← Back
CWE-284

7,483 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,483)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Derhansen
1Event Management And Registration
Jun 17, 2026
Feb 13, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check for events in the backend module got broken during the u...Show more
sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check for events in the backend module got broken during the update of the extension to TYPO3 12.4, because the `RedirectResponse` from the `$this->redirect()` function was never handled. This issue has been addressed in version 7.4.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Microsoft
1Entra Jira Sso Plugin
Aug 10, 2026
Feb 13, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability
1Microsoft
1Azure Kubernetes Service
Aug 10, 2026
Feb 13, 2024
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
1Microsoft
1Azure Site Recovery
Aug 10, 2026
Feb 13, 2024
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Microsoft Azure Site Recovery Elevation of Privilege Vulnerability
1Microsoft
1Skype For Business Server
Aug 10, 2026
Feb 13, 2024
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Skype for Business Information Disclosure Vulnerability
1Moodle
1Moodle
Jun 17, 2026
Feb 12, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to...Show more
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.Show less
1Mattermost
1Mattermost Server
Jun 17, 2026
Feb 9, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in channel member counts being leaked to a user without permissions.
1Minbrowser
1Min
Jun 17, 2026
Feb 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resources. For example, a local file may request other local files through an X...Show more
In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resources. For example, a local file may request other local files through an XML document.Show less
1Openobserve
1Openobserve
Jun 17, 2026
Feb 8, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" en...Show more
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulnerability allows any authenticated user within an organization to remove any other user from that same organization, irrespective of their respective roles. This includes the ability to remove users with "Admin" and "Root" roles. By enabling any organizational member to unilaterally alter the user base, it opens the door to unauthorized access and can cause considerable disruptions in operations. The core of the vulnerability lies in the `remove_user_from_org` function in the user management system. This function is designed to allow organizational users to remove members from their organization. The function does not check if the user initiating the request has the appropriate administrative privileges to remove a user. Any user who is part of the organization, irrespective of their role, can remove any other user, including those with higher privileges. This vulnerability is categorized as an Authorization issue leading to Unauthorized User Removal. The impact is severe, as it compromises the integrity of user management within organizations. By exploiting this vulnerability, any user within an organization, without the need for administrative privileges, can remove critical users, including "Admins" and "Root" users. This could result in unauthorized system access, administrative lockout, or operational disruptions. Given that user accounts are typically created by "Admins" or "Root" users, this vulnerability can be exploited by any user who has been granted access to an organization, thereby posing a critical risk to the security and operational stability of the application. This issue has been addressed in release version 0.8.0. Users are advised to upgrade.Show less
1Openobserve
1Openobserve
Jun 17, 2026
Feb 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnera...Show more
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any authenticated regular user ('member') to add new users with elevated privileges, including the 'root' role, to an organization. This issue circumvents the intended security controls for role assignments. The vulnerability resides in the user creation process, where the payload does not validate the user roles. A regular user can manipulate the payload to assign root-level privileges. This vulnerability leads to Unauthorized Privilege Escalation and significantly compromises the application's role-based access control system. It allows unauthorized control over application resources and poses a risk to data security. All users, particularly those in administrative roles, are impacted. This issue has been addressed in release version 0.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Remyandrade
1Daily Habit Tracker
Jun 17, 2026
Feb 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.
1Pluginsandsnippets
1Simple Page Access Restriction
Jun 17, 2026
Feb 8, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers...Show more
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's page restriction and view page content.Show less
1Graylog
1Graylog
Jun 17, 2026
Feb 7, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the `/api/system/cluster_...Show more
Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the `/api/system/cluster_config/` endpoint. Graylog's cluster config system uses fully qualified class names as config keys. To validate the existence of the requested class before using them, Graylog loads the class using the class loader. If a user with the appropriate permissions performs the request, arbitrary classes with 1-arg String constructors can be instantiated. This will execute arbitrary code that is run during class instantiation. In the specific use case of `java.io.File`, the behavior of the internal web-server stack will lead to information exposure by including the entire file content in the response to the REST request. Versions 5.1.11 and 5.2.4 contain a fix for this issue.Show less
1Maykinmedia
1Open Forms
Jun 17, 2026
Feb 7, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authentication weakness. Superusers who have their credentials (username + p...Show more
Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authentication weakness. Superusers who have their credentials (username + password) compromised could potentially have the second-factor authentication bypassed if an attacker somehow managed to authenticate to Open Forms. The maintainers of Open Forms do not believe it is or has been possible to perform this login. However, if this were possible, the victim's account may be abused to view (potentially sensitive) submission data or have been used to impersonate other staff accounts to view and/or modify data. Three mitigating factors to help prevent exploitation include: the usual login page (at `/admin/login/`) does not fully log in the user until the second factor was succesfully provided; the additional non-MFA protected login page at `/api/v2/api-authlogin/` was misconfigured and could not be used to log in; and there are no additional ways to log in. This also requires credentials of a superuser to be compromised to be exploitable. Versions 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain the following patches to address these weaknesses: Move and only enable the API auth endpoints (`/api/v2/api-auth/login/`) with `settings.DEBUG = True`. `settings.DEBUG = True` is insecure and should never be applied in production settings. Additionally, apply a custom permission check to the hijack flow to only allow second-factor-verified superusers to perform user hijacking.Show less
1Elastic
1Network Drive Connector
Jun 17, 2026
Feb 7, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read. Although the document is not accessible to the u...Show more
An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read. Although the document is not accessible to the user in Network Drive it is visible in search applications to the user.Show less
1Elastic
1Kibana
Jun 17, 2026
Feb 7, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users...Show more
An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain unauthorized access to documents if their roles are configured with DLS or FLS against the aforementioned index.Show less
1Dell
3Encryption
Endpoint Security Suite EnterpriseSecurity Management Server
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation direc...Show more
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in installed directory and taking reverse shell of the system leading to Privilege Escalation. Show less
1Qualcomm
19Qam8255p Firmware
Qam8295p FirmwareQam8650p Firmware+16 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Automotive Multimedia due to improper access control in HAB.
1Themeisle
1Rss Aggregator By Feedzy
Jun 17, 2026
Feb 5, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashbo...Show more
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashboard in all versions up to, and including, 4.4.1. This makes it possible for authenticated attackers, with contributor access or higher, to create, edit or delete feed categories created by them.Show less
1Reputeinfosystems
1Armember
Jun 17, 2026
Feb 5, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's...Show more
The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "Default Restriction" feature and view restricted post content.Show less