← Back
CWE-284

5,470 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,470)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jul 6, 2026
Jul 3, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
-
-
Jul 6, 2026
Jul 3, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
1Microsoft
1Edge Chromium
Jul 7, 2026
Jul 3, 2026
N/A· v4
6.9 MEDIUM· v3
N/A· v2
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
1Microsoft
1Edge Chromium
Jul 6, 2026
Jul 3, 2026
N/A· v4
6.9 MEDIUM· v3
N/A· v2
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
-
-
Jul 6, 2026
Jul 3, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.
-
-
Jul 6, 2026
Jul 3, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
-
-
Jul 7, 2026
Jul 3, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.
-
-
Jul 7, 2026
Jul 3, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
-
-
Jul 7, 2026
Jul 3, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
-
-
Jul 7, 2026
Jul 3, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.
-
-
Jul 7, 2026
Jul 3, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
-
-
Jul 7, 2026
Jul 3, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.
-
-
Jul 6, 2026
Jul 3, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.
-
-
Jul 7, 2026
Jul 3, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
-
-
Jul 7, 2026
Jul 3, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are ena...Show more
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.Show less
-
-
Jul 6, 2026
Jul 3, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.
-
-
Jul 17, 2026
Jul 3, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control ov...Show more
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.Show less
-
-
Jul 7, 2026
Jul 3, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2...Show more
A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of all groups assigned to that role. The system fails to check if the administrator has permission to see those specific groups. This could allow a restricted administrator to discover "hidden" groups and see their details, such as internal names and custom settings, which might contain sensitive deployment information.Show less
1Dell
1Data Domain Operating System
Jul 8, 2026
Jul 3, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain...Show more
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.Show less
1Microsoft
1Azure Synapse
Jul 7, 2026
Jul 2, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.