CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,082)
page 49 of 405| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-73926 | Hig | 0.57 | 8.7 | 0.00 | Sep 15, 2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP… | ||
| CVE-2026-71047 | Hig | 0.57 | 8.8 | 0.00 | Sep 15, 2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | ||
| CVE-2026-70915 | Hig | 0.57 | 8.8 | 0.00 | Sep 15, 2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to… | ||
| CVE-2026-90898 | Cri | 0.57 | 9.8 | 0.00 | Sep 14, 2026 | Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every… | ||
| CVE-2026-90493 | Hig | 0.57 | 8.8 | 0.00 | Sep 13, 2026 | A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a… | ||
| CVE-2026-81941 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local… | ||
| CVE-2026-77487 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-73028 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-69282 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-69273 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-69268 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-53924 | Hig | 0.57 | — | 0.00 | Sep 3, 2026 | Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Prior to 0xc9d4e0dacd937364793278180551e59d93cd43f9, StreamingEscrow.claim() correctly rejects withdrawals… | ||
| CVE-2026-84668 | Hig | 0.57 | 8.8 | 0.00 | Sep 2, 2026 | Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user. | ||
| CVE-2026-73750 | Hig | 0.57 | 8.8 | 0.00 | Sep 1, 2026 | Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful… | ||
| CVE-2024-7953 | — | Hig | 0.57 | — | 0.00 | Sep 1, 2026 | A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could create, modify, and delete their own project. | |
| CVE-2026-84128 | Hig | 0.57 | 8.8 | 0.00 | Sep 1, 2026 | Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. | ||
| CVE-2026-84117 | Hig | 0.57 | 8.8 | 0.00 | Sep 1, 2026 | Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155. | ||
| CVE-2026-84165 | Hig | 0.57 | — | 0.01 | Sep 1, 2026 | A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the… | ||
| CVE-2026-78074 | Hig | 0.57 | — | 0.00 | Aug 31, 2026 | Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are… | ||
| CVE-2026-82859 | Cri | 0.57 | 9.8 | 0.00 | Aug 31, 2026 | hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting the weakened SCP template in downstream deployments. |
- risk 0.57cvss 8.7epss 0.00
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP…
- risk 0.57cvss 8.8epss 0.00
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
- risk 0.57cvss 8.8epss 0.00
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to…
- risk 0.57cvss 9.8epss 0.00
Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every…
- risk 0.57cvss 8.8epss 0.00
A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a…
- risk 0.57cvss 8.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local…
- risk 0.57cvss 8.8epss 0.01
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss —epss 0.00
Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Prior to 0xc9d4e0dacd937364793278180551e59d93cd43f9, StreamingEscrow.claim() correctly rejects withdrawals…
- risk 0.57cvss 8.8epss 0.00
Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user.
- risk 0.57cvss 8.8epss 0.00
Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful…
- risk 0.57cvss —epss 0.00
A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could create, modify, and delete their own project.
- risk 0.57cvss 8.8epss 0.00
Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
- risk 0.57cvss 8.8epss 0.00
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
- risk 0.57cvss —epss 0.01
A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the…
- risk 0.57cvss —epss 0.00
Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are…
- risk 0.57cvss 9.8epss 0.00
hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting the weakened SCP template in downstream deployments.