← Back
CWE-284

7,600 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,600)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mattermost
1Mattermost
Jun 17, 2026
Jul 3, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in c...Show more
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in creating a user with a user-defined user ID. This can cause some broken functionality in User Management such administrative actions against the user not working.Show less
1Mattermost
1Mattermost
Jun 17, 2026
Jul 3, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which allows an attacker to specify both a remoteId and the post ID, resulting...Show more
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which allows an attacker to specify both a remoteId and the post ID, resulting in creating a post with a user-defined post ID. This can cause some broken functionality in the channel or thread with user-defined postsShow less
1Mattermost
1Mattermost
Jun 17, 2026
Jul 3, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is t...Show more
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.Show less
1Splunk
2Cloud
Splunk
Jun 17, 2026
Jul 1, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a low-privileged user that does not hold the admin or power Splunk roles could create notifications in S...Show more
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a low-privileged user that does not hold the admin or power Splunk roles could create notifications in Splunk Web Bulletin Messages that all users on the instance receive.Show less
-
-
Jun 17, 2026
Jun 28, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can trick BigBlueButton into generating a signed join link with additi...Show more
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can trick BigBlueButton into generating a signed join link with additional parameters. One of those parameters may be "role=moderator", allowing an attacker to join a meeting as moderator using a join link that was originally created for viewer access. This vulnerability has been patched in version(s) 2.6.18, 2.7.8 and 3.0.0-alpha.7.Show less
1Goauthentik
1Authentik
Jun 17, 2026
Jun 28, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow users without the correct authorization...Show more
authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow users without the correct authorization to get OAuth tokens for an application and access it. This issue has been patched in version(s) 2024.6.0, 2024.2.4 and 2024.4.3.Show less
1Goauthentik
1Authentik
Jun 17, 2026
Jun 28, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will resul...Show more
authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin access to the Authentik application, including resetting user passwords and more. This issue has been patched in version(s) 2024.2.4, 2024.4.2 and 2024.6.0. Show less
1Markoni
2Markoni D (compact) Firmware
Markoni Dh (exciter+amplifiers) Firmware
Jun 17, 2026
Jun 27, 2024
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performing actions beyond their designated permissions.
1Gitlab
1Gitlab
Jun 17, 2026
Jun 27, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeli...Show more
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jun 27, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delet...Show more
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jun 27, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visib...Show more
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.Show less
-
-
Jun 17, 2026
Jun 25, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
Insecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share clipboard data between the SEB kiosk mode and the underlying system, compromising exam integrity. By ex...Show more
Insecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share clipboard data between the SEB kiosk mode and the underlying system, compromising exam integrity. By exploiting this flaw, an attacker can bypass exam controls and gain an unfair advantage during exams.Show less
-
-
Jun 17, 2026
Jun 25, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
GigaDevice GD32E103C8T6 devices have Incorrect Access Control.
-
-
Jun 17, 2026
Jun 25, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
Artery AT32F415CBT7 and AT32F421C8T7 devices have Incorrect Access Control.
-
-
Jun 17, 2026
Jun 24, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An authorization bypass allows remote attackers to achieve unauthenticated remote code execution.
1Access Management Specialist Project
1Access Management Specialist
Jun 17, 2026
Jun 24, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in Shenzhen Weitillage Industrial Co., Ltd the access management specialist V6.62.51215 allows a remote attacker to obtain sensitive information.
-
-
Jun 17, 2026
Jun 21, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails to check the requirement of the captcha field in submitted form data, al...Show more
An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails to check the requirement of the captcha field in submitted form data, allowing a remote user to bypass the captcha check. This only affects the captcha integration for the ext:form extension.Show less
-
-
Jun 17, 2026
Jun 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could allow privilege escalation from a low-privileged read-only...Show more
Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could allow privilege escalation from a low-privileged read-only user to a high-privileged user.Show less
-
-
Jun 17, 2026
Jun 20, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information.
2Fedoraproject
Moodle
2Fedora
Moodle
Jun 17, 2026
Jun 18, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.