VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 307 of 327
  • CVE-2026-48947MedJul 7, 2026
    risk 0.00cvss 4.9epss 0.00

    An improper access check allows privileged users to overwrite media files without editing permissions.

  • CVE-2026-24014CriJul 6, 2026
    risk 0.00cvss 9.8epss 0.01

    Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal…

  • CVE-2026-14777MedJul 6, 2026
    risk 0.00cvss 6.3epss 0.00

    A weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this issue is some unknown functionality of the file /announcements.php. Executing a manipulation can lead to unrestricted upload. The attack can be executed…

  • CVE-2026-14776MedJul 5, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is the function pathinfo of the file /upload_files.php of the component Filename Extension. Performing a manipulation results in unrestricted…

  • CVE-2026-14775MedJul 5, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /process_lesson.php. Such manipulation of the argument user_id leads to unrestricted upload. The attack may be launched remotely. The…

  • CVE-2026-9085HigJul 5, 2026
    risk 0.00cvss 8.8epss 0.00

    Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Control allows DNS Spoofing. This issue affects Pardus-Parental-Control: from <=0.5.1 before 0.7.0.

  • CVE-2026-14736HigJul 5, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was found in Ruijie RG-UAC up to 1.0-R1.8.2.p5. The impacted element is an unknown function of the file user_auth_commit.php. Performing a manipulation of the argument upload_image results in unrestricted upload. The attack is possible to be carried out remotely.…

  • CVE-2026-14698MedJul 5, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management and Examination System 1.0. Impacted is an unknown function of the file upload_files.php. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely.…

  • CVE-2025-71380HigJul 4, 2026
    risk 0.00cvss 8.8epss 0.00

    The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading to data exfiltration, service…

  • CVE-2026-58523MedJul 3, 2026
    risk 0.00cvss 6.5epss 0.00

    Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-58286HigJul 3, 2026
    risk 0.00cvss 8.1epss 0.00

    Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-58282HigJul 3, 2026
    risk 0.00cvss 8.1epss 0.00

    Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-27779HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.

  • CVE-2026-27660HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.

  • CVE-2026-26292CriJul 3, 2026
    risk 0.00cvss 9.8epss 0.00

    Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.

  • CVE-2026-26247CriJul 3, 2026
    risk 0.00cvss 9.1epss 0.00

    Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.

  • CVE-2026-25712HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.

  • CVE-2026-24690HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.

  • CVE-2026-24451HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.

  • CVE-2026-20909MedJul 3, 2026
    risk 0.00cvss 5.3epss 0.00

    Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.