CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,075 vulnerabilities with CWE-284
CVE-2026-11078 MEDIUM
Google Chrome - Improper Input Validation
CVSS 6.5
CVE-2026-11026 MEDIUM
Google Chrome < 149.0.7827.53 - Navigation Restriction Bypass via Malicious Extension
CVSS 6.5
CVE-2026-11017 MEDIUM
Google Chrome < 149.0.7827.53 - Navigation Restriction Bypass via Link Preview
CVSS 6.5
CVE-2026-5228 HIGH
Improper Access Control in Kurt Software Studio's WriteUp Mobile App
CVSS 8.8
CVE-2026-36180 MEDIUM
GNCC GP5 7.1.76 - File System Protection Bypass via Bind-Mount Attack
CVSS 4.6
CVE-2026-35904 CRITICAL
T3 Technology CPE T625Pro 1.0.07 T6825G 1.0.03 T7281 1.0.03 - Unauthenticated Telnet Service Enablement via CGI Request
CVSS 9.8
CVE-2026-10807 MEDIUM
mjperpinosa stumasy change_profile_image.php unrestricted upload
CVSS 6.3
CVE-2026-10806 MEDIUM
mjperpinosa stumasy add_post.php unrestricted upload
CVSS 6.3
CVE-2026-42074 CRITICAL
OpenClaude: Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input
CVSS 9.8
CVE-2026-40715 HIGH
Dell ThinOS 10 < 2602_10.0765_T10 - Improper Access Control
CVSS 7.8
CVE-2026-40713 MEDIUM
Dell ThinOS 10 < 2602_10.0765_T10 - Improper Access Control
CVSS 6.1
CVE-2026-9590 MEDIUM
Devolutions Server < 2026.1.19 - Authenticated Permission Bypass in Asset Information Edit
CVSS 5.3
CVE-2026-9522 MEDIUM
Devolutions Server < 2026.1.19 - Authenticated Improper Access Control in PAM Account Discovery
CVSS 5.4
CVE-2026-45080 MEDIUM
Klaw: Improper Access Control Allows Disclosure of Password Hash
CVE-2026-7198 CRITICAL
CWE-284: Improper Access Control in web services in Progress Sitefinity
CVSS 9.8
CVE-2026-3198 MEDIUM
Improper Access Control in mlflow/mlflow
CVSS 6.5
CVE-2026-9614 HIGH
Ivanti Neurons for ITSM - Authenticated Privilege Escalation to Administrative Access
CVSS 8.8
CVE-2026-45284 MEDIUM
Nextcloud user_oidc 1.3.6-8.3.9 - Improper Access Control for Deleted LDAP Users
CVSS 4.6
CVE-2026-45282 MEDIUM
Nextcloud Server 32.0.0-32.0.8 & 33.0.0-33.0.2 - Improper Access Control via Link Share
CVSS 6.5
CVE-2026-37235 HIGH
FlexRIC 2.0.0 - Unauthenticated xApp Impersonation via E42 Message xapp_id Spoofing
CVSS 7.5
CVE-2026-10277 MEDIUM
j3k0 mcp-google-workspace - Incorrect Privilege Assignment in Gmail Tool saveToDisk Function
CVSS 6.3
CVE-2026-45266 LOW
Nextcloud: Unauthorized force-mute from missing permission check when using internal signaling
CVSS 3.5
CVE-2026-45264 MEDIUM
Nextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized File Renames
CVSS 4.3
CVE-2026-45157 MEDIUM
Nextcloud: Valid share tokens allow to access tempory upload files of share owner
CVSS 6.3
CVE-2026-45154 LOW
Nextcloud: Improper Access Control in Collectives
CVSS 2.6
Details
Vulnerabilities 5,075