VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,083)

page 388 of 405
  • CVE-2026-50746CriJul 2, 2026
    risk 0.00cvss 10.0epss 0.02

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.

  • CVE-2026-56334MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    Capgo before 12.128.2 lacks an UPDATE row-level security policy for the build_requests table, preventing API-key and anonymous access from persisting builder status updates. Attackers can exploit this missing policy to cause build status and error details to remain unpersisted,…

  • CVE-2025-24816MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could allow an authenticated attacker to retrieve confidential information beyond their assigned privileges.

  • CVE-2026-51221HigJun 29, 2026
    risk 0.00cvss 7.5epss 0.00

    A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a Denial of Service (DoS) via supplying a crafted Common Packet Format (CPF) packet.

  • CVE-2026-13568HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown code of the file /api/users_handler.php of the component User Registration Endpoint. This manipulation of the argument role causes improper access controls.…

  • CVE-2026-13553HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.01

    A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of the argument image can lead to unrestricted upload. It is possible to launch the…

  • CVE-2026-13547HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/resourceUpload/upload.do. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be…

  • CVE-2026-13544MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    A flaw has been found in Feehi CMS up to 2.1.1. Affected by this issue is some unknown functionality of the file /api/users of the component API. This manipulation causes improper access controls. The attack can be initiated remotely. The exploit has been published and may be…

  • CVE-2026-56823MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/integrations/webhooks/{webhook_id}/ping` endpoint fetches the target webhook by primary key alone without verifying that the…

  • CVE-2026-48529MedJun 26, 2026
    risk 0.00cvss 6.0epss 0.00

    GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCache is implemented as a process-global singleton initialized with the first authenticated user's GraphQL client. All subsequent…

  • CVE-2026-50744MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID cookie in the HTTP headers, and although the method correctly returned an error, the associated session was not invalidated. As…

  • CVE-2026-50739MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers through the `tracker-campaigns.php` script in Revive Adserver 6.0.7 and earlier. As a result, a low‑privileged user…

  • CVE-2026-56050MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCommerce: from n/a through 33.0.18.

  • CVE-2026-46733HigJun 25, 2026
    risk 0.00cvss 7.8epss 0.00

    Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

  • CVE-2026-44958MedJun 23, 2026
    risk 0.00cvss 5.4epss 0.00

    An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such permissions were not granted. The banner-edit.php script allowed the banner status to be overwritten solely based on banner edit…

  • CVE-2026-44957MedJun 23, 2026
    risk 0.00cvss 4.3epss 0.00

    A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earlier. The API allowed entities to be reassigned to different parent entities, leading to inconsistent ownership relationships. This issue was exploitable only…

  • CVE-2026-34913MedJun 23, 2026
    risk 0.00cvss 4.3epss 0.00

    A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their trackers to campaigns owned by other managers on the same instance, resulting in…

  • CVE-2026-34912MedJun 23, 2026
    risk 0.00cvss 4.3epss 0.00

    A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user could link their zones to banners or campaigns owned by other managers on the same…

  • CVE-2025-66391HigJun 17, 2026
    risk 0.00cvss 8.8epss 0.00

    In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user…

  • CVE-2026-32752NonMar 19, 2026
    risk 0.00cvss 0.0epss 0.00

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, the ThreadPolicy::edit() method contains a broken access control vulnerability that allows any authenticated user (regardless of role or mailbox access) to read and…