CWE-284
7,617 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Fission Function admission webhook (pkg/webhook/f...Show more |
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a Fission Function spec carries three reference types...Show more |
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a low-privilege developer who could create a Kubernet...Show more |
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the Fission router registers an internal-style route...Show more |
1Splunk 2Splunk Splunk Cloud PlatformJun 17, 2026 Jun 10, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131, a user who holds a Splunk role that c...Show more |
Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Sprin...Show more |
Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data...Show more |
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vuln...Show more |
SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php. |
Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type. |
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJul 9, 2026 Jun 9, 2026 N/A· v4 7.9 HIGH· v3 N/A· v2 Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJul 9, 2026 Jun 9, 2026 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally. |
1Microsoft 4Windows 11 24h2 Windows 11 25h2Windows 11 26h1+1 moreJul 9, 2026 Jun 9, 2026 N/A· v4 7.9 HIGH· v3 N/A· v2 Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally. |
1Microsoft 3Windows 11 24h2 Windows 11 25h2Windows 11 26h1Jun 17, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. |
A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector h...Show more |
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity. |
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity. |