CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,080 vulnerabilities with CWE-284
CVE-2026-34291 HIGH
Oracle HTTP Server 12.2.1.4.0 - Privilege Escalation
CVSS 8.7
CVE-2026-34287 CRITICAL
Oracle Identity Manager Connector 12.2.1.4.0 - Unauthenticated Data Manipulation
CVSS 9.1
CVE-2026-34284 MEDIUM
Oracle BPM Suite 12.2.1.4.0 and 14.1.2.0.0 - Unauthorized Data Access
CVSS 6.1
CVE-2026-34283 MEDIUM
Oracle Identity Manager 12.2.1.4.0 and 14.1.2.0.0 - Unauthorized Data Access
CVSS 6.1
CVE-2026-34277 MEDIUM
PeopleSoft Enterprise PeopleTools 8.61-8.62 - Authenticated Improper Access Control in Fluid Core
CVSS 6.6
CVE-2026-34274 MEDIUM
Oracle Configurator 12.2.3-12.2.15 - Unauthorized Data Access
CVSS 6.1
CVE-2026-34269 MEDIUM
Oracle PeopleSoft PeopleTools 8.61-8.62 Portal - Unauthorized Data Access
CVSS 6.1
CVE-2026-22019 MEDIUM
Oracle PeopleSoft HCM Shared Components 9.2 - Unauthorized Data Access
CVSS 5.4
CVE-2026-22014 LOW
Oracle User Management 12.2.7-12.2.15 - Privilege Escalation
CVSS 3.8
CVE-2026-22011 HIGH
Oracle Applications DBA 12.2.3-12.2.15 - Privilege Escalation
CVSS 7.6
CVE-2026-22010 HIGH
Oracle Financial Services Analytical Applications Infrastructure 8.0.7.9 - Info Disclosure
CVSS 7.5
CVE-2026-21997 HIGH
Oracle Life Sciences Empirica Signal 9.2.1-9.2.3 - Unauthorized Data Modification
CVSS 8.5
CVE-2026-40889 MEDIUM
Frappe HR has Improper Access Control on Files
CVSS 6.5
CVE-2026-40888 MEDIUM
Frappe HR vulnerable to Improper Access Control
CVSS 6.5
CVE-2026-40874 MEDIUM
mailcow: dockerized missing authorization on Forwarding Hosts delete action
CVE-2026-40867 HIGH
Horilla: Unauthorized Helpdesk Attachment Access via Attachment ID Manipulation
CVE-2026-40866 HIGH
Horilla: Unauthorized Document Overwrite via File Upload Endpoint
CVE-2026-40865 HIGH
Horilla: Insecure Direct Object Reference at `/employee/view-file/<int:id>
CVE-2026-40569 CRITICAL
FreeScout's Mass Assignment in Mailbox Connection Settings Enables Silent Email Exfiltration
CVSS 9.0
CVE-2026-30452 MEDIUM
Textpattern CMS 4.9.0 - Privilege Escalation
CVSS 6.5
CVE-2026-40498 CRITICAL
FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron
CVSS 9.8
CVE-2026-31018 HIGH
Dolibarr ERP & CRM <=22.0.4 - Code Injection
CVSS 8.8
CVE-2026-29644 MEDIUM
XiangShan - Improper Access Control via Distributed CSR Write-Enable Path
CVSS 5.3
CVE-2026-39386 HIGH
Neko has Self-service Privilege Escalation for Authenticated Users
CVSS 8.8
CVE-2026-35570 HIGH
OpenClaude has Sandbox Bypass via Early-Exit Logic Flaw that Allows Path Traversal
CVSS 8.4
Details
Vulnerabilities 5,080