← Back
CWE-284

7,620 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,620)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Entra Id
Jun 17, 2026
Aug 23, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant.
1Jayesh
1Hotel Management System
Jun 17, 2026
Aug 22, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.
1Jayesh
1Hotel Management System
Jun 17, 2026
Aug 22, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the adminis...Show more
An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL access.Show less
1Jayesh
1Hotel Management System
Jun 17, 2026
Aug 22, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in administrator section.
1Mattermost
1Mattermost Server
Jun 17, 2026
Aug 22, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.
1Mattermost
1Mattermost Server
Jun 17, 2026
Aug 22, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permissions which allows a user with systems manager role with read-only access to teams to perform write oper...Show more
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permissions which allows a user with systems manager role with read-only access to teams to perform write operations on teams.Show less
1Mattermost
1Mattermost Server
Jun 17, 2026
Aug 22, 2024
N/A· v4
2.7 LOW· v3
N/A· v2
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
1Gitlab
1Gitlab
Jun 17, 2026
Aug 22, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it...Show more
An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups through GraphQL allowing unauthorised users to perform some actions at the group level.Show less
-
-
Jun 17, 2026
Aug 22, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to operation messages that are received by the device.
-
-
Jun 17, 2026
Aug 22, 2024
N/A· v4
7.6 HIGH· v3
N/A· v2
Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP.
1Mattermost
1Mattermost
Jun 17, 2026
Aug 22, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions secti...Show more
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update their role (e.g. member) to include the `manage_system` permission, effectively becoming a System Admin.Show less
1Mattermost
1Mattermost
Jun 17, 2026
Aug 22, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticated user, including guests, to mark any channel inside any team as read for any user.
1Mattermost
1Mattermost
Jun 17, 2026
Aug 22, 2024
N/A· v4
3.7 LOW· v3
N/A· v2
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are...Show more
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server."Show less
1Microsoft
1Azure Managed Instance For Apache Cassandra
Jun 17, 2026
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.
1Escanav
1Escan Management Console
Jun 17, 2026
Aug 20, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
1Joomla
1Joomla
Jun 17, 2026
Aug 20, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Access Controls allows backend users to overwrite their username when disallowed.
1Ghost
1Ghost
Jun 17, 2026
Aug 20, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerabi...Show more
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue.Show less
1Apolloconfig
1Apollo
Jun 17, 2026
Aug 20, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modi...Show more
Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessary permissions. The issue was addressed with an input parameter check which was released in version 2.3.0.Show less
1Umbraco
1Umbraco Cms
Jun 17, 2026
Aug 20, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1.2.
-
-
Jun 17, 2026
Aug 20, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a valid password.