← Back
CWE-284

7,742 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,742)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Grafana
1Grafana
Jun 17, 2026
May 13, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.
1Grafana
1Grafana
Jun 17, 2026
May 13, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
1Grafana
1Grafana
Jun 17, 2026
May 13, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.
1Vm2 Project
1Vm2
Sep 7, 2026
May 13, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require configuration — including r...Show more
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require configuration — including require: false. With access to vm2, the sandbox constructs a new inner NodeVM with its own unrestricted require settings and executes arbitrary OS commands on the host. Any application that runs untrusted code inside a NodeVM with nesting: true is fully compromised. This vulnerability is fixed in 3.11.1.Show less
1U Speed
1T18 21k Firmware
Jun 30, 2026
May 13, 2026
N/A· v4
6.8 MEDIUM· v3
N/A· v2
U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes a UART interface that lacks authentication, authorization, or access control mechanisms. An attacker...Show more
U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes a UART interface that lacks authentication, authorization, or access control mechanisms. An attacker with physical access to the UART pins can connect to the interface and gain unrestricted access to device functionality.Show less
-
-
Jun 17, 2026
May 12, 2026
5.3 MEDIUM· v4
N/A· v3
N/A· v2
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Broken Access Control allows reading of sketch logs from any user. This vu...Show more
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Broken Access Control allows reading of sketch logs from any user. This vulnerability is fixed in 1.2.3.Show less
-
-
Jun 17, 2026
May 12, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthenticated users to access job details by directly manipulating object identifiers. The endpoint lacks prop...Show more
GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthenticated users to access job details by directly manipulating object identifiers. The endpoint lacks proper authentication and authorization checks, resulting in unauthorized access to job data.Show less
-
-
Jun 17, 2026
May 12, 2026
2.3 LOW· v4
N/A· v3
N/A· v2
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, an adversary with knowledge of an investigation ID, could update the metad...Show more
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, an adversary with knowledge of an investigation ID, could update the metadata of an investigation of another user. This vulnerability is fixed in 1.2.3.Show less
1Arubanetworks
1Arubaos
Jun 17, 2026
May 12, 2026
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Successful exploitation of...Show more
A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Successful exploitation of this vulnerability could result in the disclosure of confidential system information, potentially enabling further attacks against the affected device.Show less
-
-
Jun 17, 2026
May 12, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the host filesystem. A va...Show more
Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the host filesystem. A validateFsPath() function is supposed to sandbox this access, but its blocklist is incomplete. Any web app packaged with Pulpy can read and write arbitrary files in the user's home directory — including ~/.ssh/id_rsa, ~/.aws/credentials, and ~/Library/Keychains/. This vulnerability is fixed in 0.1.1.Show less
1Fortinet
1Fortiauthenticator
Jun 17, 2026
May 12, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unautho...Show more
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests.Show less
1Microsoft
4Excel
OfficeOffice Long Term Servicing Channel+1 more
Jun 17, 2026
May 12, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
1Microsoft
1Azure Logic Apps
Jun 17, 2026
May 12, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
-
-
Jun 17, 2026
May 12, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter is Platform.SSO_URL +...Show more
linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter is Platform.SSO_URL + "/*", i.e. "https://login.microsoftonline.com/*". Chrome's urlFilter without a | or || anchor is substring-matched against the full request URL. The same applied rule action is modifyHeaders that attaches the Entra ID Primary Refresh Token cookie. The Firefox adapter in platform/firefox/js/platform-firefox.js:53 performs a belt-and-braces startsWith(Platform.SSO_URL) check before injecting the header; the Chrome adapter does not. When the extension holds broad host permissions through the optional_host_permissions: ["https://*/*"] declared in platform/chrome/manifest.json:34, a main-frame navigation to a URL whose path embeds https://login.microsoftonline.com/ causes Chrome to attach the PRT cookie to the request to the attacker-controlled host. This vulnerability is fixed in 1.8.1.Show less
1Microsoft
1365 Copilot
Jun 17, 2026
May 12, 2026
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
1Microsoft
1Powerpoint
Jun 17, 2026
May 12, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.
1Microsoft
1Word
Jun 17, 2026
May 12, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.
1Microsoft
1365 Copilot
Jun 17, 2026
May 12, 2026
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
1Microsoft
1Windows Admin Center
Jun 17, 2026
May 12, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
1Microsoft
3365 Apps
OfficeOffice Long Term Servicing Channel
Jun 17, 2026
May 12, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.