CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,223 vulnerabilities with CWE-284
CVE-2026-63235 LOW
Three Learning Koollab Lms < 5.3.2 - Denial of Service
CVSS 3.7
CVE-2026-64863 CRITICAL
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
CVSS 9.1
CVE-2026-7362 MEDIUM
IBM Sterling B2B Integrator and File Gateway - Authenticated Information Disclosure
CVSS 4.3
CVE-2026-62427 HIGH
sysctl and platform-op locks open to abuse
CVSS 8.8
CVE-2026-18038 MEDIUM
nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosure
CVSS 4.3
CVE-2026-14926 MEDIUM
FluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering
CVSS 4.2
CVE-2026-64738 CRITICAL
macOS < 14.8.8 / < 15.7.8 / < 26.6 - Sandbox Escape via Permissions Issue
CVSS 9.8
CVE-2026-64737 HIGH
macOS < 14.8.8, < 15.7.8, < 26.6 - Sandbox Escape
CVSS 8.2
CVE-2026-64732 MEDIUM
Apple Ios And iPadOS < 26.6 - Denial of Service
CVSS 4.6
CVE-2026-64723 MEDIUM
macOS < 14.8.8, < 15.7.8, < 26.6 - Sensitive User Data Exposure
CVSS 5.5
CVE-2026-64702 CRITICAL
macOS < 14.8.8, < 15.7.8, < 26.6 - Sandbox Escape via Insufficient Restrictions
CVSS 9.8
CVE-2026-43821 MEDIUM
Apple Safari - Denial of Service
CVSS 6.5
CVE-2026-43819 MEDIUM
macOS < 26.6 - Unprotected User Data Exposure via Sandbox Restriction Bypass
CVSS 5.5
CVE-2026-43779 CRITICAL
macOS < 14.8.8, < 15.7.8, < 26.6 - Network Connection Interception
CVSS 9.8
CVE-2026-43763 MEDIUM
macOS < 14.8.8, < 15.7.8, < 26.6 - Unprotected File Access via Sandbox Escape
CVSS 5.5
CVE-2026-43760 HIGH
macOS < 14.8.8 and < 26.6 - Unprotected User-Sensitive Data Access via Improper Access Restrictions
CVSS 8.6
CVE-2026-28945 HIGH
macOS < 14.8.8, < 15.7.8, < 26.6 - Unauthorized Network Access via Sandbox Permissions Bypass
CVSS 7.1
CVE-2026-12990 HIGH
Ghost Robotics Vision 60 APK 5.5.0 - Concurrent Session Access Control Bypass
CVE-2026-14235 HIGH
WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Download Key
CVSS 7.5
CVE-2026-17457 MEDIUM
mf-yang openclaw-cn Scheme navigation-guard.ts assertBrowserNavigationAllowed information disclosure
CVSS 4.3
CVE-2026-17432 MEDIUM
NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control
CVSS 5.0
CVE-2026-48034 HIGH
HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
CVE-2026-58630 CRITICAL
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-9765 HIGH
Grafana Irm < 1.164.0 - Improper Access Control
CVSS 7.1
CVE-2026-15704 CRITICAL
CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components
CVSS 9.8
Details
Vulnerabilities 6,223