CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,075 vulnerabilities with CWE-284
CVE-2026-42205 HIGH
Avo: Broken Access Control: Unauthorized Execution of Arbitrary Action Classes Across Resources
CVSS 8.8
CVE-2026-41487 MEDIUM
Langfuse: Improper role-based-access control in Langfuse LLM connection management allowed users of role “member” to retrieve stored LLM provider API keys
CVSS 5.4
CVE-2026-41491 HIGH
Dapr: Service Invocation path traversal ACL bypass
CVSS 8.1
CVE-2026-8069 HIGH
PredatorSense V3: Local Privilege Escalation (LPE) vulnerability
CVE-2026-42278 HIGH
UltraDAG: Smart Account Spending Policy Bypass via Pockets
CVE-2026-41900 HIGH
OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment
CVSS 8.8
CVE-2026-41646 MEDIUM
Nuclei: Local File Read via require() Module Loader Bypass
CVSS 5.5
CVE-2026-8127 MEDIUM
eladmin Users API Endpoint UserController.java checkLevel access control
CVSS 6.3
CVE-2026-35435 HIGH
Azure AI Foundry Elevation of Privilege Vulnerability
CVSS 8.6
CVE-2026-33109 CRITICAL
Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
CVSS 9.9
CVE-2026-37709 CRITICAL
snipe-it < 8.4.1 - Remote Code Execution via UploadedFilesController
CVSS 9.8
CVE-2026-5788 HIGH
Ivanti Endpoint Manager Mobile < 12.6.1.1, < 12.7.0.1, < 12.8.0.1 - Unauthenticated Arbitrary Method Invocation
CVSS 7.0
CVE-2026-5786 HIGH
Ivanti Endpoint Manager Mobile < 12.6.1.1, < 12.7.0.1, < 12.8.0.1 - Authenticated Privilege Escalation
CVSS 8.8
CVE-2026-41641 HIGH
NocoBase Vulnerable to SQL Validation Bypass via `sqlCollection:update` Missing `checkSQL` Call
CVSS 7.2
CVE-2026-8033 MEDIUM
PicoTronica e-Clinic Healthcare System ECHS Response Header v2 information disclosure
CVSS 5.3
CVE-2026-7959 LOW
Google Chrome - Site Isolation Bypass
CVSS 3.1
CVE-2026-20167 HIGH
Cisco IoT Field Network Director Remote Device Denial of Service Vulnerability
CVSS 7.7
CVE-2026-8028 LOW
FlowiseAI Flowise Endpoint account.service.ts verify information disclosure
CVSS 3.7
CVE-2026-8026 LOW
FlowiseAI Flowise API Response account.service.ts login information disclosure
CVSS 3.7
CVE-2026-42222 HIGH
nginx-ui: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover
CVSS 8.1
CVE-2026-42812 CRITICAL
Apache Polaris: No protection on `write.metadata.path`
CVSS 9.9
CVE-2026-7733 HIGH
funadmin Frontend Chunked Upload Endpoint UploadService.php chunkUpload unrestricted upload
CVSS 7.3
CVE-2026-7732 MEDIUM
code-projects BloodBank Managing System request_blood.php unrestricted upload
CVSS 6.3
CVE-2026-7711 HIGH
MindsDB Engine proc_wrapper.py exec unrestricted upload
CVSS 7.3
CVE-2026-7696 MEDIUM
Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform uploadH5Files unrestricted upload
CVSS 6.3
Details
Vulnerabilities 5,075