CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,075 vulnerabilities with CWE-284
CVE-2026-41277 HIGH
Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
CVSS 8.8
CVE-2026-41270 HIGH
Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
CVSS 7.1
CVE-2026-41243 MEDIUM
OpenLearn's pending forum posts remain publicly readable by direct ID when moderation mode is enabled
CVSS 5.4
CVE-2026-41166 HIGH
OpenRemote has Improper Access Control via updateUserRealmRoles function
CVSS 7.0
CVE-2026-31192 MEDIUM
Raindrop.io Bookmark Manager Web App 5.6.76.0 - Info Disclosure
CVSS 6.5
CVE-2026-22754 HIGH
ervlet Path Not Correctly Included in Path Matching of XML Authorization Rules
CVSS 7.5
CVE-2026-35252 MEDIUM
Oracle Security Service 12.2.1.4.0 - Privilege Escalation
CVSS 6.4
CVE-2026-35251 HIGH
Oracle VM VirtualBox 7.2.6 - Privilege Escalation
CVSS 7.5
CVE-2026-35250 LOW
Oracle VM VirtualBox 7.2.6 - Authenticated Partial Denial of Service
CVSS 2.3
CVE-2026-35249 LOW
Oracle VM VirtualBox 7.2.6 - Privilege Escalation
CVSS 3.2
CVE-2026-35248 MEDIUM
Oracle VM VirtualBox 7.2.6 - Authenticated Unauthorized Data Access and Partial Denial of Service
CVSS 5.0
CVE-2026-35247 MEDIUM
Oracle VM VirtualBox 7.2.6 - Privilege Escalation
CVSS 6.0
CVE-2026-35246 HIGH
Oracle VM VirtualBox 7.2.6 - Privilege Escalation
CVSS 7.5
CVE-2026-35245 HIGH
Oracle VM VirtualBox 7.2.6 - Unauthenticated Denial of Service via RDP
CVSS 7.5
CVE-2026-35244 MEDIUM
Oracle Hyperion Infrastructure Technology 11.2.24.0.000 - Privilege Escalation
CVSS 5.2
CVE-2026-35243 HIGH
Oracle ADF 12.2.1.4.0 - Privilege Escalation
CVSS 7.8
CVE-2026-35242 HIGH
Oracle VM VirtualBox 7.2.6 - Privilege Escalation
CVSS 7.5
CVE-2026-35241 MEDIUM
Oracle PeopleSoft Enterprise CS Student Records 9.2 - Info Disclosure
CVSS 5.7
CVE-2026-35240 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Authenticated Denial of Service in Server Optimizer
CVSS 4.9
CVE-2026-35239 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Authenticated Denial of Service in Server: DML
CVSS 4.9
CVE-2026-35238 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2026-35237 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2026-35236 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2026-35235 MEDIUM
MySQL Server 9.0.0-9.6.0 - Authenticated Denial of Service in GIS Component
CVSS 4.9
CVE-2026-35234 MEDIUM
MySQL Server 9.0.0-9.6.0 - Authenticated Denial of Service in Server Partition Component
CVSS 4.9
Details
Vulnerabilities 5,075