CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,302 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 63 of 127
- CVE-2024-46539HIGHCVSS 8.2EG 8.22024-10-08
Insecure permissions in the Bluetooth Low Energy (BLE) component of Fire-Boltt Artillery Smart Watch NJ-R6E-10.3 allow attackers to cause a Denial of Service (DoS).
- CVE-2024-46607HIGHCVSS 7.6EG 7.62024-09-25
Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.
- CVE-2024-46609HIGHCVSS 7.5EG 7.52024-09-25
An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords
- CVE-2024-46610HIGHCVSS 7.5EG 7.52024-09-25
An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function i…
- CVE-2024-46627CRITICALCVSS 9.1EG 9.12024-09-26
Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.
- CVE-2024-46916HIGHCVSS 8.1EG 8.12025-08-29
Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesystem is properly mounted (e.g., leveraging a delete call in /etc/rc.d/init.d/mountfs to remo…
- CVE-2024-46937CRITICALCVSS 7.5EG 9.12024-09-16
An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SAS) 1.8.x through 1.9.x before 1.9.040924 allows remote attackers gain access to user token…
- CVE-2024-46948MEDIUMCVSS 4.3EG 4.32024-11-08
Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.
- CVE-2024-46990MEDIUMCVSS 5.0EG 5.02024-09-18
Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.0.0` filter a user may bypass this block by using other registered loopback devices (like …
- CVE-2024-47145LOWCVSS 3.1EG 3.12024-09-26
Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.
- CVE-2024-47481MEDIUMCVSS 6.5EG 6.52024-10-25
Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Denial of service.
- CVE-2024-47758HIGHCVSS 8.8EG 8.82024-12-11
GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the API to take control of any user that have the same or a lower level of privileges. Version 1…
- CVE-2024-47760HIGHCVSS 8.8EG 8.82024-12-11
GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a technician with an access to the API can take control of an account with higher privileges. Version 10.0.17 contains a patch…
- CVE-2024-47910HIGHCVSS 7.2EG 7.22024-10-04
An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.
- CVE-2024-47975HIGHCVSS 7.0EG 7.02024-10-07
Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access or an attacker with local access to potentially enable denial of service.
- CVE-2024-47976MEDIUMCVSS 6.7EG 6.72024-10-07
Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access.
- CVE-2024-48010MEDIUMCVSS 6.5EG 6.52024-11-08
Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to escalation of privile…
- CVE-2024-48899MEDIUMCVSS 4.3EG 4.32024-11-20
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
- CVE-2024-48905CRITICALCVSS 9.1EG 9.12025-05-01
Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.
- CVE-2024-48912HIGHCVSS 8.1EG 8.12024-12-11
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an authenticated user can use an application endpoint to delete any user account. Version 10.0.17 contains a patch for this i…
- CVE-2024-48925UnratedEG 0.02024-10-22
Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version 14.3.0. The issue allows low-privilege users to access the webhook API and retrieve inform…
- CVE-2024-48932MEDIUMCVSS 5.3EG 5.32024-10-24
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, the API endpoint `http://<Server-ip>/v1/users/name` allows unauthenticated users to access sensitive information, such …
- CVE-2024-48955HIGHCVSS 8.1EG 8.12024-10-29
Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not encrypted and as the system does not validate the session authorization…
- CVE-2024-49044MEDIUMCVSS 6.7EG 6.72024-11-12
Visual Studio Elevation of Privilege Vulnerability
- CVE-2024-49049HIGHCVSS 7.1EG 7.12024-11-12
Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
- CVE-2024-49068HIGHCVSS 8.2EG 8.22024-12-12
Microsoft SharePoint Elevation of Privilege Vulnerability
- CVE-2024-49105HIGHCVSS 8.4EG 8.42024-12-12
Remote Desktop Client Remote Code Execution Vulnerability
- CVE-2024-49107HIGHCVSS 7.3EG 7.32024-12-12
WmsRepair Service Elevation of Privilege Vulnerability
- CVE-2024-49600HIGHCVSS 7.8EG 7.82024-12-09
Dell Power Manager (DPM), versions prior to 3.17, contain an improper access control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privil…
- CVE-2024-49842HIGHCVSS 7.8EG 7.82025-05-06
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
- CVE-2024-4988HIGHCVSS 7.5EG 7.52024-05-21
The mobile application (com.transsion.videocallenhancer) interface has improper permission control, which can lead to the risk of private file leakage.
- CVE-2024-50353MEDIUMCVSS 5.3EG 5.32024-10-30
ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files for cloud upload. Users of this library that set a duration for a SAS Uri with a value other than 1 hour may have gener…
- CVE-2024-50558MEDIUMCVSS 4.3EG 4.32024-11-12
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8…
- CVE-2024-50653HIGHCVSS 7.5EG 7.52024-11-15
CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets and sending a large number of data packets for coupon collection, achieving u…
- CVE-2024-50945HIGHCVSS 7.5EG 7.52024-12-27
An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, allowing users to submit reviews without verifying if they have purchased the product.
- CVE-2024-5126HIGHCVSS 6.5EG 7.62024-06-06
An improper access control vulnerability exists in the lunary-ai/lunary repository, specifically within the versions.patch functionality for updating prompts. Affected versions include 1.2.2 up to but not including 1.2.25. The vulnerabilit…
- CVE-2024-5127MEDIUMCVSS 5.4EG 5.42024-06-06
In lunary-ai/lunary versions 1.2.2 through 1.2.25, an improper access control vulnerability allows users on the Free plan to invite other members and assign them any role, including those intended for Paid and Enterprise plans only. This i…
- CVE-2024-5128CRITICALCVSS 8.8EG 9.42024-06-06
An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2. This vulnerability allows unauthorized users to view, update, or delete any dataset_prompt or datase…
- CVE-2024-5131HIGHCVSS 6.5EG 7.52024-06-06
An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and including 1.2.2. The vulnerability allows unauthorized users to view any prompts in any projects by supplying a specific promp…
- CVE-2024-5168CRITICALCVSS 9.8EG 9.82024-05-23
Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerability could allow an unauthenticated user to bypass authentication entirely and execute arbitrary API requests against t…
- CVE-2024-51734HIGHCVSS 8.7EG 8.72024-11-04
Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access. This pr…
- CVE-2024-51954HIGHCVSS 8.5EG 8.52025-03-03
There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a remote, low‑privileged authenticated attacker to access secure services published to…
- CVE-2024-51988MEDIUMCVSS 6.5EG 6.52024-11-06
RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission of the user. Users who had all of the following: 1. Valid credenti…
- CVE-2024-51995HIGHCVSS 7.1EG 7.12024-11-07
Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specify an `operation` that is allowed. This issue has been addressed in version 3.2.0 by applying the same access control pa…
- CVE-2024-5248MEDIUMCVSS 6.5EG 6.52024-06-06
In lunary-ai/lunary version 1.2.5, an improper access control vulnerability exists due to a missing permission check in the `GET /v1/users/me/org` endpoint. The platform's role definitions restrict the `Prompt Editor` role to prompt manage…
- CVE-2024-52509LOWCVSS 3.5EG 3.52024-11-15
Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly allowed attaching shared files without download permissions as attachments. This allowed users to send them the files to …
- CVE-2024-52514MEDIUMCVSS 4.1EG 4.12024-11-15
Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being blocked by the files access control, the user would still be able to copy the intermediate folder inside Nextcloud allowing…
- CVE-2024-5257MEDIUMCVSS 4.9EG 4.92024-07-11
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a…
- CVE-2024-5270MEDIUMCVSS 4.3EG 4.32024-05-26
Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to check if the email signup configuration option is enabled when a user requests to switch from SAML to Email. This allows the user to switch thei…
- CVE-2024-5272MEDIUMCVSS 4.3EG 4.32024-05-26
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the de…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →