CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,082)
page 77 of 405| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-21997 | Hig | 0.55 | 8.5 | 0.00 | Apr 21, 2026 | Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core). Supported versions that are affected are 9.2.1-9.2.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | ||
| CVE-2025-48619 | Hig | 0.55 | 8.4 | 0.00 | Mar 2, 2026 | In multiple functions of ContentProvider.java, there is a possible way for an app with read-only access to truncate files due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not… | ||
| CVE-2025-14338 | Hig | 0.55 | — | 0.00 | Jan 14, 2026 | Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v0.69.0 can lead to the same issues as in CVE-2025-66005. | ||
| CVE-2025-68716 | Hig | 0.55 | 8.4 | 0.00 | Jan 8, 2026 | KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configured with no password, and administrators cannot disable SSH or enforce authentication via the CLI or web GUI. This allows any LAN-adjacent… | ||
| CVE-2025-66223 | Hig | 0.55 | — | 0.00 | Nov 29, 2025 | OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not expire once issued, remain valid even after the invited user is removed from the organization, and allow multiple invitations to the same email with different… | ||
| CVE-2025-53049 | Hig | 0.55 | 8.4 | 0.00 | Oct 21, 2025 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Administration). Supported versions that are affected are 7.6.0.0.0 and 8.2.0.0.0. Easily exploitable vulnerability allows high privileged attacker with… | ||
| CVE-2025-10847 | Hig | 0.55 | — | 0.00 | Oct 1, 2025 | DX Unified Infrastructure Management (Nimsoft/UIM) and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system. | ||
| CVE-2025-32992 | Hig | 0.55 | 8.5 | 0.00 | Aug 18, 2025 | Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control. | ||
| CVE-2025-26678 | Hig | 0.55 | 8.4 | 0.01 | Apr 8, 2025 | Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2024-51954 | Hig | 0.55 | 8.5 | 0.00 | Mar 3, 2025 | There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a remote, low‑privileged authenticated attacker to access secure services published to a standalone (unfederated) ArcGIS… | ||
| CVE-2024-49105 | Hig | 0.55 | 8.4 | 0.02 | Dec 12, 2024 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2016-10408 | Hig | 0.55 | 8.4 | 0.00 | Nov 26, 2024 | QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory. | ||
| CVE-2024-41605 | Hig | 0.55 | 8.4 | 0.00 | Sep 26, 2024 | In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse via side loading, because the update service lacks integrity validation for the updater. Attacker-controlled code may thus be… | ||
| CVE-2024-43479 | Hig | 0.55 | 8.5 | 0.01 | Sep 10, 2024 | Microsoft Power Automate Desktop Remote Code Execution Vulnerability | ||
| CVE-2024-33027 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table. | ||
| CVE-2024-5650 | Hig | 0.55 | 8.5 | 0.00 | Jun 17, 2024 | DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to intrude into a computer that installed affected product or access to a shared folder, by replacing the DLL file with a tampered one,… | ||
| CVE-2024-23360 | Hig | 0.55 | 8.4 | 0.00 | Jun 3, 2024 | Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers. | ||
| CVE-2024-23351 | Hig | 0.55 | 8.4 | 0.00 | May 6, 2024 | Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions. | ||
| CVE-2024-33396 | Hig | 0.55 | 8.4 | 0.00 | May 2, 2024 | An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component. | ||
| CVE-2023-38297 | Hig | 0.55 | 8.4 | 0.01 | Apr 22, 2024 | An issue was discovered in a third-party com.factory.mmigroup component, shipped on devices from multiple device manufacturers. Certain software builds for various Android devices contain a vulnerable pre-installed app with a package name of com.factory.mmigroup… |
- risk 0.55cvss 8.5epss 0.00
Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core). Supported versions that are affected are 9.2.1-9.2.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
- risk 0.55cvss 8.4epss 0.00
In multiple functions of ContentProvider.java, there is a possible way for an app with read-only access to truncate files due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
- risk 0.55cvss —epss 0.00
Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v0.69.0 can lead to the same issues as in CVE-2025-66005.
- risk 0.55cvss 8.4epss 0.00
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configured with no password, and administrators cannot disable SSH or enforce authentication via the CLI or web GUI. This allows any LAN-adjacent…
- risk 0.55cvss —epss 0.00
OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not expire once issued, remain valid even after the invited user is removed from the organization, and allow multiple invitations to the same email with different…
- risk 0.55cvss 8.4epss 0.00
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Administration). Supported versions that are affected are 7.6.0.0.0 and 8.2.0.0.0. Easily exploitable vulnerability allows high privileged attacker with…
- risk 0.55cvss —epss 0.00
DX Unified Infrastructure Management (Nimsoft/UIM) and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system.
- risk 0.55cvss 8.5epss 0.00
Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control.
- risk 0.55cvss 8.4epss 0.01
Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.
- risk 0.55cvss 8.5epss 0.00
There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a remote, low‑privileged authenticated attacker to access secure services published to a standalone (unfederated) ArcGIS…
- risk 0.55cvss 8.4epss 0.02
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.55cvss 8.4epss 0.00
QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory.
- risk 0.55cvss 8.4epss 0.00
In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse via side loading, because the update service lacks integrity validation for the updater. Attacker-controlled code may thus be…
- risk 0.55cvss 8.5epss 0.01
Microsoft Power Automate Desktop Remote Code Execution Vulnerability
- risk 0.55cvss 8.4epss 0.00
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
- risk 0.55cvss 8.5epss 0.00
DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to intrude into a computer that installed affected product or access to a shared folder, by replacing the DLL file with a tampered one,…
- risk 0.55cvss 8.4epss 0.00
Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.
- risk 0.55cvss 8.4epss 0.00
Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.
- risk 0.55cvss 8.4epss 0.00
An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.
- risk 0.55cvss 8.4epss 0.01
An issue was discovered in a third-party com.factory.mmigroup component, shipped on devices from multiple device manufacturers. Certain software builds for various Android devices contain a vulnerable pre-installed app with a package name of com.factory.mmigroup…