VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 318 of 406
  • CVE-2026-14614MedJul 3, 2026
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client…

  • CVE-2026-14613MedJul 3, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a…

  • CVE-2026-14052MedJun 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Insufficient policy enforcement in FileSystem in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-14034MedJun 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-14003MedJun 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)

  • CVE-2026-35162MedJun 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2026-11890MedJun 16, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve account discovery scan results.

  • CVE-2026-12212MedJun 15, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in hcengineering Huly Platform up to 0.7.0. Affected is the function getMailboxSecret of the file server/account/src/operations.ts of the component RPC Interface. The manipulation leads to improper access controls. The attack may be initiated…

  • CVE-2026-44783MedJun 12, 2026
    risk 0.28cvss 5.4epss 0.00

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a flaw in how replies to whisper posts are handled allows authenticated users outside the groups…

  • CVE-2026-11466MedJun 7, 2026
    risk 0.28cvss 5.4epss 0.00

    A weakness has been identified in zilliztech deep-searcher up to 0.0.2. This affects the function CollectionRouter.invoke of the file deepsearcher/agent/collection_router.py. This manipulation of the argument kwargs causes improper access controls. Remote exploitation of the…

  • CVE-2026-45776MedJun 5, 2026
    risk 0.28cvss 4.3epss 0.00

    OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's access control logic allows an attacker to submit a crafted HTTPS POST request that sets a session variable used for authorization decisions. If an…

  • CVE-2026-11302MedJun 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-11277MedJun 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-11274MedJun 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in DOM Distiller in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-11257MedJun 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in Browser in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-11252MedJun 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Insufficient policy enforcement in Content Settings in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-11212MedJun 4, 2026
    risk 0.28cvss 4.3epss 0.00

    Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)

  • CVE-2026-48900MedMay 26, 2026
    risk 0.28cvss 4.3epss 0.00

    An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.

  • CVE-2026-9223MedMay 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.

  • CVE-2026-5171MedMay 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request. This issue affects : * Devolutions…