CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,270 vulnerabilities with CWE-284
CVE-2026-24302
HIGH
Azure Arc - Unauthenticated Privilege Escalation via Improper Access Control
CVSS 8.6
CVE-2026-24300
CRITICAL
Azure Front Door - Privilege Escalation
CVSS 9.8
CVE-2026-1964
MEDIUM
Wekan < 8.21 - Improper Access Control in REST Endpoint
CVSS 4.3
CVE-2026-1963
MEDIUM
WeKan < 8.21 - Improper Access Control in Attachment Storage
CVSS 6.3
CVE-2026-1962
MEDIUM
Wekan < 8.21 - Improper Access Controls in Attachment Migration
CVSS 6.3
CVE-2026-1707
HIGH
pgAdmin 9.11 - Privilege Escalation
CVSS 7.4
CVE-2026-1898
MEDIUM
Wekan < 8.21 - Improper Access Control in LDAP User Sync
CVSS 6.3
CVE-2026-1896
MEDIUM
WeKan <8.20 - Improper Access Controls
CVSS 6.3
CVE-2026-1895
MEDIUM
WeKan <8.20 - Improper Access Controls
CVSS 6.3
CVE-2026-25519
HIGH
OpenSlides 4.2.5-4.2.29 - Unauthenticated Incorrect Access Control via Local Login Bypass
CVSS 8.1
CVE-2026-1813
MEDIUM
bolo-blog bolo-solo <2.6.4 - Unrestricted Upload
CVSS 6.3
CVE-2026-24670
MEDIUM
Open eClass <4.2 - Privilege Escalation
CVSS 6.5
CVE-2026-24668
MEDIUM
Open eClass <4.2 - Privilege Escalation
CVSS 6.5
CVE-2026-1117
HIGH
parisneo/lollms < 2.0.0 - Unauthenticated Improper Access Control in Socket.IO Event Handlers
CVSS 8.2
CVE-2026-1742
MEDIUM
EFM ipTIME A8004T <14.18.2 - Unrestricted Upload
CVSS 4.7
CVE-2026-24904
MEDIUM
TrustTunnel < 0.9.115 - Rule Bypass via TLS ClientHello Fragmentation
CVSS 5.3
CVE-2026-0844
HIGH
WordPress Simple User Registration <6.7 - Privilege Escalation
CVSS 8.8
CVE-2026-24740
CRITICAL
Dozzle < 9.0.3 - Improper Access Control via Container ID Targeting
CVSS 9.9
CVE-2026-24473
MEDIUM
Hono < 4.11.7 - Information Disclosure via Serve Static Middleware Path Validation
CVSS 5.3
CVE-2026-1445
MEDIUM
iJason-Liu Books_Manager <298ba736387ca37810466349af13a0fdf828e99c ...
CVSS 4.7
CVE-2026-1424
MEDIUM
PHPGurukul News Portal 1.0 - Unrestricted File Upload in Profile Pic Handler
CVSS 4.7
CVE-2026-1423
MEDIUM
Online Examination System 1.0 - Unauthenticated Arbitrary File Upload via /admin_pic.php
CVSS 6.3
CVE-2026-1411
MEDIUM
Beetel 777VR1 Firmware < 01.00.09_55 - Incorrect Privilege Assignment via UART Interface
CVSS 6.1
CVE-2026-1407
LOW
Beetel 777VR1 < 01.00.09_55 - Information Disclosure via UART Interface
CVSS 2.0
CVE-2026-24420
MEDIUM
phpmyfaq < 4.0.17 - Authenticated Improper Access Control via Attachment Download
CVSS 6.5
Details
Vulnerabilities
5,270