VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,083)

page 32 of 405
  • CVE-2026-62582CriAug 18, 2026
    risk 0.62cvss 9.6epss 0.00

    Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2026-62463CriAug 18, 2026
    risk 0.62cvss 9.6epss 0.00

    Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-61001CriAug 18, 2026
    risk 0.62cvss 9.6epss 0.00

    Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2026-60905CriAug 18, 2026
    risk 0.62cvss 9.6epss 0.00

    Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-60861CriAug 18, 2026
    risk 0.62cvss 9.6epss 0.00

    Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle…

  • CVE-2026-56161CriAug 7, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

  • CVE-2026-61097CriJul 21, 2026
    risk 0.62cvss 9.6epss 0.00

    Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network…

  • CVE-2026-60773CriJul 21, 2026
    risk 0.62cvss 9.6epss 0.00

    Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise…

  • CVE-2026-28381CriJun 22, 2026
    risk 0.62cvss 9.6epss 0.00

    The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.

  • CVE-2026-46911CriJun 17, 2026
    risk 0.62cvss 9.6epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Project Costing product of Oracle JD Edwards (component: Job Costing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via JDENET to compromise JD…

  • CVE-2026-46906CriJun 17, 2026
    risk 0.62cvss 9.6epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2026-46899CriJun 17, 2026
    risk 0.62cvss 9.6epss 0.00

    Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-46861CriJun 17, 2026
    risk 0.62cvss 9.6epss 0.00

    Vulnerability in the MySQL NDB Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0.11-8.0.46, 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2026-24303CriApr 23, 2026
    risk 0.62cvss 9.6epss 0.00

    Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-21627CriFeb 20, 2026
    risk 0.62cvss —epss 0.02

    The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functionality could be invoked without proper restriction.

  • CVE-2025-63525CriDec 1, 2025
    risk 0.62cvss 9.6epss 0.00

    An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted request to delete.php.

  • CVE-2025-54343CriNov 14, 2025
    risk 0.62cvss 9.6epss 0.00

    An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges.

  • CVE-2025-9804CriOct 16, 2025
    risk 0.62cvss 9.6epss 0.01

    An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing…

  • CVE-2025-59218CriOct 9, 2025
    risk 0.62cvss 9.6epss 0.01

    Azure Entra ID Elevation of Privilege Vulnerability

  • CVE-2024-52928CriJun 26, 2025
    risk 0.62cvss 9.6epss 0.00

    Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.