CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,075 vulnerabilities with CWE-284
CVE-2026-42205
HIGH
Avo: Broken Access Control: Unauthorized Execution of Arbitrary Action Classes Across Resources
CVSS 8.8
CVE-2026-41487
MEDIUM
Langfuse: Improper role-based-access control in Langfuse LLM connection management allowed users of role “member” to retrieve stored LLM provider API keys
CVSS 5.4
CVE-2026-41491
HIGH
Dapr: Service Invocation path traversal ACL bypass
CVSS 8.1
CVE-2026-8069
HIGH
PredatorSense V3: Local Privilege Escalation (LPE) vulnerability
CVE-2026-42278
HIGH
UltraDAG: Smart Account Spending Policy Bypass via Pockets
CVE-2026-41900
HIGH
OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment
CVSS 8.8
CVE-2026-41646
MEDIUM
Nuclei: Local File Read via require() Module Loader Bypass
CVSS 5.5
CVE-2026-8127
MEDIUM
eladmin Users API Endpoint UserController.java checkLevel access control
CVSS 6.3
CVE-2026-35435
HIGH
Azure AI Foundry Elevation of Privilege Vulnerability
CVSS 8.6
CVE-2026-33109
CRITICAL
Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
CVSS 9.9
CVE-2026-37709
CRITICAL
snipe-it < 8.4.1 - Remote Code Execution via UploadedFilesController
CVSS 9.8
CVE-2026-5788
HIGH
Ivanti Endpoint Manager Mobile < 12.6.1.1, < 12.7.0.1, < 12.8.0.1 - Unauthenticated Arbitrary Method Invocation
CVSS 7.0
CVE-2026-5786
HIGH
Ivanti Endpoint Manager Mobile < 12.6.1.1, < 12.7.0.1, < 12.8.0.1 - Authenticated Privilege Escalation
CVSS 8.8
CVE-2026-41641
HIGH
NocoBase Vulnerable to SQL Validation Bypass via `sqlCollection:update` Missing `checkSQL` Call
CVSS 7.2
CVE-2026-8033
MEDIUM
PicoTronica e-Clinic Healthcare System ECHS Response Header v2 information disclosure
CVSS 5.3
CVE-2026-7959
LOW
Google Chrome - Site Isolation Bypass
CVSS 3.1
CVE-2026-20167
HIGH
Cisco IoT Field Network Director Remote Device Denial of Service Vulnerability
CVSS 7.7
CVE-2026-8028
LOW
FlowiseAI Flowise Endpoint account.service.ts verify information disclosure
CVSS 3.7
CVE-2026-8026
LOW
FlowiseAI Flowise API Response account.service.ts login information disclosure
CVSS 3.7
CVE-2026-42222
HIGH
nginx-ui: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover
CVSS 8.1
CVE-2026-42812
CRITICAL
Apache Polaris: No protection on `write.metadata.path`
CVSS 9.9
CVE-2026-7733
HIGH
funadmin Frontend Chunked Upload Endpoint UploadService.php chunkUpload unrestricted upload
CVSS 7.3
CVE-2026-7732
MEDIUM
code-projects BloodBank Managing System request_blood.php unrestricted upload
CVSS 6.3
CVE-2026-7711
HIGH
MindsDB Engine proc_wrapper.py exec unrestricted upload
CVSS 7.3
CVE-2026-7696
MEDIUM
Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform uploadH5Files unrestricted upload
CVSS 6.3
Details
Vulnerabilities
5,075