CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,326 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 103 of 127
- CVE-2026-40009MEDIUMCVSS 6.5EG 6.52026-07-10
Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor. This issue affects Apache IoTDB: from 2.0.8 bef…
- CVE-2026-40020LOWCVSS 3.1EG 3.12026-05-12
Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to being able to spam folders to ot…
- CVE-2026-40252HIGHCVSS 8.1EG 8.12026-04-10
FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any authenticated team to access and execute applications belonging to other teams by supplying a foreign appId. While the…
- CVE-2026-4026HIGHCVSS 8.7EG 8.72026-06-19
A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user with read-only access to account settings to escalate their privileges to Administrator level.
- CVE-2026-4027HIGHCVSS 7.1EG 7.12026-06-19
A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized access to attachment files due to insufficient access control.
- CVE-2026-40300MEDIUMCVSS 6.5EG 6.52026-05-12
Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical content values, allowing low-privilege users to recover text…
- CVE-2026-40304MEDIUMCVSS 5.3EG 5.32026-04-17
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (controller/unaccess.go) contains a logical error in its ownership guard: when a frontend record has environment_id = NUL…
- CVE-2026-40381HIGHCVSS 7.8EG 7.82026-05-12
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
- CVE-2026-40420HIGHCVSS 8.8EG 8.82026-05-12
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
- CVE-2026-40452HIGHCVSS 7.5EG 7.52026-07-10
Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users. This issue affects Apache IoTDB: from 1.3.5 befor…
- CVE-2026-40474HIGHCVSS 7.6EG 7.62026-04-17
wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.change_gymconfig' but inherits WgerFormMixin instead of WgerPermissionMixin, so the permissi…
- CVE-2026-40498CRITICALCVSS 9.8EG 9.82026-04-21
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system tools that should be restricted to administrators. The /system/cron endpoint relies on a s…
- CVE-2026-40569CRITICALCVSS 9.0EG 9.02026-04-21
FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connection settings endpoints of FreeScout (`connectionIncomingSave()` at `app/Http/Controllers/Mai…
- CVE-2026-40595HIGHCVSS 7.5EG 7.52026-04-30
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes public chart retrieval and export routes that only verify project-level publ…
- CVE-2026-40603MEDIUMCVSS 6.5EG 6.52026-04-30
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes a legacy dashboard route that returns a project's report data to any authent…
- CVE-2026-40713MEDIUMCVSS 6.1EG 6.12026-06-02
Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information exposure.
- CVE-2026-40715HIGHCVSS 7.8EG 7.82026-06-02
Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
- CVE-2026-40865HIGHCVSS 7.1EG 7.12026-04-21
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document viewer allows any authenticated user to access other employees’ uploaded documents by chang…
- CVE-2026-40866HIGHCVSS 8.6EG 8.62026-04-21
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document upload endpoint allows any authenticated user to overwrite or replace or corrupt another empl…
- CVE-2026-40867HIGHCVSS 7.1EG 7.12026-04-21
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerability in the helpdesk attachment viewer allows any authenticated user to view attachments from other tickets by changing t…
- CVE-2026-40874MEDIUMCVSS 6.0EG 6.02026-04-21
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, no administrator verification takes place when deleting Forwarding Hosts with `/api/v1/delete/fwdhost`. Any authenticated user can …
- CVE-2026-40888MEDIUMCVSS 6.5EG 6.52026-04-21
Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role can access unauthorized information by exploiting certain api endpoint. Versions 15.58.1 …
- CVE-2026-40889MEDIUMCVSS 6.5EG 6.52026-04-21
Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthorized files by exploiting certain api endpoint. Versions 15.58.2 and 16.4.2 contain a patch…
- CVE-2026-40904HIGHCVSS 8.1EG 8.12026-04-30
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes multiple dataset and dataRequest endpoints that authorize low-privileged pro…
- CVE-2026-40966MEDIUMCVSS 5.9EG 5.92026-04-28
In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId. Only applications that use…
- CVE-2026-41006HIGHCVSS 7.5EG 7.52026-06-09
Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations. …
- CVE-2026-4105MEDIUMCVSS 6.7EG 6.72026-03-13
A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user …
- CVE-2026-41086HIGHCVSS 8.8EG 8.82026-05-12
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
- CVE-2026-41092HIGHCVSS 7.8EG 7.82026-06-09
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.
- CVE-2026-41100MEDIUMCVSS 4.4EG 4.42026-05-12
Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
- CVE-2026-41101HIGHCVSS 7.1EG 7.12026-05-12
Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.
- CVE-2026-41102HIGHCVSS 7.1EG 7.12026-05-12
Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.
- CVE-2026-41123MEDIUMCVSS 4.3EG 4.32026-07-03
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access…
- CVE-2026-41160MEDIUMCVSS 4.3EG 4.32026-05-28
EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business logic flaw (Broken Access Control) in EspoCRM 9.3.3 allows low-privileged users to pin arbitrary notes without having the required edit perm…
- CVE-2026-41166HIGHCVSS 7.0EG 7.02026-04-22
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak realm roles for users in another realm, including `master`. T…
- CVE-2026-41243MEDIUMCVSS 5.4EG 5.42026-04-23
OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `safeMode` is enabled, unapproved forum posts are hidden from the public list, but the direct post-read procedure still ret…
- CVE-2026-41270HIGHCVSS 7.1EG 7.12026-04-23
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) protection bypass vulnerability exists in the Custom Function feature. While the application impl…
- CVE-2026-41277HIGHCVSS 8.8EG 8.82026-04-23
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated users to control the primary key (id) and …
- CVE-2026-41487MEDIUMCVSS 5.4EG 5.42026-05-08
Langfuse is an open source large language model engineering platform. From version 3.68.0 to before version 3.167.0, there is a role-based-access control flaw in the LLM connection update flow. An authenticated, low-privileged user of rol…
- CVE-2026-41491HIGHCVSS 8.1EG 8.12026-05-08
Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3.0 to before 1.15.14, 1.16.0-rc.1 to before 1.16.14, and 1.17.0-rc.1 to before 1.17.5, a vulnerability has been found i…
- CVE-2026-41614MEDIUMCVSS 6.2EG 6.22026-05-12
Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
- CVE-2026-41641HIGHCVSS 7.2EG 7.22026-05-07
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the checkSQL() validation function that blocks dangerous SQL keywords (e.g., pg_read_file, LOAD_FILE,…
- CVE-2026-41646MEDIUMCVSS 5.5EG 5.52026-05-08
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScript protocol runtime allows JavaScript templates to read local .js and .json files through t…
- CVE-2026-41704MEDIUMCVSS 5.0EG 5.02026-05-27
AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every response, which reads response['value']['result']['compile_log_id'] (line 332-338) and passes it to download_and_delete_b…
- CVE-2026-41728HIGHCVSS 7.5EG 7.52026-06-10
Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 through…
- CVE-2026-4180HIGHCVSS 9.8EG 7.32026-03-16
A vulnerability was identified in D-Link DIR-816 1.10CNB05. The impacted element is an unknown function of the file redirect.asp of the component goahead. The manipulation of the argument token_id leads to improper access controls. The att…
- CVE-2026-41837MEDIUMCVSS 5.3EG 5.32026-06-10
Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0 t…
- CVE-2026-41847MEDIUMCVSS 5.3EG 5.32026-06-09
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.
- CVE-2026-41856HIGHCVSS 7.5EG 7.52026-06-11
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When a…
- CVE-2026-41900HIGHCVSS 8.8EG 8.82026-05-08
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was identified in the OpenLearnX code execution environment, allowing sandbox escape and arbi…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →