CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

4,788 vulnerabilities with CWE-284
CVE-2026-7578 MEDIUM
MacCMS Pro Plugin Installation add.html install unrestricted upload
CVSS 4.7
CVE-2026-2311 MEDIUM
IBM i is affected by a privilege escalation vulnerability in Web Administration GUI []
CVSS 6.4
CVE-2026-40603 MEDIUM
Chartbrew: Incorrect Access Control in /api/project/dashboard/:brewName via same-team override
CVSS 6.5
CVE-2026-40595 HIGH
Chartbrew: Incorrect Access Control in public chart and export routes via missing onReport and SharePolicy checks
CVSS 7.5
CVE-2026-40904 HIGH
Chartbrew: Incorrect Access Control in dataset and dataRequest routes via team-scoped permission checks
CVSS 8.1
CVE-2026-7468 HIGH
1024-lab smart-admin Demo Site index.html access control
CVSS 7.3
CVE-2026-7393 MEDIUM
SourceCodester Pizzafy Ecommerce System File Extension admin_class_novo.php save_menu unrestricted upload
CVSS 4.7
CVE-2026-5141 HIGH
Improper Access Control in TUBITAK BILGEM's Pardus Software Center
CVSS 8.8
CVE-2026-5780 HIGH
Multiple vulnerabilities in MphRx's Minerva
CVE-2026-5779 CRITICAL
Multiple vulnerabilities in MphRx's Minerva
CVE-2026-7238 MEDIUM
code-projects Online Music Site AdminUpdateAlbum.php unrestricted upload
CVSS 4.7
CVE-2026-40966 MEDIUM
VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration
CVSS 5.9
CVE-2026-7134 MEDIUM
code-projects Online Lot Reservation System edithousepic.php unrestricted upload
CVSS 4.7
CVE-2026-7133 MEDIUM
code-projects Online Lot Reservation System activity.php unrestricted upload
CVSS 4.7
CVE-2026-7107 MEDIUM
code-projects Invoice System in Laravel company unrestricted upload
CVSS 6.3
CVE-2026-7044 MEDIUM
GreenCMS index.php themeadd unrestricted upload
CVSS 6.3
CVE-2026-7043 MEDIUM
GreenCMS index.php pluginAddLocal unrestricted upload
CVSS 6.3
CVE-2026-7041 LOW
666ghj MiroFish Werkzeug Debugger PIN console information disclosure
CVSS 3.7
CVE-2026-7021 LOW
SmythOS sre Connector Service utils.ts information disclosure
CVSS 3.5
CVE-2026-33318 HIGH
Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers
CVSS 8.8
CVE-2026-29197 MEDIUM
Rocket.Chat <8.4.0 - Auth Bypass
CVSS 4.3
CVE-2026-24303 CRITICAL
Microsoft Partner Center Elevation of Privilege Vulnerability
CVSS 9.6
CVE-2026-41277 HIGH
Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
CVSS 8.8
CVE-2026-41270 HIGH
Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
CVSS 7.1
CVE-2026-41243 MEDIUM
OpenLearn's pending forum posts remain publicly readable by direct ID when moderation mode is enabled
CVSS 5.4
Details
Vulnerabilities 4,788