CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,223 vulnerabilities with CWE-284
CVE-2026-58039 LOW
Node - Improper Access Control
CVSS 3.3
CVE-2026-62246 HIGH
Kamaji: TenantControlPlane namespace/name collision binds two tenants to the same SQL datastore schema + DB user, breaking per-tenant isolation
CVSS 8.5
CVE-2026-66803 CRITICAL
Azure Cosmos DB Remote Code Execution Vulnerability
CVSS 10.0
CVE-2026-58043 HIGH
Node - Improper Access Control
CVSS 7.5
CVE-2026-15250 MEDIUM
LatePoint < 5.6.8 - Unauthenticated Booking Object Mass Assignment via Public Booking Funnel
CVSS 5.3
CVE-2026-14222 LOW
Easy Appointments <= 3.12.26 - Contributor+ Connection Deletion via Missing Authorization
CVSS 3.8
CVE-2026-14221 LOW
Easy Appointments <= 3.12.26 - Contributor+ Appointment Data Disclosure & Modification via Missing Authorization
CVSS 3.8
CVE-2026-11782 MEDIUM
Points and Rewards for WooCommerce < 2.10.1 - Unauthenticated Wallet and Points Tampering
CVSS 5.9
CVE-2026-18004 MEDIUM
Google Chrome < 151.0.7922.72 - Cross-Origin Data Leak via Speech Policy Enforcement
CVSS 4.3
CVE-2026-17996 MEDIUM
Google Chrome < 151.0.7922.72 - Navigation Restriction Bypass via Malicious File on macOS
CVSS 6.2
CVE-2026-17994 MEDIUM
Google Chrome on Android < 151.0.7922.72 - Navigation Restriction Bypass via Media Implementation
CVSS 4.3
CVE-2026-17986 MEDIUM
Google Chrome < 151.0.7922.72 - Same Origin Policy Bypass via Bluetooth Policy Enforcement
CVSS 6.5
CVE-2026-17976 MEDIUM
Google Chrome < 151.0.7922.72 - Extension Policy Bypass via Crafted Domain Name
CVSS 4.3
CVE-2026-17961 MEDIUM
Google Chrome < 151.0.7922.72 - Navigation Restriction Bypass via Crafted HTML Page in Session Implementation
CVSS 4.3
CVE-2026-17944 MEDIUM
Google Chrome for iOS < 151.0.7922.72 - Security Restriction Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-17917 MEDIUM
Google Chrome for iOS < 151.0.7922.72 - Security Policy Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-17781 MEDIUM
Google Chrome < 151.0.7922.72 - Cross-Origin Data Leak via Malicious Extension
CVSS 4.3
CVE-2026-67431 HIGH
MCP Ruby SDK: Ruby SSE Session Poisoning
CVE-2026-65888 CRITICAL
Joomla Gridbox < 2.20.2 - Account Takeover via socialLogin
CVE-2026-65887 CRITICAL
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2
CVE-2026-65889 CRITICAL
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < 2.20.2
CVE-2026-65943 HIGH
Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0
CVSS 7.5
CVE-2026-65884 CRITICAL
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2
CVE-2026-41920 CRITICAL
Apache Traffic Server: SNI to Host header matching policy is not properly enforced
CVSS 9.3
CVE-2026-63236 LOW
Three Learning Koollab LMS 5.3.2 - Unauthenticated SCORM Data Exposure
CVSS 3.7
Details
Vulnerabilities 6,223