CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,075 vulnerabilities with CWE-284
CVE-2026-11078
MEDIUM
Google Chrome - Improper Input Validation
CVSS 6.5
CVE-2026-11026
MEDIUM
Google Chrome < 149.0.7827.53 - Navigation Restriction Bypass via Malicious Extension
CVSS 6.5
CVE-2026-11017
MEDIUM
Google Chrome < 149.0.7827.53 - Navigation Restriction Bypass via Link Preview
CVSS 6.5
CVE-2026-5228
HIGH
Improper Access Control in Kurt Software Studio's WriteUp Mobile App
CVSS 8.8
CVE-2026-36180
MEDIUM
GNCC GP5 7.1.76 - File System Protection Bypass via Bind-Mount Attack
CVSS 4.6
CVE-2026-35904
CRITICAL
T3 Technology CPE T625Pro 1.0.07 T6825G 1.0.03 T7281 1.0.03 - Unauthenticated Telnet Service Enablement via CGI Request
CVSS 9.8
CVE-2026-10807
MEDIUM
mjperpinosa stumasy change_profile_image.php unrestricted upload
CVSS 6.3
CVE-2026-10806
MEDIUM
mjperpinosa stumasy add_post.php unrestricted upload
CVSS 6.3
CVE-2026-42074
CRITICAL
OpenClaude: Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input
CVSS 9.8
CVE-2026-40715
HIGH
Dell ThinOS 10 < 2602_10.0765_T10 - Improper Access Control
CVSS 7.8
CVE-2026-40713
MEDIUM
Dell ThinOS 10 < 2602_10.0765_T10 - Improper Access Control
CVSS 6.1
CVE-2026-9590
MEDIUM
Devolutions Server < 2026.1.19 - Authenticated Permission Bypass in Asset Information Edit
CVSS 5.3
CVE-2026-9522
MEDIUM
Devolutions Server < 2026.1.19 - Authenticated Improper Access Control in PAM Account Discovery
CVSS 5.4
CVE-2026-45080
MEDIUM
Klaw: Improper Access Control Allows Disclosure of Password Hash
CVE-2026-7198
CRITICAL
CWE-284: Improper Access Control in web services in Progress Sitefinity
CVSS 9.8
CVE-2026-3198
MEDIUM
Improper Access Control in mlflow/mlflow
CVSS 6.5
CVE-2026-9614
HIGH
Ivanti Neurons for ITSM - Authenticated Privilege Escalation to Administrative Access
CVSS 8.8
CVE-2026-45284
MEDIUM
Nextcloud user_oidc 1.3.6-8.3.9 - Improper Access Control for Deleted LDAP Users
CVSS 4.6
CVE-2026-45282
MEDIUM
Nextcloud Server 32.0.0-32.0.8 & 33.0.0-33.0.2 - Improper Access Control via Link Share
CVSS 6.5
CVE-2026-37235
HIGH
FlexRIC 2.0.0 - Unauthenticated xApp Impersonation via E42 Message xapp_id Spoofing
CVSS 7.5
CVE-2026-10277
MEDIUM
j3k0 mcp-google-workspace - Incorrect Privilege Assignment in Gmail Tool saveToDisk Function
CVSS 6.3
CVE-2026-45266
LOW
Nextcloud: Unauthorized force-mute from missing permission check when using internal signaling
CVSS 3.5
CVE-2026-45264
MEDIUM
Nextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized File Renames
CVSS 4.3
CVE-2026-45157
MEDIUM
Nextcloud: Valid share tokens allow to access tempory upload files of share owner
CVSS 6.3
CVE-2026-45154
LOW
Nextcloud: Improper Access Control in Collectives
CVSS 2.6
Details
Vulnerabilities
5,075