CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,075 vulnerabilities with CWE-284
CVE-2026-45301
HIGH
Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
CVSS 8.1
CVE-2026-44556
HIGH
Open WebUI: responses passthrough endpoint lacks access control authorization
CVSS 7.1
CVE-2026-44774
CRITICAL
Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false
CVSS 9.9
CVE-2026-7373
HIGH
Metasploit Pro on Windows: Local Privilege Escalation via OpenSSL Configuration File Loading
CVE-2026-8586
MEDIUM
Google Chrome < 148.0.7778.168 - Local Discretionary Access Control Bypass via Malicious File
CVSS 5.5
CVE-2026-8566
MEDIUM
Google Chrome < 148.0.7778.168 - Insufficient Policy Enforcement in Payments
CVSS 4.3
CVE-2026-8556
LOW
Google Chrome < 148.0.7778.168 - Cross-Origin Data Leak via ANGLE Implementation
CVSS 3.1
CVE-2026-8545
LOW
Google Chrome < 148.0.7778.168 - Cross-Origin Data Leak via Compositing Object Corruption
CVSS 3.1
CVE-2026-24711
MEDIUM
CFEngine Enterprise <3.21.8, 3.24.3, 3.27.0 - Incorrect Access Control
CVSS 5.3
CVE-2026-44478
HIGH
hoppscotch: Unauthenticated Onboarding Config Disclosure via Empty Recovery Token
CVSS 7.5
CVE-2026-33381
MEDIUM
Users can generate Service Account tokens after permissions removal
CVSS 5.9
CVE-2026-33377
HIGH
Dashboard Import Overwrites ACL — Editor Privilege Escalation to Dashboard Admin
CVSS 7.1
CVE-2026-28374
MEDIUM
IDOR in Annotations API allows unprivileged users to DELETE annotation
CVSS 4.3
CVE-2026-44007
CRITICAL
vm2: nesting: true bypasses require: false, allowing sandbox escape to arbitrary OS command execution
CVSS 9.1
CVE-2026-36738
MEDIUM
U-SPEED AC1200 T18-21K V1.0 - Incorrect Access Control
CVSS 6.8
CVE-2026-44352
MEDIUM
Flowsint: Broken Access Control allows reading of sketch logs from any user
CVE-2026-44341
MEDIUM
GoJobs: Insecure Direct Object Reference (IDOR) in Job Retrieval Endpoint
CVSS 5.3
CVE-2026-42158
LOW
Flowsint: Broken Access Control allows modification of investigation metadata from any user
CVE-2026-44874
MEDIUM
Authenticated Arbitrary File Download via AOS-10 Web-Based Management Interface
CVSS 4.9
CVE-2026-44225
CRITICAL
Pulpy: Incomplete filesystem sandbox in pulpy.fs bridge allows packaged web apps to read arbitrary user files
CVSS 9.3
CVE-2026-44277
CRITICAL
FortiAuthenticator 8.0.0-8.0.2, 6.5.0-6.5.6, 6.6.0-6.6.8, 6.4.0-6.4.10 - Improper Access Control
CVSS 9.8
CVE-2026-42832
HIGH
Microsoft Office Spoofing Vulnerability
CVSS 7.7
CVE-2026-42823
CRITICAL
Azure Logic Apps Elevation of Privilege Vulnerability
CVSS 9.9
CVE-2026-42177
MEDIUM
linux-entra-sso: PRT SSO cookie can leak to attacker-controlled hosts when broad host permissions are granted
CVSS 5.3
CVE-2026-41614
MEDIUM
M365 Copilot for Desktop Spoofing Vulnerability
CVSS 6.2
Details
Vulnerabilities
5,075