CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,075 vulnerabilities with CWE-284
CVE-2026-45301 HIGH
Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
CVSS 8.1
CVE-2026-44556 HIGH
Open WebUI: responses passthrough endpoint lacks access control authorization
CVSS 7.1
CVE-2026-44774 CRITICAL
Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false
CVSS 9.9
CVE-2026-7373 HIGH
Metasploit Pro on Windows: Local Privilege Escalation via OpenSSL Configuration File Loading
CVE-2026-8586 MEDIUM
Google Chrome < 148.0.7778.168 - Local Discretionary Access Control Bypass via Malicious File
CVSS 5.5
CVE-2026-8566 MEDIUM
Google Chrome < 148.0.7778.168 - Insufficient Policy Enforcement in Payments
CVSS 4.3
CVE-2026-8556 LOW
Google Chrome < 148.0.7778.168 - Cross-Origin Data Leak via ANGLE Implementation
CVSS 3.1
CVE-2026-8545 LOW
Google Chrome < 148.0.7778.168 - Cross-Origin Data Leak via Compositing Object Corruption
CVSS 3.1
CVE-2026-24711 MEDIUM
CFEngine Enterprise <3.21.8, 3.24.3, 3.27.0 - Incorrect Access Control
CVSS 5.3
CVE-2026-44478 HIGH
hoppscotch: Unauthenticated Onboarding Config Disclosure via Empty Recovery Token
CVSS 7.5
CVE-2026-33381 MEDIUM
Users can generate Service Account tokens after permissions removal
CVSS 5.9
CVE-2026-33377 HIGH
Dashboard Import Overwrites ACL — Editor Privilege Escalation to Dashboard Admin
CVSS 7.1
CVE-2026-28374 MEDIUM
IDOR in Annotations API allows unprivileged users to DELETE annotation
CVSS 4.3
CVE-2026-44007 CRITICAL
vm2: nesting: true bypasses require: false, allowing sandbox escape to arbitrary OS command execution
CVSS 9.1
CVE-2026-36738 MEDIUM
U-SPEED AC1200 T18-21K V1.0 - Incorrect Access Control
CVSS 6.8
CVE-2026-44352 MEDIUM
Flowsint: Broken Access Control allows reading of sketch logs from any user
CVE-2026-44341 MEDIUM
GoJobs: Insecure Direct Object Reference (IDOR) in Job Retrieval Endpoint
CVSS 5.3
CVE-2026-42158 LOW
Flowsint: Broken Access Control allows modification of investigation metadata from any user
CVE-2026-44874 MEDIUM
Authenticated Arbitrary File Download via AOS-10 Web-Based Management Interface
CVSS 4.9
CVE-2026-44225 CRITICAL
Pulpy: Incomplete filesystem sandbox in pulpy.fs bridge allows packaged web apps to read arbitrary user files
CVSS 9.3
CVE-2026-44277 CRITICAL
FortiAuthenticator 8.0.0-8.0.2, 6.5.0-6.5.6, 6.6.0-6.6.8, 6.4.0-6.4.10 - Improper Access Control
CVSS 9.8
CVE-2026-42832 HIGH
Microsoft Office Spoofing Vulnerability
CVSS 7.7
CVE-2026-42823 CRITICAL
Azure Logic Apps Elevation of Privilege Vulnerability
CVSS 9.9
CVE-2026-42177 MEDIUM
linux-entra-sso: PRT SSO cookie can leak to attacker-controlled hosts when broad host permissions are granted
CVSS 5.3
CVE-2026-41614 MEDIUM
M365 Copilot for Desktop Spoofing Vulnerability
CVSS 6.2
Details
Vulnerabilities 5,075