CWE-284: Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
3,335 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-56290 — Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
- CVE-2026-48939 — Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
- CVE-2026-48908 — Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
- CVE-2026-35616 — A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta
- CVE-2025-12480 — Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to init
- CVE-2024-20767 — ColdFusion | Improper Access Control (CWE-284)
- CVE-2026-48907 — Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
- CVE-2025-31125 — Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
- CVE-2026-34908 — A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS de
- CVE-2025-27140 — WeGIA vulnerable to OS Command Injection at endpoint 'importar_dump.php' parameter 'import' (RCE)
- CVE-2026-65182 — Apache Tomcat: Bypass longest prefix security constraint
- CVE-2026-33478 — AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection
- CVE-2026-32760 — File Browser Self Registration Grants Any User Admin Access When Default Permissions Include Admin
- CVE-2026-30966 — Parse Server role escalation and CLP bypass via direct `_Join` table write
- CVE-2026-27591 — Winter: Privilege escalation by authenticated backend users
- CVE-2026-2550 — EFM iptime A6004MX timepro.cgi commit_vpncli_file_upload unrestricted upload
- CVE-2025-26617 — SQL Injection endpoint 'historico_paciente.php' parameter 'id_fichamedica' in WeGIA
- CVE-2025-26616 — Path Traversal endpoint 'exportar_dump.php' parameter 'file' in WeGIA
- CVE-2025-26615 — Path Traversal endpoint 'examples.php' parameter 'src' in WeGIA
- CVE-2025-26613 — OS Command Injection endpoint 'gerenciar_backup.php' parameter 'file' (RCE) in WeGIA
Recently published
- CVE-2026-86774 — Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy
- CVE-2026-19625 — IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities
- CVE-2026-75998 — ColdFusion | Improper Access Control (CWE-284)
- CVE-2026-86672 — ningzichun Student Management System Backup example.7z information disclosure
- CVE-2026-22575 — An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10
- CVE-2026-26084 — A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8,
- CVE-2026-84385 — A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5
- CVE-2026-86666 — aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload
- CVE-2026-86519 — code-projects Student Crud Operation Backup File card_activation.sql information disclosure
- CVE-2026-86512 — java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply access control
- CVE-2026-86308 — light0011 cms Debug Mode config.php information disclosure
- CVE-2026-86305 — light0011 cms Upload.class.php upload unrestricted upload
- CVE-2026-86302 — code-projects Hospital Information System SQL Database Backup File his.sql information disclosure
- CVE-2026-86285 — BookStack Attachment Edit Endpoint AttachmentController.php getUpdateForm access control
- CVE-2026-86284 — jaychouchannel Tourism-Management-System CommonController.java getOption information disclosure
- CVE-2026-86272 — Beijing Meite Software Technology U+Smart Enjoyment WebSite UploadFormImg.ashx unrestricted upload
- CVE-2026-86239 — liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload
- CVE-2026-86228 — JeecgBoot AiragModelController.java exportXls access control
- CVE-2026-86217 — code-projects Hotel and Tourism Reservation in PHP Database Backup hotel_db%20(1).sql information disclosure
- CVE-2026-86242 — Unauthenticated RCE via Custom Plugin HTTP Path on Dynamically Linked Builds
More specific weaknesses
- CWE-1191 — On-Chip Debug and Test Interface With Improper Access Control
- CWE-1220 — Insufficient Granularity of Access Control
- CWE-1224 — Improper Restriction of Write-Once Bit Fields
- CWE-1231 — Improper Prevention of Lock Bit Modification
- CWE-1233 — Security-Sensitive Hardware Controls with Missing Lock Bit Protection
- CWE-1252 — CPU Hardware Not Configured to Support Exclusivity of Write and Execute Operations
- CWE-1257 — Improper Access Control Applied to Mirrored or Aliased Memory Regions
- CWE-1259 — Improper Restriction of Security Token Assignment
- CWE-1260 — Improper Handling of Overlap Between Protected Memory Ranges
- CWE-1262 — Improper Access Control for Register Interface
- CWE-1263 — Improper Physical Access Control
- CWE-1267 — Policy Uses Obsolete Encoding
- CWE-1270 — Generation of Incorrect Security Tokens
- CWE-1274 — Improper Access Control for Volatile Memory Containing Boot Code
- CWE-1276 — Hardware Child Block Incorrectly Connected to Parent System
- CWE-1283 — Mutable Attestation or Measurement Reporting Data
- CWE-1290 — Incorrect Decoding of Security Identifiers
- CWE-1292 — Incorrect Conversion of Security Identifiers
- CWE-1294 — Insecure Security Identifier Mechanism
- CWE-1296 — Incorrect Chaining or Granularity of Debug Components
- CWE-1304 — Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation
- CWE-1311 — Improper Translation of Security Attributes by Fabric Bridge
- CWE-1312 — Missing Protection for Mirrored Regions in On-Chip Fabric Firewall
- CWE-1313 — Hardware Allows Activation of Test or Debug Logic at Runtime
- CWE-1315 — Improper Setting of Bus Controlling Capability in Fabric End-point
- CWE-1316 — Fabric-Address Map Allows Programming of Unwarranted Overlaps of Protected and Unprotected Ranges
- CWE-1317 — Improper Access Control in Fabric Bridge
- CWE-1320 — Improper Protection for Outbound Error Messages and Alert Signals
- CWE-1323 — Improper Management of Sensitive Trace Data
- CWE-1334 — Unauthorized Error Injection Can Degrade Hardware Redundancy
- CWE-269 — Improper Privilege Management
- CWE-282 — Improper Ownership Management
- CWE-285 — Improper Authorization
- CWE-286 — Incorrect User Management
- CWE-287 — Improper Authentication
- CWE-749 — Exposed Dangerous Method or Function
- CWE-923 — Improper Restriction of Communication Channel to Intended Endpoints