CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,294 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 48 of 126
- CVE-2023-49473CRITICALCVSS 9.8EG 9.82024-04-30
Shenzhen JF6000 Cloud Media Collaboration Processing Platform firmware version V1.2.0 and software version V2.0.0 build 6245 is vulnerable to Incorrect Access Control.
- CVE-2023-49543CRITICALCVSS 9.8EG 9.82024-03-01
Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions without authenticating.
- CVE-2023-49545HIGHCVSS 7.5EG 7.52024-03-01
A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.
- CVE-2023-49647HIGHCVSS 8.8EG 8.82024-01-12
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2023-49694HIGHCVSS 7.8EG 7.82023-11-29
A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application directory. The user can then execute the JSP files under the …
- CVE-2023-49791MEDIUMCVSS 5.4EG 5.42023-12-22
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9…
- CVE-2023-49874MEDIUMCVSS 4.3EG 4.32023-12-12
Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest to update the tasks of a private playbook run if they know the run ID.
- CVE-2023-49930CRITICALCVSS 9.8EG 9.82024-02-29
An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
- CVE-2023-49931CRITICALCVSS 9.8EG 9.82024-02-29
An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.
- CVE-2023-49961HIGHCVSS 7.5EG 7.52024-01-08
WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead to sensitive data exposure.
- CVE-2023-49978HIGHCVSS 8.8EG 8.82024-03-21
Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators.
- CVE-2023-49982HIGHCVSS 8.8EG 8.82024-03-21
Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts.
- CVE-2023-5009CRITICALCVSS 9.8EG 9.82023-09-19
An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled secu…
- CVE-2023-50159HIGHCVSS 8.8EG 8.82024-01-11
In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrary code to be executed. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-Ap…
- CVE-2023-50181MEDIUMCVSS 4.9EG 4.92024-07-09
An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only authenticated attacker to perform some write actions via crafted HTTP or HTTPS requests.
- CVE-2023-50257CRITICALCVSS 9.6EG 9.62024-02-19
eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Even with the application of SROS2, due to the issue where the data (`p[UD]`) and `guid` values used t…
- CVE-2023-50300MEDIUMCVSS 5.1EG 5.12025-10-01
IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper access controls.
- CVE-2023-50333MEDIUMCVSS 4.3EG 4.32024-01-02
Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names.
- CVE-2023-50341HIGHCVSS 7.5EG 7.62024-01-03
HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, reflects a "Missing Access Control" vulnerability, which could lead to inadvertent exposure of…
- CVE-2023-50343HIGHCVSS 6.5EG 8.32024-01-03
HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Admin Users that can allow access to sensitive information about other users.
- CVE-2023-50344MEDIUMCVSS 5.4EG 5.42024-01-03
HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download certain files.
- CVE-2023-50440MEDIUMCVSS 5.5EG 5.52023-12-13
ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission)…
- CVE-2023-50702HIGHCVSS 8.8EG 8.82024-03-26
Sikka SSCWindowsService 5 2023-09-14 executes a program as LocalSystem but allows full control by low-privileged users (and low-privileged users have write access to %PROGRAMDATA%\SSCService). Consequently, low-privileged users can execute…
- CVE-2023-50706MEDIUMCVSS 4.3EG 4.32023-12-20
A user without administrator permissions with access to the UC500 windows system could perform a memory dump of the running processes and extract clear credentials or valid session tokens.
- CVE-2023-50783MEDIUMCVSS 6.5EG 6.52023-12-21
Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially lea…
- CVE-2023-50928CRITICALCVSS 9.0EG 9.02023-12-22
"Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially claim and access empty AWS accounts by sending request…
- CVE-2023-5098HIGHCVSS 8.1EG 8.12023-10-31
The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like subscribers) from overwriting any options on a site with the string "true", which could lead to a variety of outcomes, i…
- CVE-2023-5106HIGHCVSS 7.5EG 8.22023-10-02
An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through…
- CVE-2023-51065HIGHCVSS 7.5EG 7.52024-01-13
Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from the QStar Server.
- CVE-2023-51070HIGHCVSS 7.5EG 7.52024-01-13
An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server.
- CVE-2023-51384MEDIUMCVSS 5.5EG 5.52023-12-18
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key…
- CVE-2023-51390HIGHCVSS 7.5EG 7.52023-12-21
journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging…
- CVE-2023-51644CRITICALCVSS 7.3EG 9.82024-11-22
Allegra SiteConfigAction Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is not required to exploit this…
- CVE-2023-51661HIGHCVSS 8.6EG 8.62023-12-22
Wasmer is a WebAssembly runtime that enables containers to run anywhere: from Desktop to the Cloud, Edge and even the browser. Wasm programs can access the filesystem outside of the sandbox. Service providers running untrusted Wasm code on…
- CVE-2023-51751MEDIUMCVSS 6.8EG 6.82024-01-11
ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.
- CVE-2023-51774HIGHCVSS 8.4EG 8.42024-02-29
The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.
- CVE-2023-51786CRITICALCVSS 9.1EG 9.12024-03-07
An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privileges and obtain sensitive information via Incorrect Access Control.
- CVE-2023-5198MEDIUMCVSS 4.3EG 4.32023-09-29
An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to prote…
- CVE-2023-5207HIGHCVSS 8.8EG 8.82023-09-30
A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context…
- CVE-2023-52099HIGHCVSS 7.5EG 7.52024-01-16
Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-52105HIGHCVSS 7.5EG 7.52024-01-16
The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.
- CVE-2023-52114HIGHCVSS 7.5EG 7.52024-01-16
Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.
- CVE-2023-52164MEDIUMCVSS 5.1EG 5.12025-02-03
access_device.cgi on Digiever DS-2105 Pro 3.1.0.71-11 devices allows arbitrary file read. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
- CVE-2023-52362HIGHCVSS 7.5EG 7.52024-02-18
Permission management vulnerability in the lock screen module.Successful exploitation of this vulnerability may affect availability.
- CVE-2023-52367HIGHCVSS 7.7EG 7.72024-02-18
Vulnerability of improper access control in the media library module.Successful exploitation of this vulnerability may affect service availability and integrity.
- CVE-2023-52375HIGHCVSS 7.5EG 7.52024-02-18
Permission control vulnerability in the WindowManagerServices module.Successful exploitation of this vulnerability may affect availability.
- CVE-2023-5240HIGHCVSS 7.5EG 7.52023-10-13
Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.
- CVE-2023-52537HIGHCVSS 7.5EG 7.52024-04-08
Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2023-52711HIGHCVSS 7.8EG 7.82024-05-28
Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place by previous UEFI phases to prevent direct access to the SPI flash. The second issue can be…
- CVE-2023-52712HIGHCVSS 7.8EG 7.82024-05-28
Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place by previous UEFI phases to prevent direct access to the SPI flash. The second issue can be…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →