← Back
CWE-284

7,464 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,464)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
1Climatix Pol909 Firmware
Jun 17, 2026
Mar 8, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices cont...Show more
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices contains an information disclosure vulnerability which could allow logged in users to access sensitive files.Show less
1Jfrog
1Artifactory
Jun 17, 2026
Mar 2, 2022
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.
1Jfrog
1Artifactory
Jun 17, 2026
Mar 2, 2022
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in t...Show more
JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.Show less
1Webmin
1Webmin
Jun 17, 2026
Mar 2, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.
1Orange Form Project
1Orange Form
Jun 17, 2026
Feb 28, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls, for example the or_delete_filed one which is available to both unauthenticated and authenticated us...Show more
The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls, for example the or_delete_filed one which is available to both unauthenticated and authenticated users could allow attackers to delete arbitrary posts.The AJAX calls performing actions on posts also do not ensure that the post belong to them (or that they are allowed to perform such action on it)Show less
1Zulip
1Zulip
Jun 17, 2026
Feb 26, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper Access Control in GitHub repository zulip/zulip prior to 4.10.
1Zulip
1Zulip Server
Jun 17, 2026
Feb 26, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which h...Show more
Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organizations is vulnerable to an attack where an invitation created in one organization (potentially as a role with elevated permissions) can be used to join any other organization. This bypasses any restrictions on required domains on users' email addresses, may be used to gain access to organizations which are only accessible by invitation, and may be used to gain access with elevated privileges. This issue has been patched in release 4.10. There are no known workarounds for this issue. ### Patches _Has the problem been patched? What versions should users upgrade to?_ ### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ ### References _Are there any links users can visit to find out more?_ ### For more information If you have any questions or comments about this advisory, you can discuss them on the [developer community Zulip server](https://zulip.com/developer-community/), or email the [Zulip security team](mailto:security@zulip.com).Show less
1Rockwellautomation
21734 Aentr Point I/o Dual Port Network Adaptor Series B Firmware
1734 Aentr Point I/o Dual Port Network Adaptor Series C Firmware
Jun 17, 2026
Feb 24, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can send a crafted request that may allow for modification of the configuratio...Show more
The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can send a crafted request that may allow for modification of the configuration settings.Show less
11byte
9Copy9
ExactspyFonetracker+6 more
Jun 17, 2026
Feb 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Feb 23, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
1Framasoft
1Peertube
Jun 17, 2026
Feb 23, 2022
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.
1Quadlayers
1Perfect Brands For Woocommerce
Jun 17, 2026
Feb 18, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The vulnerability allows Subscriber+ level users to create brands in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4).
1Forgerock
1Access Management
Jun 17, 2026
Feb 14, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects...Show more
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all previous versions.Show less
1Samsung
1Livewallpaperservice
Jun 17, 2026
Feb 11, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a proper permission.
1Samsung
1Searchwidget
Jun 17, 2026
Feb 11, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Improper access control vulnerability in Samsung SearchWidget prior to versions 2.3.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview.
1Samsung
1Wear Os
Jun 17, 2026
Feb 11, 2022
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Unprotected component vulnerability in StTheaterModeDurationAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to disable theater mode without a proper permission.
1Samsung
1Wear Os
Jun 17, 2026
Feb 11, 2022
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to enable bedtime mode without a proper permission.
1Samsung
1Wear Os
Jun 17, 2026
Feb 11, 2022
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.
1Samsung
1Wear Os
Jun 17, 2026
Feb 11, 2022
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
An Improper access control vulnerability in StBedtimeModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.
1Samsung
1Reminder
Jun 17, 2026
Feb 11, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Improper access control vulnerability in Reminder prior to versions 12.3.01.3000 in Android S(12), 12.2.05.6000 in Android R(11) and 11.6.08.6000 in Andoid Q(10) allows attackers to register reminders or execute exporete...Show more
Improper access control vulnerability in Reminder prior to versions 12.3.01.3000 in Android S(12), 12.2.05.6000 in Android R(11) and 11.6.08.6000 in Andoid Q(10) allows attackers to register reminders or execute exporeted activities remotely.Show less