VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 306 of 327
  • CVE-2026-15518MedJul 13, 2026
    risk 0.00cvss 4.7epss 0.00

    A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryController::storeFile of the file src/Http/Controllers/Admin/FileLibraryController.php of the component Media Library Insert Page. Such manipulation of the argument…

  • CVE-2026-15488HigJul 12, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileController::upload of the file app/common/controller/FileController.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched…

  • CVE-2026-15476MedJul 12, 2026
    risk 0.00cvss 5.3epss 0.00

    A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack can only be performed from a local…

  • CVE-2026-15475MedJul 12, 2026
    risk 0.00cvss 5.3epss 0.00

    A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. This manipulation causes improper access controls. The attack can only be executed locally. The…

  • CVE-2026-56335MedJul 10, 2026
    risk 0.00cvss 6.5epss 0.00

    Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration fields through PostgREST by exploiting a null authentication check in the immutability trigger. Attackers with write API keys can…

  • CVE-2026-40452HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.00

    Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users. This issue affects Apache IoTDB: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10. …

  • CVE-2026-40009MedJul 10, 2026
    risk 0.00cvss 6.5epss 0.00

    Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor. This issue affects Apache IoTDB: from 2.0.8 before 2.0.10. Users are recommended to…

  • CVE-2026-15329MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in zhayujie CowAgent up to 2.1.0. This issue affects the function BrowserTool._do_navigate of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in information disclosure. The attack can be…

  • CVE-2026-15319HigJul 10, 2026
    risk 0.00cvss 7.3epss 0.00

    A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the file web/backend/middleware/access_control.go of the component Launcher. Such manipulation leads to improper access controls. The attack may be performed from…

  • CVE-2025-45422HigJul 9, 2026
    risk 0.00cvss 8.1epss 0.00

    Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes to port forwarding rules.

  • CVE-2025-63579HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypted. Passwords and other sensitive…

  • CVE-2026-59720HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPublic input field while schema.prisma defaults isPublic to true, causing mock servers linked to private collections to be publicly…

  • CVE-2026-15188MedJul 9, 2026
    risk 0.00cvss 6.3epss 0.00

    A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affected by this vulnerability is the function EditEmployeeProfileAPIView of the file accounts/api/views.py of the component Employee Dashboard Endpoint. This…

  • CVE-2026-58525HigJul 8, 2026
    risk 0.00cvss 8.2epss 0.00

    Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-56217MedJul 8, 2026
    risk 0.00cvss 4.3epss 0.00

    Capgo before 12.128.2 contains a policy bypass vulnerability in app_versions update enforcement that allows app-scoped API keys to downgrade encrypted bundles to non-encrypted state. Attackers with app-scoped all API keys can directly update the app_versions table via PostgREST…

  • CVE-2026-48958HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    An improper access check allows unauthorized users to create custom fields via webservices endpoints.

  • CVE-2026-48957HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    An improper access check allows unauthorized users to access com_privacy datasets.

  • CVE-2026-48956MedJul 7, 2026
    risk 0.00cvss 5.0epss 0.00

    An improper access check allows users to display a list of modules in the frontend.

  • CVE-2026-48955MedJul 7, 2026
    risk 0.00cvss 6.5epss 0.00

    An improper access check allows unauthorized users to access workflow stage and transition information.

  • CVE-2026-48948HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.