CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
4,788 vulnerabilities with CWE-284
CVE-2026-20697
MEDIUM
macOS <14.8.5 - Privilege Escalation
CVSS 5.3
CVE-2026-20632
MEDIUM
Apple macOS <26.4 - Info Disclosure
CVSS 5.3
CVE-2026-20622
HIGH
macOS <15.7.4 - Info Disclosure
CVSS 7.5
CVE-2026-33316
HIGH
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement
CVSS 8.1
CVE-2026-33484
HIGH
Langflow has Unauthenticated IDOR on Image Downloads
CVSS 7.5
CVE-2026-33309
CRITICAL
Langflow has an Arbitrary File Write (RCE) via v2 API
CVSS 9.9
CVE-2026-32299
HIGH
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
CVSS 7.5
CVE-2026-0898
CRITICAL
Pega Browser Extension for Pega Robot Studio 22.1 and R25 - Arbitrary File Write
CVE-2026-33478
CRITICAL
AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection
CVSS 10.0
CVE-2026-4586
MEDIUM
CodePhiliaX Chat2DB JDBC Driver Upload JdbcDriverController.java upload unrestricted upload
CVSS 6.3
CVE-2026-4628
MEDIUM
Keycloak: org.keycloak.authorization: keycloak: unauthorized resource modification due to improper access control
CVSS 4.3
CVE-2026-4536
HIGH
Acrel Environmental Monitoring Cloud Platform unrestricted upload
CVSS 7.3
CVE-2026-4514
MEDIUM
PbootCMS Backend UserController.php access control
CVSS 6.3
CVE-2026-4505
MEDIUM
eosphoros-ai DB-GPT FastAPI Endpoint controller.py module_plugin.refresh_plugins unrestricted upload
CVSS 6.3
CVE-2026-32768
CRITICAL
Chall-Manager's invalid NetworkPolicy enables a malicious actor to pivot into another namespace
CVSS 9.9
CVE-2026-32938
CRITICAL
SiYuan has an Arbitrary File Read in its Desktop Publish Service
CVSS 9.9
CVE-2026-33062
HIGH
free5GC NRF Discovery EncodeGroupId Function Panics on Malformed group-id-list Parameter
CVSS 7.5
CVE-2026-32769
CRITICAL
Fullchain's Invalid NetworkPolicy enables a malicious actor to pivot into another namespace
CVSS 9.8
CVE-2026-32761
MEDIUM
File Browser has an Authorization Policy Bypass in its Public Share Download Flow
CVSS 6.5
CVE-2026-32760
CRITICAL
File Browser Self Registration Grants Any User Admin Access When Default Permissions Include Admin
CVSS 9.8
CVE-2026-33393
MEDIUM
Discourse fixes loose hostname matching in spam host allowlist
CVSS 4.3
CVE-2026-32752
NONE
FreeScout: Broken Access Control in ThreadPolicy — Any User Can Read/Edit All Customer Messages
CVE-2026-32038
CRITICAL
OpenClaw - Sandbox Network Isolation Bypass via docker.network=container Parameter
CVSS 9.8
CVE-2026-32737
CRITICAL
Romeo's invalid NetworkPolicy enables a malicious actor to pivot into another namespace
CVSS 10.0
CVE-2026-32693
HIGH
Unauthorized access to Kubernetes secrets in Juju
CVSS 8.8
Details
Vulnerabilities
4,788