CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,075 vulnerabilities with CWE-284
CVE-2026-41102 HIGH
Microsoft PowerPoint for Android Spoofing Vulnerability
CVSS 7.1
CVE-2026-41101 HIGH
Microsoft Word for Android Spoofing Vulnerability
CVSS 7.1
CVE-2026-41100 MEDIUM
Microsoft 365 Copilot for Android Spoofing Vulnerability
CVSS 4.4
CVE-2026-41086 HIGH
Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-40420 HIGH
Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-40381 HIGH
Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-33834 HIGH
Microsoft Windows 10 Version 1607 - Windows Event Logging Service Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-32209 MEDIUM
Microsoft Windows 10 Version 1607 - Windows Filtering Platform (WFP) Security Feature Bypass Vulnerability
CVSS 4.4
CVE-2026-40300 MEDIUM
Zulip: Message edit history visible in "moves only" policy through /api/v1/messages/{id}/history
CVSS 6.5
CVE-2026-20887 HIGH
Intel Vision software - Improper Access Control
CVE-2026-40020 LOW
OX Dovecot Pro < 2.3.0 - Improper Access Control via IMAP SETACL Command
CVSS 3.1
CVE-2026-43652 HIGH
macOS < 26.5 - Unprotected User Data Exposure via Permissions Issue
CVSS 7.5
CVE-2026-28993 MEDIUM
iOS and iPadOS < 18.7.9 - Unauthenticated User-Sensitive Data Exposure via Missing Consent Prompt
CVSS 5.5
CVE-2026-28988 MEDIUM
iOS and iPadOS < 26.5 - Improper Access Control
CVSS 5.5
CVE-2026-28978 HIGH
macOS < 14.8.7, < 15.7.7, < 26.5 - Sandbox Escape via Permissions Issue
CVSS 8.8
CVE-2026-28974 HIGH
iOS and iPadOS < 26.5 - Denial of Service via Unauthorized Actions
CVSS 7.5
CVE-2026-28965 HIGH
iOS and iPadOS < 26.5 - Unprotected User Data Exposure via Lock Screen
CVSS 7.5
CVE-2026-28957 LOW
iOS and iPadOS < 18.7.9 and < 26.5 - Unauthorized Screen Capture via Camera Metadata Access
CVSS 3.3
CVE-2026-28930 HIGH
macOS < 26.5 - Unprotected User Data Exposure via Permissions Issue
CVSS 7.5
CVE-2026-28922 MEDIUM
macOS - Information Disclosure
CVSS 6.5
CVE-2026-28910 LOW
macOS < 26.4 - Unauthorized File Access via Improper Permissions
CVSS 3.3
CVE-2026-7813 CRITICAL
pgAdmin 4: Cross-user data access and shared-server privilege escalation in server mode
CVSS 9.9
CVE-2026-8233 MEDIUM
Dotouch XproUPF access control
CVSS 4.6
CVE-2026-42569 CRITICAL
phpvms: /importer authorization bypass causing full database wipe
CVSS 9.4
CVE-2026-1749 MEDIUM
HikCentral Professional - Privilege Escalation
CVSS 6.8
Details
Vulnerabilities 5,075