CWE-284
7,820 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,820)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations. |
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require configuration — including r...Show more |
U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes a UART interface that lacks authentication, authorization, or access control mechanisms. An attacker...Show more |
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Broken Access Control allows reading of sketch logs from any user. This vu...Show more |
GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthenticated users to access job details by directly manipulating object identifiers. The endpoint lacks prop...Show more |
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, an adversary with knowledge of an investigation ID, could update the metad...Show more |
A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Successful exploitation of...Show more |
Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the host filesystem. A va...Show more |
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unautho...Show more |
1Microsoft 4Excel OfficeOffice Long Term Servicing Channel+1 moreJun 17, 2026 May 12, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. |
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. |
linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter is Platform.SSO_URL +...Show more |
Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally. |
Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally. |
Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. |
Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. |
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. |
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelJun 17, 2026 May 12, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. |
1Microsoft 1Azure Connected Machine Agent Jun 17, 2026 May 12, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. |
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJun 17, 2026 May 12, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. |