← Back
CWE-284

7,479 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Elastic
1Elastic Sharepoint Online Python Connector
Jun 17, 2026
Oct 26, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharep...Show more
An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through Elasticsearch.Show less
1Sielco
15Analog Fm Transmitter Exc1000gt Firmware
Analog Fm Transmitter Exc1000gx FirmwareAnalog Fm Transmitter Exc100gt Firmware+12 more
Jun 17, 2026
Oct 26, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters....Show more
The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters. Show less
1Sielco
15Analog Fm Transmitter Exc1000gt Firmware
Analog Fm Transmitter Exc1000gx FirmwareAnalog Fm Transmitter Exc100gt Firmware+12 more
Jun 17, 2026
Oct 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.
1Palantir
1Tiles
Jun 17, 2026
Oct 26, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all the endpoints.
1Linecorp
1Line
Jun 17, 2026
Oct 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
1Boschrexroth
3Ctrlx Hmi Web Panel Wr2107 Firmware
Ctrlx Hmi Web Panel Wr2110 FirmwareCtrlx Hmi Web Panel Wr2115 Firmware
Jun 17, 2026
Oct 25, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
The vulnerability allows a low privileged user that have access to the device when locked in Kiosk mode to install an arbitrary Android application and leverage it to have access to critical device settings such as the d...Show more
The vulnerability allows a low privileged user that have access to the device when locked in Kiosk mode to install an arbitrary Android application and leverage it to have access to critical device settings such as the device power management or eventually the device secure settings (ADB debug).Show less
1Dromara
1Sa Token
Jun 17, 2026
Oct 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.
1Ui
1Unifi Network Application
Jun 17, 2026
Oct 25, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to d...Show more
Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network. Affected Products: UDM UDM-PRO UDM-SE UDR UDW Mitigation: Update UniFi Network to Version 7.5.187 or later. Show less
1Line
1Kaibutsunosato
Jun 17, 2026
Oct 20, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
1Dlink
2Dsl 2730u Firmware
Dsl 2750u Firmware
Jun 17, 2026
Oct 19, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The UART/Serial interface on the PCB, provides log output and a root terminal without proper access con...Show more
D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The UART/Serial interface on the PCB, provides log output and a root terminal without proper access control.Show less
1Cisco
1Catalyst Sd Wan Manager
Jun 17, 2026
Oct 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This vulnerability is due to improper validation of par...Show more
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This vulnerability is due to improper validation of parameters that are sent to the web UI. An attacker could exploit this vulnerability by logging in to Cisco Catalyst SD-WAN Manager and issuing crafted requests using the web UI. A successful exploit could allow the attacker to obtain arbitrary files from the underlying Linux file system of an affected system. To exploit this vulnerability, the attacker must be an authenticated user.Show less
2Netapp
Oracle
2Mysql Connector/j
Oncommand Insight
Jun 17, 2026
Oct 17, 2023
N/A· v4
8.3 HIGH· v3
N/A· v2
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with n...Show more
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).Show less
1Discourse
1Discourse
Jun 17, 2026
Oct 16, 2023
N/A· v4
3.7 LOW· v3
N/A· v2
Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can use the `/polls/grouped_poll_results` endpoint to view the content of options in the poll and the nu...Show more
Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can use the `/polls/grouped_poll_results` endpoint to view the content of options in the poll and the number of votes for groups of poll participants. This impacts private polls where the results were intended to only be viewable by authorized users. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. There is no workaround for this issue apart from upgrading to the fixed version. Show less
1Extremenetworks
1Exos
Jun 17, 2026
Oct 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain escalated privileges using crafted telnet commands via Redis server.
1Devolutions
1Devolutions Server
Jun 17, 2026
Oct 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.
1Dell
1Emc Openmanage Server Administrator
Jun 17, 2026
Oct 13, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell OpenManage Server Administrator, versions 11.0.0.0 and prior, contains an Improper Access Control vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to execute arbitra...Show more
Dell OpenManage Server Administrator, versions 11.0.0.0 and prior, contains an Improper Access Control vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to execute arbitrary code in order to elevate privileges on the system. Exploitation may lead to a complete system compromise. Show less
1Vantage6
1Vantage6
Jun 17, 2026
Oct 11, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
vantage6 is privacy preserving federated learning infrastructure. The endpoint /api/collaboration/{id}/task is used to collect all tasks from a certain collaboration. To get such tasks, a user should have permission to v...Show more
vantage6 is privacy preserving federated learning infrastructure. The endpoint /api/collaboration/{id}/task is used to collect all tasks from a certain collaboration. To get such tasks, a user should have permission to view the collaboration and to view the tasks in it. However, prior to version 4.0.0, it is only checked if the user has permission to view the collaboration. Version 4.0.0 contains a patch. There are no known workarounds.Show less
1Yifanwireless
1Yf325 Firmware
Jun 17, 2026
Oct 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network re...Show more
A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.Show less
1Yifanwireless
1Yf325 Firmware
Jun 17, 2026
Oct 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network...Show more
An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability.Show less
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Oct 11, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality.