CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,270 vulnerabilities with CWE-284
CVE-2026-1170 MEDIUM
birkir prime < 0.4.0 - Information Disclosure via GraphQL API
CVSS 5.3
CVE-2026-23522 LOW
LobeChat <2.0.0-next.193 - Privilege Escalation
CVSS 3.7
CVE-2026-1181 CRITICAL
Altium 365 - Improper Access Control via Overly Permissive CORS Policy
CVSS 9.0
CVE-2026-1152 MEDIUM
technical-laohu mpay < 1.2.4 - Unrestricted File Upload via QR Code Image Handler
CVSS 4.7
CVE-2026-1126 MEDIUM
LWJ Flow - Unrestricted File Upload in SVG File Handler
CVSS 6.3
CVE-2026-1107 MEDIUM
EyouCMS <1.7.1/5.0 - Unrestricted Upload
CVSS 6.3
CVE-2026-1061 MEDIUM
xiweicheng TMS <2.28.0 - Unrestricted Upload
CVSS 6.3
CVE-2026-1009 CRITICAL
Altium Live - Authenticated Stored Cross-Site Scripting in Forum Post Content
CVSS 9.0
CVE-2026-23496 MEDIUM
Pimcore Web2Print Tools Bundle <6.1.1 - Privilege Escalation
CVSS 5.4
CVE-2026-23495 MEDIUM
Pimcore <2.2.3-1.7.16 - Info Disclosure
CVSS 4.3
CVE-2026-23494 MEDIUM
Pimcore <12.3.1-11.5.14 - Info Disclosure
CVSS 4.3
CVE-2026-22909 HIGH
SICK TDC-X401GL Firmware - Unauthenticated Improper Access Control
CVSS 7.5
CVE-2026-21889 HIGH
Weblate < 5.15.2 - Unauthenticated Screenshot Access via Direct HTTP Request
CVSS 7.5
CVE-2026-20949 HIGH
Microsoft Office Excel - Info Disclosure
CVSS 7.8
CVE-2026-20929 HIGH
Windows HTTP.sys - Privilege Escalation
CVSS 7.5
CVE-2026-20843 HIGH
Windows RRAS - Privilege Escalation
CVSS 7.8
CVE-2026-20839 MEDIUM
Windows Client-Side Caching - Info Disclosure
CVSS 5.5
CVE-2026-20825 MEDIUM
Windows 10 1809 and Windows Server 2019 < 10.0.17763.8276 - Authenticated Information Disclosure
CVSS 4.4
CVE-2026-0386 HIGH
Windows Server 2008-2025 - Unauthenticated Remote Code Execution via Deployment Services
CVSS 7.5
CVE-2026-0881 CRITICAL
Firefox and Thunderbird < 147.0 - Sandbox Escape via Messaging System Component
CVSS 10.0
CVE-2026-22033 MEDIUM
Label Studio < 1.22.0 - Stored Cross-Site Scripting via Custom Hotkeys
CVSS 5.4
CVE-2026-22605 MEDIUM
OpenProject < 16.6.3 - Improper Access Control via Meeting Details
CVSS 4.3
CVE-2026-22043 CRITICAL
RustFS 1.0.0-alpha.13-1.0.0-alpha.78 - Privilege Escalation via Flawed IAM deny_only Short-Circuit
CVSS 9.8
CVE-2026-21694 MEDIUM
Titra < 0.99.50 - Improper Access Control
CVSS 6.8
CVE-2026-0643 HIGH
projectworlds House Rental and Property Listing 1.0 - Unrestricted File Upload via Signup Image Parameter
CVSS 7.3
Details
Vulnerabilities 5,270