← Back
CWE-284

7,477 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,477)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sick
1Icr890 4 Firmware
Jun 17, 2026
Jul 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP address based on missing access contr...Show more
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP address based on missing access control.Show less
1Sick
1Icr890 4 Firmware
Jun 17, 2026
Jul 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.
1Glpi Project
1Glpi
Jun 17, 2026
Jul 5, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Ver...Show more
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contains a patch for this issue.Show less
1Glpi Project
1Glpi
Jun 17, 2026
Jul 5, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a on a file accessible by an authenticated user (or not for certain actions), a...Show more
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a on a file accessible by an authenticated user (or not for certain actions), allows a threat actor to interact, modify, or see Dashboard data. Version 10.0.8 contains a patch for this issue.Show less
1Glpi Project
1Glpi
Jun 17, 2026
Jul 5, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user, allows access t...Show more
GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user, allows access to the view all KnowbaseItems. Version 10.0.8 has a patch for this issue.Show less
1Glpi Project
1Glpi
Jun 17, 2026
Jul 5, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user. This allows acce...Show more
GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user. This allows access to the list of all users and their personal information. Users should upgrade to version 10.0.8 to receive a patch.Show less
1Samsung
1Searchwidget
Jun 17, 2026
Jun 28, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity.
2Fedoraproject
Plantuml
2Fedora
Plantuml
Jun 17, 2026
Jun 27, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Jun 23, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise...Show more
NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.0.0 until 21.0.9.12, 22.0.0 until 22.2.10.12, 23.0.0 until 23.0.12.7, 24.0.0 until 24.0.12.2, 25.0.0 until 25.0.7, and 26.0.0 until 26.0.2, when two server are registered as trusted servers for each other and successfully exchanged the share secrets, the malicious server could modify or delete VCards in the system addressbook on the origin server. This would impact the available and shown information in certain places, such as the user search and avatar menu. If a manipulated user modifies their own data in the personal settings the entry is fixed again. Nextcloud Server n 25.0.7 and 26.0.2 and Nextcloud Enterprise Server 21.0.9.12, 22.2.10.12, 23.0.12.7, 24.0.12.2, 25.0.7, and 26.0.2 contain a patch for this issue. A workaround is available. Remove all trusted servers in the "Administration" > "Sharing" settings `…/index.php/settings/admin/sharing`. Afterwards, trigger a recreation of the local system addressbook with the following `occ dav:sync-system-addressbook`.Show less
1Nextcloud
1End To End Encryption
Jun 17, 2026
Jun 23, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessibl...Show more
Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommended that the Nextcloud End-to-end encryption app is upgraded to version 1.12.4 that contains the fix. Show less
1Remult
1Remult
Jun 17, 2026
Jun 23, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Remult is a CRUD framework for full-stack TypeScript. If you used the apiPrefilter option of the `@Entity` decorator, by setting it to a function that returns a filter that prevents unauthorized access to data, an attack...Show more
Remult is a CRUD framework for full-stack TypeScript. If you used the apiPrefilter option of the `@Entity` decorator, by setting it to a function that returns a filter that prevents unauthorized access to data, an attacker who knows the `id` of an entity instance is not authorized to access, can gain read, update and delete access to it. The issue is fixed in version 0.20.6. As a workaround, set the `apiPrefilter` option to a filter object instead of a function.Show less
1Admidio
1Admidio
Jun 17, 2026
Jun 23, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.
1Admidio
1Admidio
Jun 17, 2026
Jun 23, 2023
N/A· v4
3.5 LOW· v3
N/A· v2
Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.
1Cloudflare
1Warp
Jun 17, 2026
Jun 20, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Cloudflare WARP client for Windows (up to v2023.3.381.0) allowed a malicious actor to remotely access the warp-svc.exe binary due to an insufficient access control policy on an IPC Named Pipe. This would have enabled an...Show more
Cloudflare WARP client for Windows (up to v2023.3.381.0) allowed a malicious actor to remotely access the warp-svc.exe binary due to an insufficient access control policy on an IPC Named Pipe. This would have enabled an attacker to trigger WARP connect and disconnect commands, as well as obtaining network diagnostics and application configuration from the target's device. It is important to note that in order to exploit this, a set of requirements would need to be met, such as the target's device must've been reachable on port 445, allowed authentication with NULL sessions or otherwise having knowledge of the target's credentials. Show less
1Ruijie
1Rg Ew1200g Firmware
Jun 17, 2026
Jun 18, 2023
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in Ruijie RG-EW1200G EW_3.0(1)B11P204. It has been declared as critical. This vulnerability affects unknown code of the file app.09df2a9e44ab48766f5f.js of the component Admin Password Handler....Show more
A vulnerability was found in Ruijie RG-EW1200G EW_3.0(1)B11P204. It has been declared as critical. This vulnerability affects unknown code of the file app.09df2a9e44ab48766f5f.js of the component Admin Password Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-231802 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Cdatatec
1Web Management System
Jun 17, 2026
Jun 18, 2023
N/A· v4
7.5 HIGH· v3
7.5 HIGH· v2
A vulnerability was found in C-DATA Web Management System up to 20230607. It has been classified as critical. This affects an unknown part of the file /cgi-bin/jumpto.php?class=user&page=config_save&isphp=1 of the compon...Show more
A vulnerability was found in C-DATA Web Management System up to 20230607. It has been classified as critical. This affects an unknown part of the file /cgi-bin/jumpto.php?class=user&page=config_save&isphp=1 of the component User Creation Handler. The manipulation of the argument user/newpassword leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-231801 was assigned to this vulnerability.Show less
1Hikvision
37Ds K1t320efwx Firmware
Ds K1t320efx FirmwareDs K1t320ewx Firmware+34 more
Jun 17, 2026
Jun 15, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Some access control/intercom products have unauthorized modification of device network configuration vulnerabilities. Attackers can modify device network configuration by sending specific data packets to the vulnerable i...Show more
Some access control/intercom products have unauthorized modification of device network configuration vulnerabilities. Attackers can modify device network configuration by sending specific data packets to the vulnerable interface within the same local network.Show less
1Hikvision
26Ds K1t320efwx Firmware
Ds K1t320efx FirmwareDs K1t320ewx Firmware+23 more
Jun 17, 2026
Jun 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the...Show more
Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the same time as a valid user logs in, and gain device operation permissions by forging the IP and session ID of an authenticated user.Show less
1Microsoft
9Windows 10 1607
Windows 10 1809Windows 10 21h2+6 more
Jun 17, 2026
Jun 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Windows Collaborative Translation Framework Elevation of Privilege Vulnerability
1Arista
1Cloudvision Portal
Jun 17, 2026
Jun 13, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry a...Show more
On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision Portal product when run on-premise. It does not impact CloudVision as-a-Service.Show less