CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,080 vulnerabilities with CWE-284
CVE-2026-34291
HIGH
Oracle HTTP Server 12.2.1.4.0 - Privilege Escalation
CVSS 8.7
CVE-2026-34287
CRITICAL
Oracle Identity Manager Connector 12.2.1.4.0 - Unauthenticated Data Manipulation
CVSS 9.1
CVE-2026-34284
MEDIUM
Oracle BPM Suite 12.2.1.4.0 and 14.1.2.0.0 - Unauthorized Data Access
CVSS 6.1
CVE-2026-34283
MEDIUM
Oracle Identity Manager 12.2.1.4.0 and 14.1.2.0.0 - Unauthorized Data Access
CVSS 6.1
CVE-2026-34277
MEDIUM
PeopleSoft Enterprise PeopleTools 8.61-8.62 - Authenticated Improper Access Control in Fluid Core
CVSS 6.6
CVE-2026-34274
MEDIUM
Oracle Configurator 12.2.3-12.2.15 - Unauthorized Data Access
CVSS 6.1
CVE-2026-34269
MEDIUM
Oracle PeopleSoft PeopleTools 8.61-8.62 Portal - Unauthorized Data Access
CVSS 6.1
CVE-2026-22019
MEDIUM
Oracle PeopleSoft HCM Shared Components 9.2 - Unauthorized Data Access
CVSS 5.4
CVE-2026-22014
LOW
Oracle User Management 12.2.7-12.2.15 - Privilege Escalation
CVSS 3.8
CVE-2026-22011
HIGH
Oracle Applications DBA 12.2.3-12.2.15 - Privilege Escalation
CVSS 7.6
CVE-2026-22010
HIGH
Oracle Financial Services Analytical Applications Infrastructure 8.0.7.9 - Info Disclosure
CVSS 7.5
CVE-2026-21997
HIGH
Oracle Life Sciences Empirica Signal 9.2.1-9.2.3 - Unauthorized Data Modification
CVSS 8.5
CVE-2026-40889
MEDIUM
Frappe HR has Improper Access Control on Files
CVSS 6.5
CVE-2026-40888
MEDIUM
Frappe HR vulnerable to Improper Access Control
CVSS 6.5
CVE-2026-40874
MEDIUM
mailcow: dockerized missing authorization on Forwarding Hosts delete action
CVE-2026-40867
HIGH
Horilla: Unauthorized Helpdesk Attachment Access via Attachment ID Manipulation
CVE-2026-40866
HIGH
Horilla: Unauthorized Document Overwrite via File Upload Endpoint
CVE-2026-40865
HIGH
Horilla: Insecure Direct Object Reference at `/employee/view-file/<int:id>
CVE-2026-40569
CRITICAL
FreeScout's Mass Assignment in Mailbox Connection Settings Enables Silent Email Exfiltration
CVSS 9.0
CVE-2026-30452
MEDIUM
Textpattern CMS 4.9.0 - Privilege Escalation
CVSS 6.5
CVE-2026-40498
CRITICAL
FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron
CVSS 9.8
CVE-2026-31018
HIGH
Dolibarr ERP & CRM <=22.0.4 - Code Injection
CVSS 8.8
CVE-2026-29644
MEDIUM
XiangShan - Improper Access Control via Distributed CSR Write-Enable Path
CVSS 5.3
CVE-2026-39386
HIGH
Neko has Self-service Privilege Escalation for Authenticated Users
CVSS 8.8
CVE-2026-35570
HIGH
OpenClaude has Sandbox Bypass via Early-Exit Logic Flaw that Allows Path Traversal
CVSS 8.4
Details
Vulnerabilities
5,080