← Back
CWE-284

7,479 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Arris
3Tg1672g Firmware
Tg852g FirmwareTg862g Firmware
Jun 17, 2026
Sep 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame.
1Trendylogics
1Crypto Currency Tracker
Jun 17, 2026
Sep 8, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an Admin account via a crafted POST request.
1Solarwinds
1Serv U
Jun 17, 2026
Sep 7, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to p...Show more
A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 15.4.  SolarWinds found that the issue was not completely fixed in 15.4 Hotfix 1. Show less
1Fortinet
1Fortiswitchmanager
Jun 17, 2026
Sep 7, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API.
1Adobe
1Coldfusion
Jun 17, 2026
Sep 7, 2023
N/A· v4
7.4 HIGH· v3
N/A· v2
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when checking permissions in the CFIDE path. An authenticated attacker could leve...Show more
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when checking permissions in the CFIDE path. An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment. Show less
1Magento
1Magento
Jun 17, 2026
Sep 6, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within Magento's Media Gallery Upload workflow. By storing a specially crafted...Show more
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within Magento's Media Gallery Upload workflow. By storing a specially crafted file in the website gallery, an authenticated attacker with administrative privilege can gain access to delete the .htaccess file. This could result in the attacker achieving remote code execution.Show less
1Openautomationsoftware
1Oas Platform
Jun 17, 2026
Sep 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An...Show more
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An attacker can send a sequence of requests to trigger this vulnerability.Show less
1Usememos
1Memos
Jun 17, 2026
Sep 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.
1Instantcms
1Instantcms
Jun 17, 2026
Aug 31, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
1Yugabyte
1Yugabytedb
Jun 17, 2026
Aug 30, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be seen by noting that it extends Controller rather than AuthenticatedContr...Show more
The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be seen by noting that it extends Controller rather than AuthenticatedController and includes no further checks. This issue affects YugabyteDB Anywhere: from 2.0.0 through 2.17.3 Show less
1Jupyter
1Jupyter Server
Jun 17, 2026
Aug 28, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain file contents, or accessing files when opening untrusted files via "Ope...Show more
jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain file contents, or accessing files when opening untrusted files via "Open image in new tab". This issue has been addressed in commit `87a49272728` which has been included in release `2.7.2`. Users are advised to upgrade. Users unable to upgrade may use the lower performance `--ContentsManager.files_handler_class=jupyter_server.files.handlers.FilesHandler`, which implements the correct checks.Show less
1Byzoro
1Smart S85f Management Platform
Jun 17, 2026
Aug 26, 2023
N/A· v4
6.5 MEDIUM· v3
2.7 LOW· v2
A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230816. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /sysmanage/licence.php. The m...Show more
A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230816. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /sysmanage/licence.php. The manipulation leads to improper access controls. The exploit has been disclosed to the public and may be used. The identifier VDB-238057 was assigned to this vulnerability.Show less
1Openfga
1Openfga
Jun 17, 2026
Aug 25, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. The...Show more
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. The vulnerability affects customers using `ListObjects` with specific models. The affected models contain expressions of type `rel1 from type1`. This issue has been patched in version 1.3.1.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Aug 24, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki supports scheduled jobs that contain Groovy scripts. Currently, the job checks the content author of the job...Show more
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki supports scheduled jobs that contain Groovy scripts. Currently, the job checks the content author of the job for programming right. However, modifying or adding a job script to a document doesn't modify the content author. Together with a CSRF vulnerability in the job scheduler, this can be exploited for remote code execution by an attacker with edit right on the wiki. If the attack is successful, an error log entry with "Job content executed" will be produced. This vulnerability has been patched in XWiki 14.10.9 and 15.4RC1.Show less
1Lenovo
87Ideapad 1 14ijl7 Firmware
Ideapad 1 15ijl7 FirmwareIdeapad 1 14iau7 Firmware+84 more
Jun 17, 2026
Aug 23, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Emb...Show more
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface.Show less
1Cisco
1Application Policy Infrastructure Controller
Jun 17, 2026
Aug 23, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (...Show more
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (for example, access policies) created by users associated with a different security domain on an affected system. This vulnerability is due to improper access control when restricted security domains are used to implement multi-tenancy for policies outside the tenant boundaries. An attacker with a valid user account associated with a restricted security domain could exploit this vulnerability. A successful exploit could allow the attacker to read, modify, or delete policies created by users associated with a different security domain. Exploitation is not possible for policies under tenants that an attacker has no authorization to access.Show less
1Elecom
1Lan W451ngr Firmware
Jun 17, 2026
Aug 18, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
LAN-W451NGR all versions provided by LOGITEC CORPORATION contains an improper access control vulnerability, which allows an unauthenticated attacker to log in to telnet service.
1Acymailing
1Acymailing
Jun 17, 2026
Aug 17, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns.
1Acymailing
1Acymailing
Jun 17, 2026
Aug 17, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized users to create new mailing lists.
1Powerjob
1Powerjob
Jun 17, 2026
Aug 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for querying via appId parameter to /container/list.