CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,321 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 97 of 127
- CVE-2026-27624MEDIUMCVSS 6.5EG 6.52026-02-25
Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denied-peer-ip" and/or default loopback restrictions. CVE-2020-26262 addressed bypasses involvi…
- CVE-2026-27660HIGHCVSS 7.5EG 7.52026-07-03
Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.
- CVE-2026-2768CRITICALCVSS 10.0EG 10.02026-02-24
Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
- CVE-2026-27708HIGHCVSS 7.1EG 7.12026-06-24
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method accepts an order_id parameter and fetches the associated order without verifying the authent…
- CVE-2026-27723MEDIUMCVSS 5.3EG 5.32026-03-05
OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker can create wiki pages belonging to unpermitted projects through an improperly authenticated request. This issue has been…
- CVE-2026-27779HIGHCVSS 7.5EG 7.52026-07-03
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
- CVE-2026-27914HIGHCVSS 7.8EG 7.82026-04-14
Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.
- CVE-2026-27975CRITICALCVSS 9.8EG 9.82026-02-26
Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbitrary code on this server. This is fixed in the version 2.2.13.
- CVE-2026-28215CRITICALCVSS 9.1EG 9.12026-02-26
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration of a self-hosted Hoppscotch instance including OAuth provider credentials …
- CVE-2026-28218MEDIUMCVSS 5.4EG 5.42026-02-26
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access control in Data Explorer plugin allows any authenticated user to execute SQL queries that have no explicit group assignm…
- CVE-2026-28230MEDIUMCVSS 6.3EG 6.32026-02-26
SteVe is an open-source EV charging station management system. In versions up to and including 3.11.0, when a charger sends a StopTransaction message, SteVe looks up the transaction solely by transactionId (a sequential integer starting fr…
- CVE-2026-28276HIGHCVSS 7.5EG 7.52026-02-26
Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions prior to 0.32.2 where uploaded documents are served from a publicly accessible /uploads/ directory without any authentic…
- CVE-2026-28304CRITICALCVSS 9.1EG 9.12026-07-21
SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
- CVE-2026-28306CRITICALCVSS 9.1EG 9.12026-07-21
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
- CVE-2026-28307CRITICALCVSS 9.1EG 9.12026-07-21
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.
- CVE-2026-28321CRITICALCVSS 9.1EG 9.12026-07-21
SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and t…
- CVE-2026-28374MEDIUMCVSS 4.3EG 4.32026-05-13
Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.
- CVE-2026-28378LOWCVSS 3.1EG 3.12026-07-07
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
- CVE-2026-28381CRITICALCVSS 8.1EG 9.62026-06-22
The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.
- CVE-2026-28410HIGHCVSS 8.1EG 8.12026-03-05
The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to version 3.0.0, a flaw in the token vesting contracts allows users to access tokens that should still be locked according …
- CVE-2026-28415MEDIUMCVSS 4.7EG 4.32026-03-01
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target() function in Gradio's OAuth flow accepts an unvalidated _target_url query parameter, allowing redirection to arbitrary…
- CVE-2026-2849MEDIUMCVSS 6.3EG 5.42026-02-20
A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function deleteCache/removeAllCache/syncCache of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys…
- CVE-2026-2850MEDIUMCVSS 6.5EG 6.32026-02-20
A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addCustomer/updateCustomer/deleteCustomer of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus\controller\C…
- CVE-2026-2851MEDIUMCVSS 5.3EG 6.32026-02-20
A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability affects the function addInport/updateInport/deleteInport of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus…
- CVE-2026-2852MEDIUMCVSS 6.3EG 6.32026-02-20
A vulnerability was identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects the function addSales/updateSales/deleteSales of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus\controller…
- CVE-2026-2861MEDIUMCVSS 5.3EG 5.32026-02-21
A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Changes/Viewfile/Oops. The manipulation results in information disclosure. It is possible to launch the attack remotely. The…
- CVE-2026-28682MEDIUMCVSS 6.4EG 6.42026-03-06
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implementation on /uploadStatus publishes global upload state to any authenticated listener and inc…
- CVE-2026-28699HIGHCVSS 8.1EG 8.12026-06-16
Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.
- CVE-2026-28790HIGHCVSS 7.5EG 7.52026-03-05
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to terminate running actions through KillAction even when authRequireGuestsToLogin: true is enabl…
- CVE-2026-28803MEDIUMCVSS 6.5EG 6.52026-03-11
Open Forms allows users create and publish smart forms. Prior to 3.3.13 and 3.4.5, to be able to cosign, the cosigner receives an e-mail with instructions or a deep-link to start the cosign flow. The submission reference is communicated so…
- CVE-2026-28818MEDIUMCVSS 5.3EG 5.32026-03-25
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.
- CVE-2026-28821HIGHCVSS 8.4EG 8.42026-03-25
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be abl…
- CVE-2026-28823MEDIUMCVSS 4.9EG 4.92026-03-25
A path handling issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.4. An app with root privileges may be able to delete protected system files.
- CVE-2026-28824MEDIUMCVSS 5.3EG 5.32026-03-25
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.
- CVE-2026-28828MEDIUMCVSS 5.3EG 5.32026-03-25
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.
- CVE-2026-28833MEDIUMCVSS 6.2EG 6.22026-03-25
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. An app may be able to enumerate a user's installed apps.
- CVE-2026-28837HIGHCVSS 7.5EG 7.52026-03-25
A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.
- CVE-2026-28838MEDIUMCVSS 5.3EG 5.32026-03-25
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.
- CVE-2026-28855HIGHCVSS 7.5EG 7.52026-03-25
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3. An app may be able to access protected user data.
- CVE-2026-28856MEDIUMCVSS 4.6EG 4.62026-03-25
The issue was addressed with improved authentication. This issue is fixed in iOS 26.4 and iPadOS 26.4, visionOS 26.4, watchOS 26.4. An attacker with physical access to a locked device may be able to view sensitive user information.
- CVE-2026-28862MEDIUMCVSS 5.3EG 5.32026-03-25
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access user-sensitive data.
- CVE-2026-28863MEDIUMCVSS 6.5EG 6.52026-03-25
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to fingerprint the user.
- CVE-2026-28876HIGHCVSS 7.5EG 7.52026-03-25
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, vis…
- CVE-2026-28880MEDIUMCVSS 6.5EG 6.52026-03-25
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able t…
- CVE-2026-28895MEDIUMCVSS 4.6EG 4.62026-03-25
The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical access to an iOS device with Stolen Device Protection enabled may be able to access biometrics-gated Protected Apps wi…
- CVE-2026-28910LOWCVSS 3.3EG 3.32026-05-11
This issue was addressed with improved permissions checking. This issue is fixed in macOS Tahoe 26.4. A malicious app may be able to access arbitrary files.
- CVE-2026-28922MEDIUMCVSS 6.5EG 6.52026-05-11
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to access private information.
- CVE-2026-28930HIGHCVSS 7.5EG 7.52026-05-11
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protected user data.
- CVE-2026-2894CRITICALCVSS 9.1EG 9.12026-02-21
A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/login/forget.html. Such manipulation leads to information disclosure. The attack may be laun…
- CVE-2026-28945HIGHCVSS 7.1EG 7.12026-07-27
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to bypass network restrictions.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →