VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 337 of 404
  • CVE-2022-24923MedFeb 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Samsung SearchWidget prior to versions 2.3.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview.

  • CVE-2022-23997MedFeb 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Unprotected component vulnerability in StTheaterModeDurationAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to disable theater mode without a proper permission.

  • CVE-2022-23996MedFeb 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to enable bedtime mode without a proper permission.

  • CVE-2022-23995MedFeb 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.

  • CVE-2021-4016MedJan 21, 2022
    risk 0.26cvss 4.0epss 0.00

    Rapid7 Insight Agent, versions prior to 3.1.3, suffer from an improper access control vulnerability whereby, the user has access to the snapshot directory. An attacker can access, read and copy any of the files in this directory e.g. asset_info.json or file_info.json, leading to…

  • CVE-2021-25463MedSep 9, 2021
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview.

  • CVE-2020-15279MedMay 18, 2021
    risk 0.26cvss 4.0epss 0.00

    An Improper Access Control vulnerability in the logging component of Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.23.320 allows a regular user to learn the scanning exclusion paths. This issue was discovered during external security research.

  • CVE-2021-25359MedApr 9, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP information without proper permissions via untrusted applications.

  • CVE-2018-15398MedOct 5, 2018
    risk 0.26cvss 4.0epss 0.02

    A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control list (ACL) that is configured for an interface of an…

  • CVE-2026-89328LowSep 16, 2026
    risk 0.25cvss 3.8epss 0.00

    The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any member of a board to carry out manager-only actions on it,…

  • CVE-2026-62532LowAug 18, 2026
    risk 0.25cvss 3.8epss 0.00

    Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via SQL to compromise Oracle…

  • CVE-2026-58429MedAug 13, 2026
    risk 0.25cvss 4.9epss 0.00

    Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

  • CVE-2026-14222LowJul 30, 2026
    risk 0.25cvss 3.8epss 0.00

    The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.

  • CVE-2026-14221LowJul 30, 2026
    risk 0.25cvss 3.8epss 0.00

    The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment…

  • CVE-2026-16072MedJul 17, 2026
    risk 0.25cvss 4.9epss 0.00

    A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application…

  • CVE-2026-22014LowApr 21, 2026
    risk 0.25cvss 3.8epss 0.00

    Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to…

  • CVE-2026-22692MedApr 14, 2026
    risk 0.25cvss 4.9epss 0.00

    October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vulnerability in the optional Twig safe mode feature (CMS_SAFE_MODE). Certain methods on the collect() helper were not properly…

  • CVE-2026-0871MedFeb 27, 2026
    risk 0.25cvss 4.9epss 0.00

    A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles,…

  • CVE-2026-27152LowFeb 26, 2026
    risk 0.25cvss 3.8epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, DM communication-preference bypass when adding members via `Chat::AddUsersToChannel` — a user could add targets who have blocked/ignored/muted them to an existing DM channel,…

  • CVE-2026-22728MedFeb 26, 2026
    risk 0.25cvss 4.9epss 0.00

    Bitnami Sealed Secrets is vulnerable to a scope-widening attack during the secret rotation (/v1/rotate) flow. The rotation handler derives the sealing scope for the newly encrypted output from untrusted spec.template.metadata.annotations present in the input SealedSecret. By…