CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

4,788 vulnerabilities with CWE-284
CVE-2026-20697 MEDIUM
macOS <14.8.5 - Privilege Escalation
CVSS 5.3
CVE-2026-20632 MEDIUM
Apple macOS <26.4 - Info Disclosure
CVSS 5.3
CVE-2026-20622 HIGH
macOS <15.7.4 - Info Disclosure
CVSS 7.5
CVE-2026-33316 HIGH
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement
CVSS 8.1
CVE-2026-33484 HIGH
Langflow has Unauthenticated IDOR on Image Downloads
CVSS 7.5
CVE-2026-33309 CRITICAL
Langflow has an Arbitrary File Write (RCE) via v2 API
CVSS 9.9
CVE-2026-32299 HIGH
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
CVSS 7.5
CVE-2026-0898 CRITICAL
Pega Browser Extension for Pega Robot Studio 22.1 and R25 - Arbitrary File Write
CVE-2026-33478 CRITICAL
AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection
CVSS 10.0
CVE-2026-4586 MEDIUM
CodePhiliaX Chat2DB JDBC Driver Upload JdbcDriverController.java upload unrestricted upload
CVSS 6.3
CVE-2026-4628 MEDIUM
Keycloak: org.keycloak.authorization: keycloak: unauthorized resource modification due to improper access control
CVSS 4.3
CVE-2026-4536 HIGH
Acrel Environmental Monitoring Cloud Platform unrestricted upload
CVSS 7.3
CVE-2026-4514 MEDIUM
PbootCMS Backend UserController.php access control
CVSS 6.3
CVE-2026-4505 MEDIUM
eosphoros-ai DB-GPT FastAPI Endpoint controller.py module_plugin.refresh_plugins unrestricted upload
CVSS 6.3
CVE-2026-32768 CRITICAL
Chall-Manager's invalid NetworkPolicy enables a malicious actor to pivot into another namespace
CVSS 9.9
CVE-2026-32938 CRITICAL
SiYuan has an Arbitrary File Read in its Desktop Publish Service
CVSS 9.9
CVE-2026-33062 HIGH
free5GC NRF Discovery EncodeGroupId Function Panics on Malformed group-id-list Parameter
CVSS 7.5
CVE-2026-32769 CRITICAL
Fullchain's Invalid NetworkPolicy enables a malicious actor to pivot into another namespace
CVSS 9.8
CVE-2026-32761 MEDIUM
File Browser has an Authorization Policy Bypass in its Public Share Download Flow
CVSS 6.5
CVE-2026-32760 CRITICAL
File Browser Self Registration Grants Any User Admin Access When Default Permissions Include Admin
CVSS 9.8
CVE-2026-33393 MEDIUM
Discourse fixes loose hostname matching in spam host allowlist
CVSS 4.3
CVE-2026-32752 NONE
FreeScout: Broken Access Control in ThreadPolicy — Any User Can Read/Edit All Customer Messages
CVE-2026-32038 CRITICAL
OpenClaw - Sandbox Network Isolation Bypass via docker.network=container Parameter
CVSS 9.8
CVE-2026-32737 CRITICAL
Romeo's invalid NetworkPolicy enables a malicious actor to pivot into another namespace
CVSS 10.0
CVE-2026-32693 HIGH
Unauthorized access to Kubernetes secrets in Juju
CVSS 8.8
Details
Vulnerabilities 4,788