← Back
CWE-284

7,480 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,480)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Silverpeas
1Silverpeas
Jul 9, 2026
Dec 13, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or perm...Show more
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.Show less
1Fortinet
2Fortios
Fortiproxy
Jun 17, 2026
Dec 13, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below ma...Show more
An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below may allow a remote unauthenticated attacker to bypass the firewall deny geolocalisation policy via timing the bypass with a GeoIP database update.Show less
1Relyum
1Rely Pcie Firmware
Jun 17, 2026
Dec 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central password hash file of the operating system.
1Mattermost
1Mattermost Server
Jun 17, 2026
Dec 12, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook....Show more
Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team.  Show less
1Mattermost
1Mattermost Server
Jun 17, 2026
Dec 12, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest to update the tasks of a private playbook run if they know the run ID.
1Huawei
1Ar617vw Firmware
Jun 17, 2026
Dec 12, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
An improper access control vulnerability exists in a Huawei datacom product. Attackers can exploit this vulnerability to obtain partial device information.
1Softwareag
1Webmethods
Jun 17, 2026
Dec 7, 2023
N/A· v4
6.5 MEDIUM· v3
7.5 HIGH· v2
A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown function of the file wm.server/connect/. The manipulation leads to improper access controls. It is p...Show more
A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown function of the file wm.server/connect/. The manipulation leads to improper access controls. It is possible to launch the attack remotely. To access a file like /assets/ a popup may request username and password. By just clicking CANCEL you will be redirected to the directory. If you visited /invoke/wm.server/connect, you'll be able to see details like internal IPs, ports, and versions. In some cases if access to /assets/ is refused, you may enter /assets/x as a wrong value, then come back to /assets/ which we will show the requested data. It appears that insufficient access control is depending on referrer header data. VDB-247158 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Pleasanter
1Pleasanter
Jun 17, 2026
Dec 6, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Pleasanter 1.3.47.0 and earlier contains an improper access control vulnerability, which may allow a remote authenticated attacker to view the temporary files uploaded by other users who are not permitted to access.
1Qemu
1Qemu
Jun 17, 2026
Dec 6, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exporte...Show more
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creating and opening a device file in the shared folder.Show less
1Qualcomm
13Qca6574 Firmware
Qca6574a FirmwareQca6574au Firmware+10 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities.
1Dell
1Rugged Control Center
Jun 17, 2026
Dec 2, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured fol...Show more
Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder when product installation repair is performed, leading to privilege escalation on the system. Show less
1Dell
1Rugged Control Center
Jun 17, 2026
Dec 2, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Rugged Control Center, version prior to 4.7, contains an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured fol...Show more
Dell Rugged Control Center, version prior to 4.7, contains an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder during product installation and upgrade, leading to privilege escalation on the system. Show less
1Dell
1Rugged Control Center
Jun 17, 2026
Dec 1, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy...Show more
Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources. Show less
1Netgear
1Prosafe Network Management System
Jun 17, 2026
Nov 29, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application directory. The user can then execute the J...Show more
A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application directory. The user can then execute the JSP files under the security context of SYSTEM. Show less
1Oroinc
1Orocommerce
Jun 17, 2026
Nov 28, 2023
N/A· v4
5.8 MEDIUM· v3
N/A· v2
OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order totals information may be received by Order ID. This issue is patched in version 5.0.11 and 5.1.1.
1Oroinc
1Orocommerce
Jun 17, 2026
Nov 28, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to in...Show more
OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.11 and 5.1.1. Show less
1Oroinc
1Client Relationship Management
Jun 17, 2026
Nov 28, 2023
N/A· v4
5.0 MEDIUM· v3
N/A· v2
OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security c...Show more
OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and 5.1.1.Show less
1Oroinc
1Oroplatform
Jun 17, 2026
Nov 27, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks....Show more
OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.Show less
1Mattermost
1Mattermost
Jun 17, 2026
Nov 27, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, ni...Show more
Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards. Show less
1Mattermost
1Mattermost
Jun 17, 2026
Nov 27, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member...Show more
Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled Show less