CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
4,788 vulnerabilities with CWE-284
CVE-2026-7578
MEDIUM
MacCMS Pro Plugin Installation add.html install unrestricted upload
CVSS 4.7
CVE-2026-2311
MEDIUM
IBM i is affected by a privilege escalation vulnerability in Web Administration GUI []
CVSS 6.4
CVE-2026-40603
MEDIUM
Chartbrew: Incorrect Access Control in /api/project/dashboard/:brewName via same-team override
CVSS 6.5
CVE-2026-40595
HIGH
Chartbrew: Incorrect Access Control in public chart and export routes via missing onReport and SharePolicy checks
CVSS 7.5
CVE-2026-40904
HIGH
Chartbrew: Incorrect Access Control in dataset and dataRequest routes via team-scoped permission checks
CVSS 8.1
CVE-2026-7468
HIGH
1024-lab smart-admin Demo Site index.html access control
CVSS 7.3
CVE-2026-7393
MEDIUM
SourceCodester Pizzafy Ecommerce System File Extension admin_class_novo.php save_menu unrestricted upload
CVSS 4.7
CVE-2026-5141
HIGH
Improper Access Control in TUBITAK BILGEM's Pardus Software Center
CVSS 8.8
CVE-2026-5780
HIGH
Multiple vulnerabilities in MphRx's Minerva
CVE-2026-5779
CRITICAL
Multiple vulnerabilities in MphRx's Minerva
CVE-2026-7238
MEDIUM
code-projects Online Music Site AdminUpdateAlbum.php unrestricted upload
CVSS 4.7
CVE-2026-40966
MEDIUM
VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration
CVSS 5.9
CVE-2026-7134
MEDIUM
code-projects Online Lot Reservation System edithousepic.php unrestricted upload
CVSS 4.7
CVE-2026-7133
MEDIUM
code-projects Online Lot Reservation System activity.php unrestricted upload
CVSS 4.7
CVE-2026-7107
MEDIUM
code-projects Invoice System in Laravel company unrestricted upload
CVSS 6.3
CVE-2026-7044
MEDIUM
GreenCMS index.php themeadd unrestricted upload
CVSS 6.3
CVE-2026-7043
MEDIUM
GreenCMS index.php pluginAddLocal unrestricted upload
CVSS 6.3
CVE-2026-7041
LOW
666ghj MiroFish Werkzeug Debugger PIN console information disclosure
CVSS 3.7
CVE-2026-7021
LOW
SmythOS sre Connector Service utils.ts information disclosure
CVSS 3.5
CVE-2026-33318
HIGH
Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers
CVSS 8.8
CVE-2026-29197
MEDIUM
Rocket.Chat <8.4.0 - Auth Bypass
CVSS 4.3
CVE-2026-24303
CRITICAL
Microsoft Partner Center Elevation of Privilege Vulnerability
CVSS 9.6
CVE-2026-41277
HIGH
Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
CVSS 8.8
CVE-2026-41270
HIGH
Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
CVSS 7.1
CVE-2026-41243
MEDIUM
OpenLearn's pending forum posts remain publicly readable by direct ID when moderation mode is enabled
CVSS 5.4
Details
Vulnerabilities
4,788