CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,322 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 99 of 127
- CVE-2026-32038CRITICALCVSS 9.8EG 9.82026-03-19
OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to join another container's network namespace. Attackers can configure the docker.network parameter with container:<id> value…
- CVE-2026-3209MEDIUMCVSS 6.3EG 6.32026-02-25
A vulnerability has been found in fosrl Pangolin up to 1.15.4-s.3. This affects the function verifyRoleAccess/verifyApiKeyRoleAccess of the component Role Handler. The manipulation leads to improper access controls. Remote exploitation of …
- CVE-2026-32102MEDIUMCVSS 6.5EG 6.52026-03-11
OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution events and action output to authenticated dashboard subscribers without enforcing per-act…
- CVE-2026-32138HIGHCVSS 8.2EG 8.22026-03-12
NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. Prior to 2.0.0, a security vulnerability was identified where Firebase and Web3Forms API keys were exposed. An attacker …
- CVE-2026-32209MEDIUMCVSS 4.4EG 4.42026-05-12
Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
- CVE-2026-32214MEDIUMCVSS 5.5EG 5.52026-04-14
Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
- CVE-2026-32220MEDIUMCVSS 4.4EG 4.42026-04-14
Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
- CVE-2026-32254HIGHCVSS 7.1EG 7.12026-03-18
Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not validate externalIPs or loadBalancer IPs before programming them into the node's network configuration. Version 2.8.0 …
- CVE-2026-32299HIGHCVSS 7.5EG 7.52026-03-23
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the page content retrieval feature may allow…
- CVE-2026-3268MEDIUMCVSS 4.3EG 5.42026-02-26
A vulnerability was detected in psi-probe PSI Probe up to 5.3.0. The affected element is an unknown function of the file psi-probe-core/src/main/java/psiprobe/controllers/sessions/RemoveSessAttributeController.java of the component Session…
- CVE-2026-32693HIGHCVSS 8.8EG 8.82026-03-18
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set"…
- CVE-2026-32699MEDIUMCVSS 5.3EG 5.32026-05-05
FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to validate the nick parameter during a POST request to the EditUser controller. Although the user interface prevent…
- CVE-2026-32720HIGHCVSS 7.1EG 7.12026-03-16
The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). Prior to 0.2.1, due to a mis-written NetworkPolicy, a malicious actor can pivot from a co…
- CVE-2026-32737CRITICALCVSS 10.0EG 10.02026-03-18
Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests within GitHub Actions. Prior to version 0.2.1, due to a mis-written NetworkPolicy, a malicio…
- CVE-2026-32752HIGHCVSS 8.1EG 8.12026-03-19
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, the ThreadPolicy::edit() method contains a broken access control vulnerability that allows any authenticated user (regardless…
- CVE-2026-32760CRITICALCVSS 9.8EG 9.82026-03-20
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2.61.2 and below, any unauthenticated visitor can register a full administrator account wh…
- CVE-2026-32761MEDIUMCVSS 6.5EG 6.52026-03-20
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.0 and below contain a permission enforcement bypass which allows users who are denied do…
- CVE-2026-32768CRITICALCVSS 9.9EG 9.92026-03-20
Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. In versions prior to 0.6.5, due to a miswritten NetworkPolicy, a malicious actor can pivot from an instance to any Pod out of the origin namespace.…
- CVE-2026-32769CRITICALCVSS 9.8EG 9.82026-03-20
Fullchain is an umbrella project for deploying a ready-to-use CTF platform. In versions prior to 0.1.1, due to a mis-written NetworkPolicy, a malicious actor can pivot from a subverted application to any Pod out of the origin namespace. T…
- CVE-2026-32938CRITICALCVSS 6.5EG 9.92026-03-20
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the desktop copies local files pointed to by file:// links in pasted HTML into the workspace assets directory without validating …
- CVE-2026-32994MEDIUMCVSS 5.3EG 5.32026-05-19
The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any authenticated user to retrieve the full content of any message from any room (private groups, …
- CVE-2026-32995HIGHCVSS 7.5EG 7.52026-05-28
The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7.13.8, and <7.10.12 accepts a client-supplied IMessage object and passes it directly to translateMessage() without chec…
- CVE-2026-33031HIGHCVSS 8.1EG 8.12026-04-20
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously issued API tokens for up to the token lifetime. In practice, disabling a compromised account …
- CVE-2026-33062HIGHCVSS 7.5EG 7.52026-03-20
free5GC is an open source 5G core network. free5GC NRF prior to version 1.4.2 has an Improper Input Validation vulnerability leading to Denial of Service. All deployments of free5GC using the NRF discovery service are affected. The `Encode…
- CVE-2026-33103MEDIUMCVSS 5.5EG 5.52026-04-14
Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.
- CVE-2026-33109CRITICALCVSS 9.9EG 9.92026-05-07
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
- CVE-2026-33212LOWCVSS 3.1EG 3.12026-04-15
Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. The attacker ne…
- CVE-2026-33309CRITICALCVSS 9.9EG 9.92026-03-19
Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68478 (External Control of File Name), leading to the root architectural issue within `Loca…
- CVE-2026-33316HIGHCVSS 8.1EG 8.12026-03-24
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled users to regain access to their accounts. The `ResetPassword()` function sets the user’s s…
- CVE-2026-33318HIGHCVSS 8.8EG 8.82026-04-24
Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on servers migrated from password authentication to OpenID Connect. Three weaknesses combine: `…
- CVE-2026-33377HIGHCVSS 7.1EG 7.12026-05-13
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
- CVE-2026-33381MEDIUMCVSS 5.9EG 5.92026-05-13
When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.
- CVE-2026-33393MEDIUMCVSS 4.3EG 4.32026-03-19
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `allowed_spam_host_domains` check used `String#end_with?` without domain boundary validation, allowing domains like `attacker…
- CVE-2026-33415LOWCVSS 2.7EG 2.72026-03-31
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated moderator-level user could retrieve post conten…
- CVE-2026-33478CRITICALCVSS 10.0EG 10.02026-03-23
WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. The `…
- CVE-2026-33484HIGHCVSS 7.5EG 7.52026-03-20
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/api/v1/files/images/{flow_id}/{file_name}` endpoint serves image files without any authentication or ownership check. Any…
- CVE-2026-33622HIGHCVSS 8.8EG 8.82026-03-26
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.3` through `v0.8.5` allow arbitrary JavaScript execution through `POST /wait` and `POST /tabs/{id}/wait` when the request uses `…
- CVE-2026-33726MEDIUMCVSS 4.3EG 4.32026-03-27
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.14, 1.18.8, and 1.19.2, Ingress Network Policies are not enforced for traffic from pods to L7 Services (Envoy, GAMMA) with a …
- CVE-2026-33834HIGHCVSS 7.8EG 7.82026-05-12
Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-33890CRITICALCVSS 9.8EG 9.82026-03-27
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated attacker can register an arbitrary passkey and subsequently authenticate with it to obtain a full admin session. The appli…
- CVE-2026-33951HIGHCVSS 7.5EG 7.52026-04-02
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the SignalK Server exposes an unauthenticated HTTP endpoint that allows remote attackers to modify navigation data source priorit…
- CVE-2026-34045CRITICALCVSS 9.1EG 9.12026-04-07
Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extr…
- CVE-2026-34082MEDIUMCVSS 4.3EG 4.32026-04-20
Dify is an open-source LLM app development platform. Prior to 1.13.1, the method `DELETE /console/api/installed-apps/<appId>/conversations/<conversationId>` has poor authorization checking and allows any Dify-authenticated user to delete s…
- CVE-2026-34233MEDIUMCVSS 6.5EG 6.52026-05-19
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers expose DataTable endpoints without authorization checks, allowing any authenticated user to access sensitive administr…
- CVE-2026-34234CRITICALCVSS 10.0EG 10.02026-05-19
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is vulnerable to unauthenticated Remote Code Execution (RCE) because it performs the install…
- CVE-2026-34248MEDIUMCVSS 5.7EG 5.72026-04-08
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means they can see each other's tickets) could see fields which are not intended for customers - including fields not in…
- CVE-2026-34269MEDIUMCVSS 6.1EG 6.12026-04-21
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows unauthenticated attacker with network acc…
- CVE-2026-34274MEDIUMCVSS 6.1EG 6.12026-04-21
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with networ…
- CVE-2026-34277MEDIUMCVSS 6.6EG 6.62026-04-21
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows high privileged attacker with network…
- CVE-2026-34283MEDIUMCVSS 6.1EG 6.12026-04-21
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Identity Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated a…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →