CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,321 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 96 of 127
- CVE-2026-24300CRITICALCVSS 9.8EG 9.82026-02-05
Azure Front Door Elevation of Privilege Vulnerability
- CVE-2026-24302HIGHCVSS 9.8EG 8.62026-02-05
Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-24303CRITICALCVSS 9.6EG 9.62026-04-23
Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
- CVE-2026-24304CRITICALCVSS 8.8EG 9.92026-01-23
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
- CVE-2026-24306CRITICALCVSS 9.8EG 9.82026-01-22
Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-24420MEDIUMCVSS 6.5EG 6.52026-01-24
phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below allow an authenticated user without the dlattachment permission to download FAQ attachments due to a incomprehensive permissions check. The presence of a right key i…
- CVE-2026-24451HIGHCVSS 7.5EG 7.52026-07-03
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.
- CVE-2026-24473MEDIUMCVSS 5.3EG 5.32026-01-27
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve static Middleware for the Cloudflare Workers adapter contains an information disclosure vulnerability that may allow attac…
- CVE-2026-24509MEDIUMCVSS 5.5EG 5.52026-03-11
Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.
- CVE-2026-24668MEDIUMCVSS 6.5EG 6.52026-02-03
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulnerability allows authenticated students to add content to existing course units, an action …
- CVE-2026-24670MEDIUMCVSS 6.5EG 6.52026-02-03
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulnerability allows authenticated students to create new course units, an action normally rest…
- CVE-2026-24690HIGHCVSS 7.5EG 7.52026-07-03
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
- CVE-2026-24711MEDIUMCVSS 5.3EG 5.32026-05-14
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.
- CVE-2026-24740CRITICALCVSS 9.9EG 9.92026-01-27
Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell endpoints allows a user restricted by label filters (for example, `label=env=dev`) to obtain an interactive root shell i…
- CVE-2026-24896MEDIUMCVSS 6.5EG 6.52026-02-25
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Control vulnerability exists in OpenEMR’s edih_main.php endpoint, which allows any authentic…
- CVE-2026-24904MEDIUMCVSS 5.3EG 5.32026-01-29
TrustTunnel is an open-source VPN protocol with a rule bypass issue in versions prior to 0.9.115. In `tls_listener.rs`, `TlsListener::listen()` peeks 1024 bytes and calls `extract_client_random(...)`. If `parse_tls_plaintext` fails (for ex…
- CVE-2026-25176HIGHCVSS 7.8EG 7.82026-03-10
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2026-25229MEDIUMCVSS 6.5EG 6.52026-02-19
Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have a broken access control vulnerability which allows authenticated users with write access to any repository to modify labels belonging to other repositories. The…
- CVE-2026-25231HIGHCVSS 7.5EG 7.52026-02-09
FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthenticated file read vulnerability due to the lack of access control on the /uploads directory. Files uploaded to this di…
- CVE-2026-2549HIGHCVSS 7.3EG 7.32026-02-16
A vulnerability has been found in zhanghuanhao LibrarySystem 图书馆管理系统 up to 1.1.1. This impacts an unknown function of the file BookController.java. The manipulation leads to improper access controls. The attack is possible to…
- CVE-2026-2550CRITICALCVSS 9.8EG 9.82026-02-16
A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit…
- CVE-2026-25519HIGHCVSS 9.8EG 8.12026-02-04
OpenSlides is a free, web based presentation and assembly system for managing and projecting agenda, motions and elections of an assembly. Prior to version 4.2.29, OpenSlides supports local logins with username and password or an optionall…
- CVE-2026-25702CRITICALCVSS 9.8EG 9.82026-03-05
A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via nftables to not be effective.This issue affects SUSE Linux Enterprise Server: from 9e6d9d…
- CVE-2026-25712HIGHCVSS 7.5EG 7.52026-07-03
Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.
- CVE-2026-25758HIGHCVSS 7.5EG 7.52026-02-06
Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow that allows any guest user to bind arbitrary guest addresses to their order by manipulating …
- CVE-2026-25877MEDIUMCVSS 6.5EG 6.52026-03-06
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, the application performs authorization checks based solely on the project_id parameter w…
- CVE-2026-2592HIGHCVSS 7.7EG 7.72026-02-17
The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Update in all versions up to and including 5.0.16. This is due to the payment callback handler 'Return_from_ZarinPal_Gatew…
- CVE-2026-25966MEDIUMCVSS 5.9EG 5.92026-02-24
ImageMagick is free and open-source software used for editing and manipulating digital images. The shipped "secure" security policy includes a rule intended to prevent reading/writing from standard streams. However, ImageMagick also suppor…
- CVE-2026-26145MEDIUMCVSS 4.8EG 4.82026-07-02
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
- CVE-2026-26183HIGHCVSS 7.8EG 7.82026-04-14
Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.
- CVE-2026-26247CRITICALCVSS 9.1EG 9.12026-07-03
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
- CVE-2026-26292CRITICALCVSS 9.8EG 9.82026-07-03
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
- CVE-2026-26325HIGHCVSS 7.2EG 7.22026-02-19
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, a mismatch between `rawCommand` and `command[]` in the node host `system.run` handler could cause allowlist/approval evaluation to be performed on one command while executing…
- CVE-2026-26328MEDIUMCVSS 6.5EG 6.52026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, under iMessage `groupPolicy=allowlist`, group authorization could be satisfied by sender identities coming from the DM pairing store, broadening DM trust into group contexts.…
- CVE-2026-26417HIGHCVSS 8.1EG 8.12026-03-05
A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to reset passwords of arbitrary user accounts via crafted requests.
- CVE-2026-26418HIGHCVSS 7.5EG 7.52026-03-05
Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows remote attackers to access application functionality without restriction via the network.
- CVE-2026-2665MEDIUMCVSS 6.3EG 6.32026-02-18
A vulnerability was detected in huanzi-qch base-admin up to 57a8126bb3353a004f3c7722089e3b926ea83596. Impacted is the function Upload of the file SysFileController.java of the component JSP Parser. Performing a manipulation of the argument…
- CVE-2026-2666MEDIUMCVSS 7.2EG 4.72026-02-18
A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestric…
- CVE-2026-2667MEDIUMCVSS 5.3EG 5.32026-02-18
A vulnerability has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. The impacted element is an unknown function of the file /dispatch/api?cmd=userinfo. The manipulation leads to improper access con…
- CVE-2026-2668HIGHCVSS 7.3EG 7.32026-02-18
A vulnerability was found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This affects an unknown function of the file /dm/dispatch/user/add of the component User Handler. The manipulation results in improper…
- CVE-2026-2669MEDIUMCVSS 6.5EG 6.52026-02-18
A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impacts an unknown function of the file /dm/dispatch/user/delete of the component User Handler. This manipulation of the arg…
- CVE-2026-2684HIGHCVSS 9.8EG 7.32026-02-19
A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function of the file /Archive/ErecordManage/uploadFile.html. Executing a manipulation of the argumen…
- CVE-2026-26977MEDIUMCVSS 5.3EG 5.32026-02-20
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized users are able to access the details of unpublished courses via API endpoints. A fix for this…
- CVE-2026-2699CRITICALCVSS 9.8EG 9.82026-04-02
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.
- CVE-2026-27152LOWCVSS 3.8EG 3.82026-02-26
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, DM communication-preference bypass when adding members via `Chat::AddUsersToChannel` — a user could add targets who have blocked/ignore…
- CVE-2026-2734MEDIUMCVSS 6.5EG 6.52026-05-21
In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-model authorization checks when basic authentication is enabled. This allows any authentic…
- CVE-2026-2742MEDIUMCVSS 5.3EG 5.32026-03-10
An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24.9.7 and 25.0.0 through 25.0.1, applications using Spring Security due to inconsistent path pattern matching of reserv…
- CVE-2026-27449HIGHCVSS 7.5EG 7.52026-02-26
Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where certain API endpoints are exposed without enforcing authentication or authorization checks.…
- CVE-2026-27471CRITICALCVSS 9.1EG 9.12026-02-21
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been f…
- CVE-2026-27591CRITICALCVSS 9.9EG 9.92026-03-11
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend users to escalate their accounts level of access to the system…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →