VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 343 of 404
  • CVE-2026-62577LowAug 18, 2026
    risk 0.21cvss 3.3epss 0.00

    Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the…

  • CVE-2026-62526LowAug 18, 2026
    risk 0.21cvss 3.3epss 0.00

    Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to…

  • CVE-2026-59763MedAug 13, 2026
    risk 0.21cvss 4.3epss 0.00

    Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

  • CVE-2026-58039LowJul 31, 2026
    risk 0.21cvss 3.3epss 0.00

    A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects…

  • CVE-2026-61071LowJul 21, 2026
    risk 0.21cvss 3.3epss 0.00

    Vulnerability in the PeopleSoft Enterprise FIN Engineering Argentina product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to…

  • CVE-2026-47055LowJul 21, 2026
    risk 0.21cvss 3.2epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes…

  • CVE-2026-21953LowJul 21, 2026
    risk 0.21cvss 3.3epss 0.00

    Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where…

  • CVE-2026-55548MedJul 16, 2026
    risk 0.21cvss 4.3epss 0.00

    Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request omitted specific packet names: with an empty…

  • CVE-2026-48936LowJun 26, 2026
    risk 0.21cvss 3.3epss 0.00

    A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**.

  • CVE-2026-11459LowJun 7, 2026
    risk 0.21cvss 3.3epss 0.00

    A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. Impacted is an unknown function in the library saappctl.sys of the component IOCTL Handler. The manipulation leads to information disclosure. Local access is required to approach this attack. The…

  • CVE-2026-45264MedJun 1, 2026
    risk 0.21cvss 4.3epss 0.00

    Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before 21.0.4, a user with READ and CREATE permission, but no UPDATE permission for a…

  • CVE-2026-41160MedMay 28, 2026
    risk 0.21cvss 4.3epss 0.00

    EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business logic flaw (Broken Access Control) in EspoCRM 9.3.3 allows low-privileged users to pin arbitrary notes without having the required edit permissions for the parent object. Due to a…

  • CVE-2026-9604MedMay 26, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improper access controls. The attack can be executed remotely. The exploit is now…

  • CVE-2026-34754MedMay 20, 2026
    risk 0.21cvss 4.3epss 0.00

    Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to upload attachments to private Issues they are not authorized to access. This issue has been fixed in version 2.28.2.

  • CVE-2026-28957LowMay 11, 2026
    risk 0.21cvss 3.3epss 0.00

    An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, visionOS 26.5. An app may be able to capture a user's screen.

  • CVE-2026-28910LowMay 11, 2026
    risk 0.21cvss 3.3epss 0.00

    This issue was addressed with improved permissions checking. This issue is fixed in macOS Tahoe 26.4. A malicious app may be able to access arbitrary files.

  • CVE-2026-29197MedApr 24, 2026
    risk 0.21cvss 4.3epss 0.00

    In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/logs and /api/apps/:id/logs have a typo in the required permission check, allowing authenticated users without the proper permissions to read apps-engine logs.

  • CVE-2026-35249LowApr 21, 2026
    risk 0.21cvss 3.2epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes…

  • CVE-2026-34082MedApr 20, 2026
    risk 0.21cvss 4.3epss 0.00

    Dify is an open-source LLM app development platform. Prior to 1.13.1, the method `DELETE /console/api/installed-apps//conversations/` has poor authorization checking and allows any Dify-authenticated user to delete someone else's chat history. Version…

  • CVE-2026-35619MedApr 10, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to enforce operator read scope requirements. Attackers with only operator.approvals scope can enumerate gateway model metadata through the HTTP compatibility…