CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,075 vulnerabilities with CWE-284
CVE-2026-9352
MEDIUM
NousResearch hermes-agent Messaging Gateway local.py _make_run_env information disclosure
CVSS 5.3
CVE-2026-9349
MEDIUM
calcom cal.diy Generic React API bookings-single-view.getServerSideProps.tsx getServerSideProps information disclosure
CVSS 5.3
CVE-2026-39968
HIGH
TypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview Endpoint
CVSS 7.1
CVE-2026-9223
MEDIUM
Devolutions Server < 2026.1.16.0 - Improper Access Control
CVSS 4.3
CVE-2026-5171
MEDIUM
Devolutions Server - Improper Access Control
CVSS 4.3
CVE-2026-34908
CRITICAL
Ubiquiti INC UniFi OS Server - Improper Access Control
CVSS 10.0
CVE-2026-8240
MEDIUM
Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure in Backend\SummaryTemplate
CVSS 5.3
CVE-2026-41999
MEDIUM
PowerDNS Authoritative 5.0.0-5.0.4 - Improper Access Control via TCP PROXY Requests
CVSS 4.8
CVE-2026-2734
MEDIUM
Authorization Bypass in SearchModelVersions in mlflow/mlflow
CVSS 6.5
CVE-2026-39310
HIGH
Trilium Notes: Authentication Bypass in Clipper API for Electron (Desktop) Builds
CVSS 8.6
CVE-2026-44926
HIGH
InfoScale CmdServer < 7.4.2 - Access Control Mishandling
CVSS 8.8
CVE-2026-0856
HIGH
Mesalvo Meona Client Launcher <= 19.06.2020 & Server <= 2025.04 - Improper Access Control
CVSS 7.8
CVE-2026-34754
MEDIUM
MantisBT allows unauthorized users to upload attachments to restricted issues via REST API
CVSS 4.3
CVE-2026-34390
MEDIUM
MantisBT: Privilege Escalation from Manager to Administrator
CVE-2026-34358
HIGH
CtrlPanel: Missing Authorization on Admin Write Endpoints Allows RBAC Bypass
CVSS 8.1
CVE-2026-34234
CRITICAL
CtrlPanel: Unauthenticated RCE using installer script
CVSS 10.0
CVE-2026-39250
HIGH
Innoshop 0.6.0 - Authenticated Authorization Bypass
CVSS 7.3
CVE-2026-34233
MEDIUM
CtrlPanel has Missing Authentication Checks in Datatable Admin Endpoints
CVSS 6.5
CVE-2026-37979
MEDIUM
Keycloak: keycloak: information disclosure via oidc token introspection endpoint audience bypass
CVSS 6.5
CVE-2026-31388
MEDIUM
Apache OFBiz: Cross-Tenant Data Exposure via Program Export Feature
CVSS 5.3
CVE-2026-32994
MEDIUM
Rocket.Chat <8.5.0 Authenticated Improper Access Control via Autotranslate
CVSS 5.3
CVE-2026-8766
MEDIUM
Kilo-Org kilocode Environment Variable config.ts load information disclosure
CVSS 4.3
CVE-2026-8758
HIGH
Metasoft 美特软件 MetaCRM upload3.jsp unrestricted upload
CVSS 7.3
CVE-2026-8752
MEDIUM
h2oai h2o-3 Rapids setproperty Primitive AstSetProperty.java exec access control
CVSS 5.3
CVE-2026-8750
MEDIUM
h2oai h2o-3 ImportFile API PersistNFS.java importFiles information disclosure
CVSS 5.3
Details
Vulnerabilities
5,075