CWE-284
Improper Access Control
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 50 of 112- CVE-2026-47200—EPSS 0%2 h ago
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, when experime
npm - CVE-2026-53520Medium· 6.58 h ago
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing. Thi
- CVE-2025-24165Medium· 5.5EPSS 0%8 h ago
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.
- CVE-2026-44783Medium· 5.4EPSS 0%9 h ago
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a flaw in how replies to whisper posts are handled allows authent
- CVE-2026-20259Medium· 5.5EPSS 0%11 h ago
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131, a user who holds a Splunk role that contains the high-pri
- CVE-2026-49161High· 7.8EPSS 0%11 h ago
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
- CVE-2026-46695—EPSS 0%11 h ago
BoxLite: Permission Bypass Allows Modification of Read-Only Files
pypinpmgocrates.io - CVE-2026-44249—EPSS 0%11 h ago
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
maven - CVE-2026-53982Medium· 6.511 h ago
Capgo Console prior to 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker to block authentication and onboarding functions by triggering account deletion while a device identifier is link
- CVE-2026-11459Low· 3.3EPSS 0%12 h ago
A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. Impacted is an unknown function in the library saappctl.sys of the component IOCTL Handler. The manipulation leads to information disclosure. Local access is r
- CVE-2023-38205High· 7.5KEVEPSS 94%14 h ago
Adobe ColdFusion Improper Access Control Vulnerability
- CVE-2025-24989High· 8.2KEVEPSS 32%14 h ago
Microsoft Power Pages Improper Access Control Vulnerability
- CVE-2016-8735Critical· 9.8KEVEPSS 94%14 h ago
Apache Tomcat Remote Code Execution Vulnerability
- CVE-2021-22941Critical· 9.8KEVEPSS 88%14 h ago
Citrix ShareFile Improper Access Control Vulnerability
- CVE-2023-23752Medium· 5.3KEVEXPLOITEPSS 95%14 h ago
Joomla! Improper Access Control Vulnerability
- CVE-2016-3393High· 7.8KEVEPSS 56%14 h ago
Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability
- CVE-2015-1427Critical· 9.8KEVEXPLOITEPSS 92%14 h ago
Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
- CVE-2021-23874High· 8.2KEVEPSS 1%14 h ago
McAfee Total Protection (MTP) Improper Privilege Management Vulnerability
- CVE-2019-1653High· 7.5KEVEXPLOITEPSS 94%14 h ago
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
- CVE-2023-27350Critical· 9.8KEVEXPLOITEPSS 94%14 h ago
PaperCut MF/NG Improper Access Control Vulnerability
- CVE-2023-26360High· 8.6KEVEXPLOITEPSS 94%14 h ago
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
- CVE-2025-31125Medium· 5.3KEVEPSS 83%14 h ago
Vite Vitejs Improper Access Control Vulnerability
- CVE-2016-7256High· 8.8KEVEPSS 56%14 h ago
Microsoft Windows Open Type Font Remote Code Execution Vulnerability
- CVE-2014-3120High· 8.1KEVEXPLOITEPSS 85%14 h ago
Elasticsearch Remote Code Execution Vulnerability
- CVE-2016-3715Medium· 5.5KEVEXPLOITEPSS 89%14 h ago
ImageMagick Arbitrary File Deletion Vulnerability
- CVE-2025-12480Critical· 9.1KEVEPSS 80%14 h ago
Gladinet Triofox Improper Access Control Vulnerability
- CVE-2024-45519Critical· 10.0KEVEPSS 94%14 h ago
Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability
- CVE-2023-7028Critical· 10.0KEVEXPLOITEPSS 93%14 h ago
GitLab Community and Enterprise Editions Improper Access Control Vulnerability
- CVE-2026-35616Critical· 9.8KEVEPSS 36%14 h ago
Fortinet FortiClient EMS Improper Access Control Vulnerability
- CVE-2025-59230High· 7.8KEVEPSS 4%14 h ago
Microsoft Windows Improper Access Control Vulnerability
- CVE-2023-29298High· 7.5KEVEPSS 94%14 h ago
Adobe ColdFusion Improper Access Control Vulnerability
- CVE-2024-27348Critical· 9.8KEVEXPLOITEPSS 94%14 h ago
Apache HugeGraph-Server Improper Access Control Vulnerability
- CVE-2020-8193Medium· 6.5KEVEPSS 94%14 h ago
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability
- CVE-2024-40766Critical· 9.8KEVEPSS 3%14 h ago
SonicWall SonicOS Improper Access Control Vulnerability
- CVE-2020-8196Medium· 4.3KEVEPSS 68%14 h ago
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
- CVE-2022-23134Low· 3.7KEVEPSS 93%14 h ago
Zabbix Frontend Improper Access Control Vulnerability
- CVE-2020-2506High· 7.3KEVEPSS 18%14 h ago
QNAP Helpdesk Improper Access Control Vulnerability
- CVE-2016-4437Critical· 9.8KEVEXPLOITEPSS 94%14 h ago
Apache Shiro Code Execution Vulnerability
- CVE-2024-20767High· 7.4KEVEXPLOITEPSS 94%14 h ago
Adobe ColdFusion Improper Access Control Vulnerability
- CVE-2023-24489Critical· 9.8KEVEPSS 94%14 h ago
Citrix Content Collaboration ShareFile Improper Access Control Vulnerability
- CVE-2025-33073High· 8.8KEVEXPLOITEPSS 44%14 h ago
Microsoft Windows SMB Client Improper Access Control Vulnerability
- CVE-2026-44976—EPSS 0%14 h ago
Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue has been patched in version 16.17.4.
- CVE-2026-44208—EPSS 0%14 h ago
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "submit_discussion()" endpoint allows for unauthorized access to resources. This issue has been patched in versions 15.107.
- CVE-2026-47182—EPSS 0%14 h ago
Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private files by guessing the file path. This issue has been patched in version 16.17.4.
- CVE-2026-47366High· 7.2EPSS 0%15 h ago
Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in pr
- CVE-2026-41856High· 7.5EPSS 0%16 h ago
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When al
- CVE-2025-43339Medium· 5.5EPSS 0%18 h ago
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to access sensitive user data.
- CVE-2025-46308Medium· 5.3EPSS 0%18 h ago
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to leak sensitive user information.
- CVE-2025-46315High· 7.5EPSS 0%18 h ago
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data.
- CVE-2026-48610High· 8.1EPSS 0%1 d ago
Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.