CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
7,380 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 84 of 148
- CVE-2025-56405HIGHCVSS 7.5EG 7.52025-09-10
An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP service through the SSE protocol.
- CVE-2025-56406HIGHCVSS 7.5EG 7.52025-09-10
An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE: the Supplier's position is that authentication is not mandatory for MCP servers, and the…
- CVE-2025-5649MEDIUMCVSS 6.5EG 6.52025-06-05
A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /admin/core/new_user of the component Register Interface. The manipulation leads to impr…
- CVE-2025-56499MEDIUMCVSS 6.5EG 6.52025-11-18
Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key from the config file.
- CVE-2025-57130HIGHCVSS 8.8EG 8.82025-11-05
An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, authenticated attacker to escalate their privileges. By sending a specially crafted HTTP request, a low-privilege user ca…
- CVE-2025-57197MEDIUMCVSS 6.0EG 6.52025-09-29
In the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for the PIN change feature. A local attacker with root access to the device can dynamically instrument the app to bypass th…
- CVE-2025-57210HIGHCVSS 7.5EG 7.52025-12-04
Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive information via unspecified vectors.
- CVE-2025-57212HIGHCVSS 7.5EG 7.52025-12-04
Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive information via a crafted request.
- CVE-2025-57213HIGHCVSS 7.5EG 7.52025-12-04
Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensitive information via a crafted request.
- CVE-2025-57219MEDIUMCVSS 5.3EG 5.32025-08-28
Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attackers to escalate privileges or access sensitive components via a crafted request.
- CVE-2025-57247CRITICALCVSS 9.1EG 9.12025-10-06
The BATBToken smart contract (address 0xfbf1388408670c02f0dbbb74251d8ded1d63b7a2, Compiler Version v0.8.26+commit.8a97fa7a) contains incorrect access control implementation in whitelist management functions. The setColdWhiteList() and setS…
- CVE-2025-57266CRITICALCVSS 9.8EG 9.82025-09-29
An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthenticated attackers to gain sensitive information such as API Keys via the /api/assistant/list endpoint.
- CVE-2025-5728HIGHCVSS 8.8EG 8.82025-06-06
A vulnerability classified as critical was found in SourceCodester Open Source Clinic Management System 1.0. This vulnerability affects unknown code of the file /manage_website.php. The manipulation of the argument website_image leads to u…
- CVE-2025-57428MEDIUMCVSS 6.5EG 6.52025-09-29
Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port 23 and execute hardware-level flash and register manipulation com…
- CVE-2025-57438MEDIUMCVSS 6.8EG 6.82025-09-22
The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intended to be accessible only after the admin explicitly grants access to a manager-level account. However, a manager-level …
- CVE-2025-57489HIGHCVSS 8.1EG 8.12025-12-01
Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of a setuid binary.
- CVE-2025-57567CRITICALCVSS 9.1EG 9.12025-10-17
A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default theme directory (/themes/defaut/css/minify.php). An authenticated administrator user can overw…
- CVE-2025-57758MEDIUMCVSS 4.3EG 4.32025-08-28
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in the back end doesn't check if a user is allowed to access the corresponding module. This issue has been patched in versi…
- CVE-2025-58055MEDIUMCVSS 4.3EG 4.32025-10-01
Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endpoints for topic “Title”, “Category”, and “Tags” allowed authenticated users to extract information about to…
- CVE-2025-58149HIGHCVSS 7.5EG 7.52025-10-31
When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the device might have. As a result a domain can still have access any 64bit memory BAR when such device is no longer assi…
- CVE-2025-58337MEDIUMCVSS 5.4EG 5.42025-11-05
An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have been prevented by read-only restrictions. Impact: Bypasses read-only mode;…
- CVE-2025-5840HIGHCVSS 7.3EG 7.32025-06-07
A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_update_customer_order.php. The manipulation of the argument uploaded_file …
- CVE-2025-58459MEDIUMCVSS 4.3EG 4.32025-09-03
Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endpoints, allowing attackers with Overall/Read permission to enumerate graph IDs.
- CVE-2025-58714HIGHCVSS 7.8EG 7.82025-10-14
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2025-58724HIGHCVSS 7.8EG 7.82025-10-14
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
- CVE-2025-58726HIGHCVSS 7.5EG 7.52025-10-14
Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
- CVE-2025-5873MEDIUMCVSS 6.3EG 6.32025-06-09
A vulnerability was detected in eCharge Hardy Barth Salia PLCC up to 2.3.81. Affected by this issue is some unknown functionality of the file /firmware.php of the component Web UI. Performing a manipulation of the argument media results in…
- CVE-2025-58751MEDIUMCVSS 5.3EG 5.32025-09-08
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly e…
- CVE-2025-58752MEDIUMCVSS 5.3EG 5.32025-09-08
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server …
- CVE-2025-59199HIGHCVSS 7.8EG 7.82025-10-14
Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.
- CVE-2025-59201HIGHCVSS 7.8EG 7.82025-10-14
Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.
- CVE-2025-59218CRITICALCVSS 9.6EG 9.62025-10-09
Azure Entra ID Elevation of Privilege Vulnerability
- CVE-2025-59230CRITICALCVSS 7.8EG 9.0⚠ KEV2025-10-14
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
- CVE-2025-59253MEDIUMCVSS 5.5EG 5.52025-10-14
Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
- CVE-2025-59273HIGHCVSS 7.3EG 7.32025-10-23
Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-59308MEDIUMCVSS 4.7EG 4.72026-04-24
In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a multi-tenanted site can masquerade as an institution member in an institution for which they are not an administrator, …
- CVE-2025-59333HIGHCVSS 8.1EG 8.12025-09-16
The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-server, fails to implement adequate security controls to properly enforce a "read-only" mode. This vulnerability affects…
- CVE-2025-59422LOWCVSS 3.1EG 3.12025-09-25
Dify is an open-source LLM app development platform. In version 1.8.1, a broken access control vulnerability on the /console/api/apps/<APP_ID>chat-messages?conversation_id=<CONVERSATION_ID>&limit=10 endpoint allows users in the same worksp…
- CVE-2025-59434CRITICALCVSS 9.6EG 9.62025-09-22
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Hosted Flowise, an authenticated vulnerability in Flowise Cloud allows any user on the free tier to access sensitive enviro…
- CVE-2025-59494HIGHCVSS 7.8EG 7.82025-10-14
Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
- CVE-2025-59500HIGHCVSS 7.7EG 7.72025-10-23
Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network.
- CVE-2025-59512HIGHCVSS 7.8EG 7.82025-11-11
Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.
- CVE-2025-59517HIGHCVSS 7.8EG 7.82025-12-09
Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-5962HIGHCVSS 7.7EG 7.72025-09-22
A flaw was found in the Lightspeed history service. Insufficient access controls allow a local, unprivileged user to access and manipulate the chat history of another user on the same system. By abusing inter-process communication calls t…
- CVE-2025-59697HIGHCVSS 7.2EG 7.22025-12-02
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloader configuration…
- CVE-2025-59702HIGHCVSS 7.2EG 7.22025-12-02
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with elevated privileges to falsify tamper events by accessing internal co…
- CVE-2025-59703CRITICALCVSS 9.1EG 9.12025-12-02
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to access the internal components of the appliance, without leaving tamper…
- CVE-2025-59810MEDIUMCVSS 6.5EG 6.52025-12-09
An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiS…
- CVE-2025-59923LOWCVSS 2.7EG 2.72025-12-09
An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker …
- CVE-2025-59932HIGHCVSS 8.6EG 8.62025-09-27
Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authentication or authorization. This could have enabled unauthori…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →