← Back
CWE-284

7,464 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,464)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Macos
Jun 17, 2026
Sep 23, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to capture a user’s screen.
1Apple
2Mac Os X
Macos
Jun 17, 2026
Sep 23, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to modify protected parts of the file system.
1Apple
1Macos
Jun 17, 2026
Sep 23, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5. An app may be able to bypass Privacy preferences.
1Apple
1Macos
Jun 17, 2026
Sep 23, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. An app may gain unauthorized access to Bluetooth.
1Rocketchat
1Rocket.chat
Jun 17, 2026
Sep 23, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An improper access control vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 due to input data in the getUsersOfRoom Meteor server method is not type validated, so that MongoDB query operator objects are accep...Show more
An improper access control vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 due to input data in the getUsersOfRoom Meteor server method is not type validated, so that MongoDB query operator objects are accepted by the server, so that instead of a matching rid String a$regex query can be executed, bypassing the room access permission check for every but the first matching room.Show less
1Evohclaimable Project
1Evohclaimable
Jun 17, 2026
Sep 21, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Access control vulnerability in Evoh NFT EvohClaimable contract with sha256 hash code fa2084d5abca91a62ed1d2f1cad3ec318e6a9a2d7f1510a00d898737b05f48ae allows remote attackers to execute fraudulent NFT transfers.
1Jenkins
1Wildfly Deployer
Jun 17, 2026
Sep 21, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system.
1Apple
4Ipados
Iphone OsMacos+1 more
Jun 17, 2026
Sep 20, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to read sensitive location information.
1Apple
1Macos
Jun 17, 2026
Sep 20, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.5. An app may be able to access user-sensitive data.
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Sep 20, 2022
N/A· v4
2.4 LOW· v3
N/A· v2
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. A person with physical access to an iOS device may be able to access photos from the lock screen.
1Forgerock
1Ldap Connector
Jun 17, 2026
Sep 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Manage...Show more
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)Show less
1Kubernetes
1Cri O
Jun 17, 2026
Sep 19, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where s...Show more
Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.Show less
1Neoinfosys
1Nis Hap11ac Firmware
Jun 17, 2026
Sep 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use this vulnerability to induce all attacks such as source code hijacking, remote control of the device.
1Zoom
1Zoom On Premise Meeting Connector Mmr
Jun 17, 2026
Sep 16, 2022
N/A· v4
8.2 HIGH· v3
N/A· v2
Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not aut...Show more
Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.Show less
1Devolutions
1Remote Desktop Manager
Jun 17, 2026
Sep 13, 2022
N/A· v4
7.0 HIGH· v3
N/A· v2
Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackers to bypass the application lock. This issue affects: Devolutions Remote Desktop...Show more
Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackers to bypass the application lock. This issue affects: Devolutions Remote Desktop Manager version 2022.2.14 and prior versions.Show less
1Contechealth
1Cms8000 Firmware
Jun 17, 2026
Sep 13, 2022
N/A· v4
5.7 MEDIUM· v3
N/A· v2
The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malicious name, including non-standard characters that, when the device attem...Show more
The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malicious name, including non-standard characters that, when the device attempts connecting to the malicious SSID, the device can be exploited to write arbitrary files or display incorrect information.Show less
1Contechealth
1Cms8000 Firmware
Jun 17, 2026
Sep 13, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to device functionality. No authentication or controls are in place to pr...Show more
A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to device functionality. No authentication or controls are in place to prevent a threat actor from maliciously modifying firmware and performing a drive-by attack to load the firmware on any CMS8000 device.Show less
1Siemens
1Coreshield One Way Gateway
Jun 17, 2026
Sep 13, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file permissions that could allow a local attacker to escalate privileges to...Show more
A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file permissions that could allow a local attacker to escalate privileges to local administrator.Show less
1Samsung
1Galaxy Watch Plugin
Jun 17, 2026
Sep 9, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the file without permission.
1Samsung
1Contacts Provider
Jun 17, 2026
Sep 9, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Improper access control vulnerability in ContactsDumpActivity of?Contacts Provider prior to version 12.7.59 allows attacker to access the file without permission.