CWE-284
7,479 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to...Show more |
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization gr...Show more |
Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.26.0-pre1, lib/policy/checker.go PathChecker.Check() trusted the client...Show more |
Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored sou...Show more |
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a...Show more |
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-savin...Show more |
Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_READ` and `TDE_IOCTL_INDEXIO_WRITE` permit unprivil...Show more |
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening rele...Show more |
Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (Do...Show more |
1Microsoft 3Configuration Manager 2503 Configuration Manager 2509Configuration Manager 2603Jul 30, 2026 Jul 14, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. |
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJul 17, 2026 Jul 14, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. |
1Microsoft 4Windows 10 1809 Windows Server 2019Windows Server 2022+1 moreJul 23, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally. |
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
1Microsoft 9Windows 10 1809 Windows 10 21h2Windows 10 22h2+6 moreJul 22, 2026 Jul 14, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. |
1Microsoft 4Windows 11 24h2 Windows 11 25h2Windows 11 26h1+1 moreJul 22, 2026 Jul 14, 2026 N/A· v4 7.1 HIGH· v3 N/A· v2 Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. |
1Microsoft 7Windows 10 21h2 Windows 10 22h2Windows 11 24h2+4 moreJul 22, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. |
1Microsoft 5Windows 11 24h2 Windows 11 25h2Windows 11 26h1+2 moreJul 22, 2026 Jul 14, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. |
1Microsoft 9Windows 10 1809 Windows 10 21h2Windows 10 22h2+6 moreJul 22, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
1Microsoft 9Windows 10 1809 Windows 10 21h2Windows 10 22h2+6 moreJul 23, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. |