← Back
CWE-284

7,480 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,480)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jul 7, 2026
Jul 3, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
-
-
Jul 7, 2026
Jul 3, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.
-
-
Jul 6, 2026
Jul 3, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.
-
-
Jul 7, 2026
Jul 3, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
-
-
Jul 7, 2026
Jul 3, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are ena...Show more
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.Show less
-
-
Jul 6, 2026
Jul 3, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.
1Redhat
1Build Of Keycloak
Aug 11, 2026
Jul 3, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control ov...Show more
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.Show less
1Redhat
1Build Of Keycloak
Aug 31, 2026
Jul 3, 2026
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2...Show more
A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of all groups assigned to that role. The system fails to check if the administrator has permission to see those specific groups. This could allow a restricted administrator to discover "hidden" groups and see their details, such as internal names and custom settings, which might contain sensitive deployment information.Show less
1Dell
1Data Domain Operating System
Jul 8, 2026
Jul 3, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain...Show more
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.Show less
1Microsoft
1Azure Synapse
Jul 7, 2026
Jul 2, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
1Ui
1Unifi Talk Application
Jul 9, 2026
Jul 2, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.
1Ui
1Unifi Network Application
Jul 6, 2026
Jul 2, 2026
N/A· v4
8.3 HIGH· v3
N/A· v2
A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi N...Show more
A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.Show less
1Ui
1Unifi Connect
Jul 9, 2026
Jul 2, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such...Show more
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.Show less
1Ui
1Unifi Network Application
Jul 6, 2026
Jul 2, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
1Ui
19Enterprise Network Video Recorder Core Firmware
Enterprise Network Video Recorder FirmwareUnifi Cloud Gateway Fiber Firmware+16 more
Jul 10, 2026
Jul 2, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges...Show more
A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.Show less
1Ui
1Unifi Protect
Jul 7, 2026
Jul 2, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.
1Ui
1Unifi Protect
Jul 6, 2026
Jul 2, 2026
N/A· v4
8.6 HIGH· v3
N/A· v2
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.
1Ui
2Unifi Access
Unifi Access Application
Aug 17, 2026
Jul 2, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
1Ui
1Unifi Connect Application
Jul 29, 2026
Jul 2, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
1Lfprojects
1Mlflow
Jul 6, 2026
Jul 2, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization cont...Show more
In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they do not have permission to access. The issue arises from the `_before_request` handler, which does not register authorization validators for trace endpoints, resulting in requests proceeding without validation. This vulnerability can expose sensitive data, destroy audit logs, and allow unauthorized modifications.Show less