policy bypass vulnerability in app_versions update enforcement that allows app-scoped API keys to downgrade encrypted bundles to non-encrypted state. Attackers with app-scoped all API keys can directly update the app_versions table via PostgREST… | ||
| CVE-2026-48958 | Hig | 0.00 | 8.8 | 0.00 | Jul 7, 2026 | An improper access check allows unauthorized users to create custom fields via webservices endpoints. | ||
| CVE-2026-48957 | Hig | 0.00 | 8.8 | 0.00 | Jul 7, 2026 | An improper access check allows unauthorized users to access com_privacy datasets. | ||
| CVE-2026-48956 | Med | 0.00 | 5.0 | 0.00 | Jul 7, 2026 | An improper access check allows users to display a list of modules in the frontend. | ||
| CVE-2026-48955 | Med | 0.00 | 6.5 | 0.00 | Jul 7, 2026 | An improper access check allows unauthorized users to access workflow stage and transition information. | ||
| CVE-2026-48948 | Hig | 0.00 | 8.8 | 0.00 | Jul 7, 2026 | An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. |
- risk 0.00cvss 4.7epss 0.00
A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryController::storeFile of the file src/Http/Controllers/Admin/FileLibraryController.php of the component Media Library Insert Page. Such manipulation of the argument…
- risk 0.00cvss 7.3epss 0.00
A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileController::upload of the file app/common/controller/FileController.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched…
- risk 0.00cvss 5.3epss 0.00
A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack can only be performed from a local…
- risk 0.00cvss 5.3epss 0.00
A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. This manipulation causes improper access controls. The attack can only be executed locally. The…
- risk 0.00cvss 6.5epss 0.00
Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration fields through PostgREST by exploiting a null authentication check in the immutability trigger. Attackers with write API keys can…
- risk 0.00cvss 7.5epss 0.00
Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users. This issue affects Apache IoTDB: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10. …
- risk 0.00cvss 6.5epss 0.00
Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor. This issue affects Apache IoTDB: from 2.0.8 before 2.0.10. Users are recommended to…
- risk 0.00cvss 4.3epss 0.00
A vulnerability was found in zhayujie CowAgent up to 2.1.0. This issue affects the function BrowserTool._do_navigate of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in information disclosure. The attack can be…
- risk 0.00cvss 7.3epss 0.00
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the file web/backend/middleware/access_control.go of the component Launcher. Such manipulation leads to improper access controls. The attack may be performed from…
- risk 0.00cvss 8.1epss 0.00
Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes to port forwarding rules.
- risk 0.00cvss 7.5epss 0.00
Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypted. Passwords and other sensitive…
- risk 0.00cvss 7.5epss 0.00
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPublic input field while schema.prisma defaults isPublic to true, causing mock servers linked to private collections to be publicly…
- risk 0.00cvss 6.3epss 0.00
A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affected by this vulnerability is the function EditEmployeeProfileAPIView of the file accounts/api/views.py of the component Employee Dashboard Endpoint. This…
- risk 0.00cvss 8.2epss 0.00
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.00cvss 4.3epss 0.00
Capgo before 12.128.2 contains a policy bypass vulnerability in app_versions update enforcement that allows app-scoped API keys to downgrade encrypted bundles to non-encrypted state. Attackers with app-scoped all API keys can directly update the app_versions table via PostgREST…
- risk 0.00cvss 8.8epss 0.00
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
- risk 0.00cvss 8.8epss 0.00
An improper access check allows unauthorized users to access com_privacy datasets.
- risk 0.00cvss 5.0epss 0.00
An improper access check allows users to display a list of modules in the frontend.
- risk 0.00cvss 6.5epss 0.00
An improper access check allows unauthorized users to access workflow stage and transition information.
- risk 0.00cvss 8.8epss 0.00
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.