← Back
CWE-284

7,479 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hcltech
1Dfx Server
Jul 21, 2026
Jul 16, 2026
N/A· v4
6.3 MEDIUM· v3
N/A· v2
HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to...Show more
HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.Show less
1Redhat
1Build Of Keycloak
Aug 9, 2026
Jul 16, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization gr...Show more
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provider to obtain a JWT for a disabled user. This allows unauthorized access to sensitive resources.Show less
-
-
Aug 12, 2026
Jul 15, 2026
N/A· v4
5.8 MEDIUM· v3
N/A· v2
Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.26.0-pre1, lib/policy/checker.go PathChecker.Check() trusted the client...Show more
Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.26.0-pre1, lib/policy/checker.go PathChecker.Check() trusted the client-controlled X-Original-URI header before matching r.URL.Path, allowing an HTTP client to match default data/common/keep-internet-working.yaml ALLOW rules such as ^/\.well-known/.*$ and bypass the Anubis challenge. This issue is fixed in version 1.26.0-pre1.Show less
-
-
Jul 16, 2026
Jul 15, 2026
N/A· v4
8.5 HIGH· v3
N/A· v2
Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored sou...Show more
Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored source boardId and do not validate a new boardId in the update modifier. Any authenticated user with write access to their own board can call /cards/update, /lists/update, or /swimlanes/update to move cards, lists, or swimlanes into a private board they are not a member of. This issue is fixed in version 9.37.Show less
-
-
Jul 16, 2026
Jul 15, 2026
N/A· v4
7.7 HIGH· v3
N/A· v2
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a...Show more
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a GUI_WND_HOOK_REGISTER request without validating that the thread belongs to the sandboxed process or that the function pointer is in the caller address space, and GuiServer::WndHookNotifySlave then calls OpenThread(THREAD_SET_CONTEXT, FALSE, whk->hthread) and QueueUserAPC((PAPCFUNC)whk->hproc, hThread, (ULONG_PTR)req->threadid) as SYSTEM, allowing a sandboxed process to execute arbitrary code in an unsandboxed host process. This issue is fixed in version 1.17.6.Show less
-
-
Jul 20, 2026
Jul 15, 2026
N/A· v4
8.2 HIGH· v3
N/A· v2
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-savin...Show more
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing unauthorized modification of dashboard configuration and potential service disruption. This issue is fixed in version 4.0.8.Show less
-
-
Jul 16, 2026
Jul 15, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_READ` and `TDE_IOCTL_INDEXIO_WRITE` permit unprivil...Show more
Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_READ` and `TDE_IOCTL_INDEXIO_WRITE` permit unprivileged user-mode callers to perform arbitrary hardware I/O port reads and writes without authorization checks. A local attacker can abuse this functionality to manipulate hardware registers, tamper with firmware-related interfaces, cause system instability, or establish persistent low-level compromise.Show less
1Cisco
2Roomos
Roomos Cloud
Aug 14, 2026
Jul 15, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening rele...Show more
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20150 are related to improper access control that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.Show less
-
-
Jul 15, 2026
Jul 14, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (Do...Show more
Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (DoS) via removing the license from the webserver.Show less
1Microsoft
3Configuration Manager 2503
Configuration Manager 2509Configuration Manager 2603
Jul 30, 2026
Jul 14, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
1Microsoft
1365 Copilot
Jul 16, 2026
Jul 14, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jul 17, 2026
Jul 14, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
1Microsoft
4Windows 10 1809
Windows Server 2019Windows Server 2022+1 more
Jul 23, 2026
Jul 14, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.
1Microsoft
1Sharepoint Server
Jul 15, 2026
Jul 14, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
1Microsoft
9Windows 10 1809
Windows 10 21h2Windows 10 22h2+6 more
Jul 22, 2026
Jul 14, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
1Microsoft
4Windows 11 24h2
Windows 11 25h2Windows 11 26h1+1 more
Jul 22, 2026
Jul 14, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
1Microsoft
7Windows 10 21h2
Windows 10 22h2Windows 11 24h2+4 more
Jul 22, 2026
Jul 14, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
1Microsoft
5Windows 11 24h2
Windows 11 25h2Windows 11 26h1+2 more
Jul 22, 2026
Jul 14, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.
1Microsoft
9Windows 10 1809
Windows 10 21h2Windows 10 22h2+6 more
Jul 22, 2026
Jul 14, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
1Microsoft
9Windows 10 1809
Windows 10 21h2Windows 10 22h2+6 more
Jul 23, 2026
Jul 14, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.