VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 308 of 327
  • CVE-2026-41123MedJul 3, 2026
    risk 0.00cvss 4.3epss 0.00

    Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A…

  • CVE-2026-26145MedJul 2, 2026
    risk 0.00cvss 4.8epss 0.00

    Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-55119HigJul 2, 2026
    risk 0.00cvss 8.1epss 0.00

    A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.

  • CVE-2026-55118HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.

  • CVE-2026-55116CriJul 2, 2026
    risk 0.00cvss 9.0epss 0.00

    A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.

  • CVE-2026-55114HigJul 2, 2026
    risk 0.00cvss 8.8epss 0.00

    A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.

  • CVE-2026-55112HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.

  • CVE-2026-54408HigJul 2, 2026
    risk 0.00cvss 8.6epss 0.00

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.

  • CVE-2026-54407HigJul 2, 2026
    risk 0.00cvss 8.6epss 0.00

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.

  • CVE-2026-54400CriJul 2, 2026
    risk 0.00cvss 9.1epss 0.01

    A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.

  • CVE-2026-50746CriJul 2, 2026
    risk 0.00cvss 10.0epss 0.03

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.

  • CVE-2026-56334MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    Capgo before 12.128.2 lacks an UPDATE row-level security policy for the build_requests table, preventing API-key and anonymous access from persisting builder status updates. Attackers can exploit this missing policy to cause build status and error details to remain unpersisted,…

  • CVE-2025-24816MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could allow an authenticated attacker to retrieve confidential information beyond their assigned privileges.

  • CVE-2026-51221HigJun 29, 2026
    risk 0.00cvss 7.5epss 0.00

    A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a Denial of Service (DoS) via supplying a crafted Common Packet Format (CPF) packet.

  • CVE-2026-13568HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown code of the file /api/users_handler.php of the component User Registration Endpoint. This manipulation of the argument role causes improper access controls.…

  • CVE-2026-13553HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of the argument image can lead to unrestricted upload. It is possible to launch the…

  • CVE-2026-13547HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/resourceUpload/upload.do. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be…

  • CVE-2026-13544MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    A flaw has been found in Feehi CMS up to 2.1.1. Affected by this issue is some unknown functionality of the file /api/users of the component API. This manipulation causes improper access controls. The attack can be initiated remotely. The exploit has been published and may be…

  • CVE-2026-56823MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/integrations/webhooks/{webhook_id}/ping` endpoint fetches the target webhook by primary key alone without verifying that the…

  • CVE-2026-48529MedJun 26, 2026
    risk 0.00cvss 6.0epss 0.00

    GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCache is implemented as a process-global singleton initialized with the first authenticated user's GraphQL client. All subsequent…