VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 49 of 405
  • CVE-2026-73926HigSep 15, 2026
    risk 0.57cvss 8.7epss 0.00

    Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP…

  • CVE-2026-71047HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-70915HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to…

  • CVE-2026-90898CriSep 14, 2026
    risk 0.57cvss 9.8epss 0.00

    Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every…

  • CVE-2026-90493HigSep 13, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a…

  • CVE-2026-81941HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local…

  • CVE-2026-77487HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-73028HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-69282HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-69273HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-69268HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-53924HigSep 3, 2026
    risk 0.57cvss —epss 0.00

    Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Prior to 0xc9d4e0dacd937364793278180551e59d93cd43f9, StreamingEscrow.claim() correctly rejects withdrawals…

  • CVE-2026-84668HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.00

    Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user.

  • CVE-2026-73750HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful…

  • CVE-2024-7953HigSep 1, 2026
    risk 0.57cvss —epss 0.00

    A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could create, modify, and delete their own project.

  • CVE-2026-84128HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

  • CVE-2026-84117HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.

  • CVE-2026-84165HigSep 1, 2026
    risk 0.57cvss —epss 0.01

    A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the…

  • CVE-2026-78074HigAug 31, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are…

  • CVE-2026-82859CriAug 31, 2026
    risk 0.57cvss 9.8epss 0.00

    hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting the weakened SCP template in downstream deployments.