VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 55 of 405
  • CVE-2026-72561HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the platform global OIDC/SSO settings via an unprotected configuration endpoint. The endpoint performs no administrative role…

  • CVE-2026-18951HigAug 10, 2026
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit ClusterRole` permissions in a…

  • CVE-2026-13717HigAug 10, 2026
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as…

  • CVE-2026-17540HigAug 10, 2026
    risk 0.57cvss 8.8epss 0.00

    The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of…

  • CVE-2026-66494HigAug 7, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder…

  • CVE-2026-65668HigAug 7, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-67687HigAug 6, 2026
    risk 0.57cvss 8.8epss 0.00

    Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java

  • CVE-2026-62534HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-62516HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to…

  • CVE-2026-62478HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-62476HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-62447HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2026-61289HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). The supported version that is affected is 12.2.15. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2026-61168HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful…

  • CVE-2026-61166HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. …

  • CVE-2026-61127HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Solution Designer). Supported versions that are affected are 8.0.0.7.0-8.3.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2026-61078HigJul 21, 2026
    risk 0.57cvss 8.7epss 0.00

    Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2026-60989HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Advanced Collections product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-60960HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure…

  • CVE-2026-60941HigJul 21, 2026
    risk 0.57cvss 8.7epss 0.00

    Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to…