CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,075 vulnerabilities with CWE-284
CVE-2026-11464 LOW
JeecgBoot User List Endpoint SysUserController.java queryPageList information disclosure
CVSS 3.1
CVE-2026-11459 LOW
SecureAge CatchPulse IOCTL saappctl.sys information disclosure
CVSS 3.3
CVE-2026-11458 MEDIUM
erzhongxmu JeeWMS Boot Actuator Endpoint actuator information disclosure
CVSS 5.3
CVE-2026-45776 MEDIUM
Open XDMoD has Broken Access Control via Client-Controlled Session Variable
CVSS 4.3
CVE-2026-45746 CRITICAL
Termix Vulnerable to Arbitrary Command Execution via Session Hijacking
CVSS 9.0
CVE-2026-11344 HIGH
code-projects Vehicle Management System New Driver Registration Form newdriver.php unrestricted upload
CVSS 7.3
CVE-2026-11333 MEDIUM
tittuvarghese CollegeManagementSystem Student Data Upload Endpoint upload_student_data.php unrestricted upload
CVSS 6.3
CVE-2026-48907 CRITICAL
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
CVE-2026-11326 MEDIUM
OpenAI Atlas < 1.2025.288.15 - Improper Access Control
CVE-2026-11302 MEDIUM
Google Chrome for iOS < 149.0.7827.53 - Unauthenticated Discretionary Access Control Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-11277 MEDIUM
Google Chrome for iOS < 149.0.7827.53 - Discretionary Access Control Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-11275 MEDIUM
Google Chrome < 149.0.7827.53 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-11274 MEDIUM
Google Chrome < 149.0.7827.53 - Navigation Restriction Bypass via DOM Distiller
CVSS 4.3
CVE-2026-11258 MEDIUM
Google Chrome < 149.0.7827.53 - Discretionary Access Control Bypass via File System Access
CVSS 6.5
CVE-2026-11257 MEDIUM
Google Chrome < 149.0.7827.53 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-11252 MEDIUM
Google Chrome < 149.0.7827.53 - Insufficient Policy Enforcement in Content Settings
CVSS 4.3
CVE-2026-11212 MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via DevTools Policy Bypass
CVSS 4.3
CVE-2026-11210 MEDIUM
Google Chrome < 149.0.7827.53 - Discretionary Access Control Bypass via Crafted RAR File
CVSS 6.5
CVE-2026-11204 MEDIUM
Google Chrome on iOS < 149.0.7827.53 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-11197 MEDIUM
Google Chrome < 149.0.7827.53 - Same Origin Policy Bypass via Workers
CVSS 6.5
CVE-2026-11193 MEDIUM
Google Chrome < 149.0.7827.53 - Insufficient Policy Enforcement in Password Manager
CVSS 6.5
CVE-2026-11190 MEDIUM
Google Chrome < 149.0.7827.53 - Discretionary Access Control Bypass via Malicious Extension
CVSS 6.5
CVE-2026-11187 MEDIUM
Google Chrome < 149.0.7827.53 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.3
CVE-2026-11179 HIGH
Google Chrome < 149.0.7827.53 - Site Isolation Bypass via ORB
CVSS 8.8
CVE-2026-11135 MEDIUM
Google Chrome < 149.0.7827.53 - Insufficient Policy Enforcement in Autofill
CVSS 6.5
Details
Vulnerabilities 5,075