← Back
CWE-284

7,617 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Jun 10, 2026
N/A· v4
8.5 HIGH· v3
N/A· v2
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Fission Function admission webhook (pkg/webhook/f...Show more
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Fission Function admission webhook (pkg/webhook/function.go) validated that spec.secrets[].namespace and spec.configmaps[].namespace equalled the function's own namespace but performed no equivalent check on spec.environment.namespace. This issue has been patched in version 1.24.0.Show less
-
-
Jun 17, 2026
Jun 10, 2026
N/A· v4
7.7 HIGH· v3
N/A· v2
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a Fission Function spec carries three reference types...Show more
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a Fission Function spec carries three reference types — Secret, ConfigMap, and Package. The first two were namespace-validated by the admission webhook; PackageRef.Namespace was not. This issue has been patched in version 1.24.0.Show less
-
-
Jun 17, 2026
Jun 10, 2026
N/A· v4
7.7 HIGH· v3
N/A· v2
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a low-privilege developer who could create a Kubernet...Show more
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a low-privilege developer who could create a KubernetesWatchTrigger (KWT) in their own namespace was able to establish a persistent surveillance channel over any other namespace. This issue has been patched in version 1.24.0.Show less
-
-
Jun 17, 2026
Jun 10, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the Fission router registers an internal-style route...Show more
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the Fission router registers an internal-style route — /fission-function/<name> and /fission-function/<ns>/<name> — for every Function object, independent of whether any HTTPTrigger exists for that function. The route was mounted on the same listener as user-defined HTTPTriggers (svc/router, port 8888), so any caller who could reach the router could invoke any function by guessing its metadata.name (and namespace), bypassing the host / path / method / method-allow-list restrictions encoded in HTTPTrigger objects. This issue has been patched in version 1.23.0.Show less
1Splunk
2Splunk
Splunk Cloud Platform
Jun 17, 2026
Jun 10, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131, a user who holds a Splunk role that c...Show more
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131, a user who holds a Splunk role that contains the high-privilege capability `edit_saved_search_owner` could reassign saved search ownership to users outside their authorized scope. The ownership reassignment endpoint lacks access control.Show less
1Vmware
1Spring Data Rest
Jul 17, 2026
Jun 10, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Sprin...Show more
Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.Show less
1Vmware
1Spring Data Rest
Jul 17, 2026
Jun 10, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data...Show more
Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.Show less
1Adobe
1Dreamweaver
Aug 28, 2026
Jun 9, 2026
N/A· v4
8.6 HIGH· v3
N/A· v2
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vuln...Show more
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.Show less
-
-
Jun 17, 2026
Jun 9, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
-
-
Jun 17, 2026
Jun 9, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type.
1Microsoft
1Pc Manager
Jun 17, 2026
Jun 9, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Jul 9, 2026
Jun 9, 2026
N/A· v4
7.9 HIGH· v3
N/A· v2
Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Jul 9, 2026
Jun 9, 2026
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.
1Microsoft
4Windows 11 24h2
Windows 11 25h2Windows 11 26h1+1 more
Jul 9, 2026
Jun 9, 2026
N/A· v4
7.9 HIGH· v3
N/A· v2
Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
1Microsoft
3Excel
PowerpointWord
Jun 19, 2026
Jun 9, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
1Microsoft
3Windows 11 24h2
Windows 11 25h2Windows 11 26h1
Jun 17, 2026
Jun 9, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Jun 17, 2026
Jun 9, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.
1Fortinet
1Fortiportal
Jun 17, 2026
Jun 9, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector h...Show more
A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector here>Show less
-
-
Jun 17, 2026
Jun 9, 2026
N/A· v4
5.1 MEDIUM· v3
N/A· v2
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.
-
-
Jun 17, 2026
Jun 9, 2026
N/A· v4
5.2 MEDIUM· v3
N/A· v2
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.