CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,300 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 61 of 126
- CVE-2024-41732MEDIUMCVSS 4.7EG 4.72024-08-13
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might inject CSS code or links…
- CVE-2024-41806MEDIUMCVSS 5.3EG 5.32024-07-25
The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information to create cohorts in the instructor dashboard. These files are uploaded using the django default storage. With certain…
- CVE-2024-41905MEDIUMCVSS 6.8EG 6.82024-08-13
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access control for accessing the files. This could allow an authenticated attacker with low priv…
- CVE-2024-41912CRITICALCVSS 9.8EG 9.82024-08-07
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly implement access controls.
- CVE-2024-41926LOWCVSS 2.7EG 2.72024-08-01
Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore cl…
- CVE-2024-41934MEDIUMCVSS 5.9EG 5.92025-02-12
Improper access control in some Intel(R) GPA software before version 2024.3 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2024-4195LOWCVSS 2.7EG 2.72024-04-26
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authenticated as a team admin to promote guests to team admins via crafted HTTP requests.
- CVE-2024-4198LOWCVSS 2.7EG 2.72024-04-26
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.
- CVE-2024-42021HIGHCVSS 6.5EG 7.52024-09-07
An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.
- CVE-2024-42022HIGHCVSS 5.3EG 7.52024-09-07
An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.
- CVE-2024-42023HIGHCVSS 8.8EG 8.82024-09-07
An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.
- CVE-2024-42033MEDIUMCVSS 6.9EG 6.92024-08-08
Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
- CVE-2024-42048MEDIUMCVSS 6.5EG 6.52025-08-07
OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all authenticated users to write to the installation path. In combination with the application's behavior of loading DLLs …
- CVE-2024-4225HIGHCVSS 7.6EG 7.62024-04-30
Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), by DPS Telecom. Attackers can exploit those security vulnerabilities to perform critical actions such as escalate user's…
- CVE-2024-42354MEDIUMCVSS 5.3EG 5.32024-08-08
Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be marked as ApiAware in the EntityDefinition. So only ApiAware fields of the EntityDefinition wi…
- CVE-2024-42406MEDIUMCVSS 5.4EG 5.42024-09-26
Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about…
- CVE-2024-42480HIGHCVSS 8.1EG 8.12024-08-12
Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, write, and delete the d…
- CVE-2024-42497MEDIUMCVSS 6.0EG 6.02024-08-22
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permissions which allows a user with systems manager role with read-only access to teams to perform write operations on teams.
- CVE-2024-42514CRITICALCVSS 8.1EG 9.12024-10-01
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit…
- CVE-2024-42559CRITICALCVSS 9.8EG 9.82024-08-20
An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a valid password.
- CVE-2024-4263MEDIUMCVSS 5.4EG 5.42024-05-16
A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with only EDIT permissions on an experiment can delete any artifacts. This issue arises due to the lack of proper validation fo…
- CVE-2024-42655HIGHCVSS 8.8EG 8.82025-07-29
An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.
- CVE-2024-42766MEDIUMCVSS 5.4EG 5.42024-08-23
Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.
- CVE-2024-42772HIGHCVSS 7.5EG 7.52024-08-22
An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in administrator section.
- CVE-2024-42775CRITICALCVSS 9.1EG 9.12024-08-22
An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via …
- CVE-2024-42776HIGHCVSS 7.2EG 7.22024-08-22
Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.
- CVE-2024-42794MEDIUMCVSS 4.7EG 4.72024-09-16
Kashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user.
- CVE-2024-42795MEDIUMCVSS 4.2EG 4.22024-09-16
An Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_user&id=3 in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to view valid u…
- CVE-2024-42796MEDIUMCVSS 5.9EG 5.92024-09-16
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music genre entries.
- CVE-2024-42797CRITICALCVSS 9.8EG 9.82024-09-25
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music playlist entries.
- CVE-2024-42919CRITICALCVSS 9.8EG 9.82024-08-20
eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
- CVE-2024-42966CRITICALCVSS 9.8EG 9.82024-08-15
Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
- CVE-2024-42967CRITICALCVSS 9.8EG 9.82024-08-15
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
- CVE-2024-42988MEDIUMCVSS 4.3EG 4.32024-10-09
Lack of access control in ChallengeSolves (/api/v1/challenges/<challenge id>/solves) of CTFd v2.0.0 - v3.7.2 allows authenticated users to retrieve a list of users who have solved the challenge, regardless of the Account Visibility setting…
- CVE-2024-43031MEDIUMCVSS 4.3EG 4.32024-08-23
autMan v2.9.6 was discovered to contain an access control issue.
- CVE-2024-43101MEDIUMCVSS 5.3EG 5.32025-05-13
Improper access control for some Intel(R) Data Center GPU Flex Series for Windows driver software before version 31.0.101.4255 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2024-43377MEDIUMCVSS 5.4EG 5.42024-08-20
Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1.2.
- CVE-2024-43397MEDIUMCVSS 4.3EG 4.32024-08-20
Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace with…
- CVE-2024-43409MEDIUMCVSS 6.5EG 6.52024-08-20
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in …
- CVE-2024-43456MEDIUMCVSS 4.8EG 4.82024-10-08
Windows Remote Desktop Services Tampering Vulnerability
- CVE-2024-43477HIGHCVSS 7.5EG 7.52024-08-23
Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant.
- CVE-2024-43479HIGHCVSS 8.5EG 8.52024-09-10
Microsoft Power Automate Desktop Remote Code Execution Vulnerability
- CVE-2024-43492HIGHCVSS 7.8EG 7.82024-09-10
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
- CVE-2024-43503HIGHCVSS 7.8EG 7.82024-10-08
Microsoft SharePoint Elevation of Privilege Vulnerability
- CVE-2024-43530HIGHCVSS 7.8EG 7.82024-11-12
Windows Update Stack Elevation of Privilege Vulnerability
- CVE-2024-43590HIGHCVSS 7.8EG 7.82024-10-08
Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
- CVE-2024-43594HIGHCVSS 7.3EG 7.32024-12-12
Microsoft System Center Elevation of Privilege Vulnerability
- CVE-2024-43600HIGHCVSS 7.8EG 7.82024-12-12
Microsoft Office Elevation of Privilege Vulnerability
- CVE-2024-43716MEDIUMCVSS 4.3EG 4.32024-12-10
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security me…
- CVE-2024-43717MEDIUMCVSS 4.3EG 4.32024-12-10
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security me…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →