VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 60 of 405
  • CVE-2025-68623HigMar 11, 2026
    risk 0.57cvss 8.8epss 0.00

    In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an executable file during the installation process, which may result in unintended elevation of privileges. During installation, the installer runs with HIGH integrity and downloads…

  • CVE-2026-21262HigMar 10, 2026
    risk 0.57cvss 8.8epss 0.02

    Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-30855HigMar 7, 2026
    risk 0.57cvss 8.8epss 0.00

    WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass in tenant management endpoints of WeKnora application allows any authenticated user to read, modify, or delete any tenant by ID.…

  • CVE-2026-3543HigMar 4, 2026
    risk 0.57cvss 8.8epss 0.00

    Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-3542HigMar 4, 2026
    risk 0.57cvss 8.8epss 0.00

    Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-3541HigMar 4, 2026
    risk 0.57cvss 8.8epss 0.00

    Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-63409HigFeb 24, 2026
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settings and extract administrator credentials.

  • CVE-2025-70064HigFeb 18, 2026
    risk 0.57cvss 8.8epss 0.00

    PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Management) by manually browsing to the /admin/ directory after…

  • CVE-2026-23595HigFeb 17, 2026
    risk 0.57cvss 8.8epss 0.00

    An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to create privileged user accounts. Successful exploitation could allow an attacker to gain administrative access,…

  • CVE-2025-70866HigFeb 13, 2026
    risk 0.57cvss 8.8epss 0.00

    LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in through /admin/login. The vulnerability exists because the admin and user authentication guards share…

  • CVE-2026-21255HigFeb 10, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.

  • CVE-2020-37116HigFeb 3, 2026
    risk 0.57cvss 8.8epss 0.00

    GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the platform can remotely access phpMyAdmin and, after uploading a shell, view the config.php file to obtain the MySQL password, leading to full database…

  • CVE-2026-0844HigJan 28, 2026
    risk 0.57cvss 8.8epss 0.00

    The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 6.7 due to insufficient restriction on the 'profile_save_field' function. This makes it possible for authenticated attackers, with minimal permissions such…

  • CVE-2026-24740CriJan 27, 2026
    risk 0.57cvss 9.9epss 0.00

    Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell endpoints allows a user restricted by label filters (for example, `label=env=dev`) to obtain an interactive root shell in out‑of‑scope containers (for…

  • CVE-2025-61973HigJan 15, 2026
    risk 0.57cvss 8.8epss 0.00

    A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL file during the installation process, which may result in unintended elevation of privileges.

  • CVE-2026-22043CriJan 8, 2026
    risk 0.57cvss 9.8epss 0.00

    RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in RustFS IAM allows a restricted service account or STS credential to self-issue an unrestricted service account, inheriting the…

  • CVE-2025-56396HigNov 26, 2025
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user.

  • CVE-2025-64064HigNov 25, 2025
    risk 0.57cvss 8.8epss 0.00

    Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SECURITY_PROFILE_ID. Because of weak access controls any low level user can use this API and change their permission to Administrator…

  • CVE-2025-48986HigNov 20, 2025
    risk 0.57cvss 8.8epss 0.01

    Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

  • CVE-2025-43515HigNov 13, 2025
    risk 0.57cvss 8.8epss 0.00

    The issue was addressed by refusing external connections by default. This issue is fixed in Compressor 4.11.1. An unauthenticated user on the same network as a Compressor server may be able to execute arbitrary code.