CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,075 vulnerabilities with CWE-284
CVE-2026-46416
MEDIUM
Microsoft UFO shared WebSocket handler state causes cross-client response hijacking
CVSS 6.3
CVE-2026-47269
HIGH
pam_usb: deny_remote feature incorrectly classifies IPv4-mapped IPv6 remote connections as local
CVSS 7.4
CVE-2026-1933
HIGH
Samba: missing access check on reparse point operations
CVSS 7.1
CVE-2026-48906
HIGH
Extension - tassos.gr - Arbitrary File Deletion in Novarain/Tassos Framework < 6.1.0 for Joomla
CVSS 8.1
CVE-2026-49002
CRITICAL
Broken Access Control Vulnerabily in ZTE ZXUniPOS NDS-LTE product
CVSS 9.1
CVE-2026-41704
MEDIUM
Compromised VM can make arbitrary blobstore deletes
CVSS 5.0
CVE-2026-9604
MEDIUM
JeecgBoot AiragModelController access control
CVSS 4.3
CVE-2026-9581
MEDIUM
JeecgBoot add access control
CVSS 6.3
CVE-2026-9580
HIGH
JeecgBoot selectDepart LoginController.selectDepart access control
CVSS 7.3
CVE-2026-9579
MEDIUM
JeecgBoot SysUser userEdit user.getUsername access control
CVSS 6.3
CVE-2026-44730
HIGH
OpenCTI: Privilege escalation via graphQL API abusable by organization admins, due to incorrect ACL on userEdit relationAdd
CVSS 7.2
CVE-2026-9562
HIGH
sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard access control
CVSS 7.3
CVE-2026-48904
CRITICAL
Joomla! Core - [20260514] - Privilege escalation through com_users webservice endpoints
CVSS 9.8
CVE-2026-48900
MEDIUM
Joomla! Core - [20260516] - Incorrect Access Control in com_scheduler
CVSS 4.3
CVE-2026-48899
CRITICAL
Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins
CVSS 9.8
CVE-2026-48898
CRITICAL
Joomla! Core - [20260513] - Privilege escalation through com_users batch task
CVSS 9.8
CVE-2026-35223
CRITICAL
Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints
CVSS 9.8
CVE-2026-43934
MEDIUM
e107: Broken Access Control in e107 comment edit allows cross-user comment modification
CVSS 6.5
CVE-2026-9495
HIGH
@koa/router < 15.0.0 - Improper Access Control
CVSS 7.3
CVE-2026-9517
HIGH
hemant6488 CodeIgniter-StudentManagementSystem Student Management addStudentView access control
CVSS 7.3
CVE-2026-9445
MEDIUM
SourceCodester Simple POS and Inventory System File Extension addproduct.php unrestricted upload
CVSS 6.3
CVE-2026-9421
HIGH
KLiK SocialMediaWebsite File upload.inc.php uniqid unrestricted upload
CVSS 7.3
CVE-2026-9489
HIGH
NitroSense V3: Local Privilege Escalation (LPE) vulnerability
CVE-2026-9412
MEDIUM
SourceCodester Indian Invoicing System Backend Endpoint access control
CVSS 6.3
CVE-2026-9374
MEDIUM
yangzongzhuan RuoYi-Vue Common Upload Endpoint upload FileUploadUtils.upload unrestricted upload
CVSS 6.3
Details
Vulnerabilities
5,075