CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,323 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 109 of 127
- CVE-2026-47010LOWCVSS 3.7EG 3.72026-07-21
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 2…
- CVE-2026-47014HIGHCVSS 8.1EG 8.12026-07-21
Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network …
- CVE-2026-47017HIGHCVSS 8.7EG 8.72026-07-21
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Process Scheduler). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker w…
- CVE-2026-47024MEDIUMCVSS 5.4EG 5.42026-07-21
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). The supported version that is affected is 8.62. Easily exploitable vulnerability allows low privileged attacker with networ…
- CVE-2026-47027MEDIUMCVSS 5.3EG 5.32026-07-21
Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM En…
- CVE-2026-47028HIGHCVSS 8.1EG 8.12026-07-21
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged…
- CVE-2026-47030LOWCVSS 3.1EG 3.12026-07-21
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compro…
- CVE-2026-47031HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Bill Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with netwo…
- CVE-2026-47032LOWCVSS 2.6EG 2.62026-07-21
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Redwood UI). Supported versions that are affected are 24.4-26.3. Difficult to exploit vulnerability allows high privileged attacker with network access via …
- CVE-2026-47033HIGHCVSS 8.5EG 8.52026-07-21
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attac…
- CVE-2026-47034LOWCVSS 3.1EG 3.12026-07-21
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compro…
- CVE-2026-47035LOWCVSS 3.1EG 3.12026-07-21
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compro…
- CVE-2026-47039MEDIUMCVSS 6.5EG 6.52026-07-21
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Create Session p…
- CVE-2026-47049MEDIUMCVSS 4.9EG 4.92026-07-21
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows high privileged attacker…
- CVE-2026-47050HIGHCVSS 7.4EG 7.42026-07-21
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastruct…
- CVE-2026-47055LOWCVSS 3.2EG 3.22026-07-21
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastruc…
- CVE-2026-47059LOWCVSS 3.7EG 3.72026-07-21
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.1…
- CVE-2026-47060MEDIUMCVSS 6.5EG 6.52026-07-21
Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via O…
- CVE-2026-47061MEDIUMCVSS 5.6EG 5.62026-07-21
Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with access to the phys…
- CVE-2026-47062MEDIUMCVSS 5.5EG 5.52026-07-21
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastruct…
- CVE-2026-47063HIGHCVSS 7.5EG 7.52026-07-21
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19,…
- CVE-2026-47064MEDIUMCVSS 6.5EG 6.52026-07-21
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.…
- CVE-2026-47164HIGHCVSS 7.7EG 7.72026-07-15
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation and not when SSO_SIGNUPS_MATCH_EMAIL=true linked an IdP identity to…
- CVE-2026-47182MEDIUMCVSS 5.3EG 5.32026-06-12
Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private files by guessing the file path. This issue has been patched in version 16.17.4.
- CVE-2026-47200MEDIUMCVSS 5.3EG 5.32026-05-29
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, when experim…
- CVE-2026-47255HIGHCVSS 8.2EG 8.22026-05-29
AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering;…
- CVE-2026-47261HIGHCVSS 7.5EG 7.52026-06-05
Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is given DirPerms::all() and FilePerms::READ without FilePerms::WRITE, this access control mechanism can be bypassed via the…
- CVE-2026-47269HIGHCVSS 7.4EG 7.42026-05-27
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb's deny_remote feature checks utmpx ut_addr_v6 to detect whether an authentication request originates from a remote session. The out…
- CVE-2026-47279MEDIUMCVSS 6.9EG 6.92026-06-05
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints accepted a caller-supplied column ID without verifying that the column was visible in the shared view, so anyone holdi…
- CVE-2026-47301HIGHCVSS 8.8EG 8.82026-07-14
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
- CVE-2026-47366HIGHCVSS 7.2EG 7.22026-06-12
Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in p…
- CVE-2026-47396CRITICALCVSS 9.8EG 9.82026-05-29
PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVER_TOKEN` is not configured. The affected component is the `praisona…
- CVE-2026-47399HIGHCVSS 8.8EG 8.82026-05-29
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization flaw that allows an authenticated user from one wor…
- CVE-2026-47405HIGHCVSS 8.8EG 8.82026-05-29
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated low-privilege workspace member to escalate their own rol…
- CVE-2026-47647CRITICALCVSS 9.9EG 9.92026-06-18
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
- CVE-2026-47907HIGHCVSS 8.6EG 8.62026-06-09
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execut…
- CVE-2026-48034HIGHCVSS 8.5EG 8.52026-06-10
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting a different bucket. This issue has been …
- CVE-2026-48204CRITICALCVSS 9.8EG 9.82026-07-06
Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs producer selects the GridFS operation to perform from the gridfs.operation Exchange header when t…
- CVE-2026-4823LOWCVSS 2.5EG 2.52026-03-25
A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functionality of the component NTLM2 Handler. Executing a manipulation can lead to information disclosure. The attack is restr…
- CVE-2026-4830MEDIUMCVSS 5.6EG 5.62026-03-26
A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php of the component Public Share Handler. Such manipulation leads to unrestricted upload. The…
- CVE-2026-48529MEDIUMCVSS 6.0EG 6.02026-06-25
GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCache is implemented as a process-global singleton initialized with the first authenticated u…
- CVE-2026-48578HIGHCVSS 7.9EG 7.92026-06-09
Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
- CVE-2026-48610HIGHCVSS 8.1EG 8.12026-06-12
Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.
- CVE-2026-48616CRITICALCVSS 9.3EG 9.32026-06-17
Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l wi…
- CVE-2026-48617LOWCVSS 1.8EG 1.82026-06-18
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vul…
- CVE-2026-4875MEDIUMCVSS 4.7EG 4.72026-03-26
A vulnerability was determined in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /admin/mod_amenities/index.php?view=add. This manipulation of the argument image causes unrestricted …
- CVE-2026-48898CRITICALCVSS 9.8EG 9.82026-05-26
An improper access check allows privilege escalation through the com_users batch task.
- CVE-2026-48899CRITICALCVSS 9.8EG 9.82026-05-26
An improper access check allows privilege escalation through the com_users batch task.
- CVE-2026-48900MEDIUMCVSS 4.3EG 4.32026-05-26
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
- CVE-2026-48904CRITICALCVSS 9.8EG 9.82026-05-26
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →