VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 317 of 406
  • CVE-2026-73372MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.

  • CVE-2026-73371MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.

  • CVE-2026-55986MedAug 13, 2026
    risk 0.28cvss 5.4epss 0.00

    Email Management API Bypasses ManageCredentials Feature Restrictions

  • CVE-2026-14859MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX actions, allowing any authenticated users such as Subscribers to create crowdfunding campaign posts despite not being granted that permission.

  • CVE-2026-18995MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the file src/renderer/services/artifactParser.ts of the component MEDIA Path Handler. This manipulation causes information disclosure. The attack is possible to be…

  • CVE-2026-70612MedAug 5, 2026
    risk 0.28cvss 5.4epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a…

  • CVE-2026-70481MedAug 4, 2026
    risk 0.28cvss 5.4epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checking that the caller wrote the message.…

  • CVE-2026-16295MedAug 4, 2026
    risk 0.28cvss 4.3epss 0.00

    The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such as a Subscriber to render admin-only settings pages and disclose their contents, including administrative nonces,…

  • CVE-2026-12698MedAug 4, 2026
    risk 0.28cvss 4.3epss 0.00

    The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile,…

  • CVE-2026-11872MedAug 2, 2026
    risk 0.28cvss 4.3epss 0.00

    The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings…

  • CVE-2026-45086MedJul 31, 2026
    risk 0.28cvss 5.4epss 0.00

    Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics questionnaire editor without the required administrator…

  • CVE-2026-18004MedJul 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-17994MedJul 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in Media in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-17976MedJul 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted domain name. (Chromium security severity: Low)

  • CVE-2026-17961MedJul 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in Session in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-17944MedJul 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-17781MedJul 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)

  • CVE-2026-46980MedJul 21, 2026
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mobile). Supported versions that are affected are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8 and …

  • CVE-2026-21954MedJul 21, 2026
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-16454MedJul 21, 2026
    risk 0.28cvss 4.3epss 0.00

    In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identified in the Direct Device Integration (DDI) Controller. This vulnerability allows an authenticated device to escalate its permissions and bypass the strict…