CWE-284: Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

1,295
Total CVEs
213
Critical
547
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
121
2025
669
2024
305
2023
121
2022
36

Top Affected Vendors

1 Microsoft 84
2 Apple 79
3 Oracle 57
4 Intel 32
5 Cisco 21
6 Adobe 20
7 Dell 19
8 Fabian 17
9 Mattermost 12
10 Campcodes 11

All Improper Access Control CVEs (1,295)

CVE-2026-2768
10.0

This CVE describes a sandbox escape vulnerability in Firefox's IndexedDB storage component. Attackers could potentially break out of browser security ...

Feb 24, 2026
CVE-2026-21636
10.0

A critical vulnerability in Node.js v25's experimental permission model allows attacker-controlled inputs to bypass network restrictions and connect t...

Jan 20, 2026
CVE-2026-0881
10.0

This CVE describes a sandbox escape vulnerability in the Messaging System component of Firefox and Thunderbird. Attackers can potentially execute arbi...

Jan 13, 2026
CVE-2025-54339
10.0

An incorrect access control vulnerability in Desktop Alert PingAlert application server versions 6.1.0.11 to 6.1.1.2 allows remote attackers to escala...

Nov 14, 2025
CVE-2024-22216
10.0

This vulnerability allows unauthorized access to Microchip maxView Storage Manager's Redfish server, enabling attackers to modify data and disclose se...

Jan 8, 2024
CVE-2021-34795
10.0

This critical vulnerability in Cisco Catalyst PON Series Switches ONT web management interface allows unauthenticated remote attackers to log in with ...

Nov 4, 2021
CVE-2021-40113
10.0

Multiple vulnerabilities in Cisco Catalyst PON Series Switches ONT web management interface allow unauthenticated remote attackers to log in with defa...

Nov 4, 2021
CVE-2021-38454
10.0

A path traversal vulnerability in Moxa MXview Network Management software allows attackers to create or overwrite critical system files, potentially l...

Oct 12, 2021
CVE-2020-12030
10.0

This vulnerability in industrial control system gateways disables the internal firewall when VLAN features are enabled, exposing all gateway ports to ...

Sep 29, 2021
CVE-2026-24740
9.9

This vulnerability in Dozzle allows users restricted by label filters to bypass container isolation and obtain interactive root shells in out-of-scope...

Jan 27, 2026
CVE-2025-70982
9.9

CVE-2025-70982 is an improper access control vulnerability in SpringBlade v4.5.0 that allows attackers with low-level privileges to import sensitive u...

Jan 26, 2026
CVE-2025-70983
9.9

This vulnerability allows attackers with low-level privileges to escalate their privileges in SpringBlade v4.5.0 due to incorrect access control in th...

Jan 23, 2026
CVE-2026-24304
9.9

This critical vulnerability in Azure Resource Manager allows authenticated attackers to escalate privileges within Azure environments. Attackers with ...

Jan 23, 2026
CVE-2025-48983
9.9

This critical vulnerability in Veeam Backup & Replication's Mount service allows authenticated domain users to execute arbitrary code on backup infras...

Oct 31, 2025
CVE-2025-60306
9.9

Simple Car Rental System 1.0 has a session permission bypass vulnerability that allows low-privilege users to forge high-privilege sessions and perfor...

Oct 10, 2025
CVE-2024-39327
9.9

This vulnerability in Atos Eviden IDRA (Identity and Access Management solution) allows attackers to bypass access controls and illegitimately obtain ...

Feb 18, 2025
CVE-2023-29130
9.9

CVE-2023-29130 is a critical privilege escalation vulnerability in Siemens SIMATIC CN 4100 devices where improper access controls in configuration fil...

Jul 11, 2023
CVE-2022-20777
9.9

This critical vulnerability in Cisco Enterprise NFV Infrastructure Software allows attackers to escape from guest virtual machines to the host system,...

May 4, 2022
CVE-2022-20780
9.9

This vulnerability in Cisco Enterprise NFV Infrastructure Software allows attackers to escape from guest virtual machines to the host system, execute ...

May 4, 2022
CVE-2021-25320
9.9

This CVE-2021-25320 vulnerability in Rancher allows authenticated users within a cluster to access cloud provider credentials by making requests with ...

Jul 15, 2021
CVE-2026-27975
9.8

CVE-2026-27975 is an unauthenticated remote code execution vulnerability in Ajenti server admin panel. Attackers can execute arbitrary code on servers...

Feb 26, 2026
CVE-2026-2550
9.8

This vulnerability allows remote attackers to upload arbitrary files without restrictions to EFM iptime A6004MX routers via the commit_vpncli_file_upl...

Feb 16, 2026
CVE-2025-8025
9.8

This vulnerability allows unauthenticated attackers to access critical functions in Dinosoft ERP without proper authentication or access controls. Att...

Feb 11, 2026
CVE-2026-24300
9.8

This critical vulnerability in Azure Front Door allows attackers to bypass authentication and authorization controls, potentially gaining unauthorized...

Feb 5, 2026
CVE-2026-24306
9.8

CVE-2026-24306 is an improper access control vulnerability in Azure Front Door that allows unauthorized attackers to elevate privileges over a network...

Jan 22, 2026
CVE-2025-65276
9.8

This vulnerability allows unauthenticated attackers to directly access the administrative dashboard of HashTech without credentials, granting full adm...

Nov 26, 2025
CVE-2025-63218
9.8

This vulnerability allows unauthenticated remote attackers to completely compromise Axel Technology WOLF1MS and WOLF2MS devices by accessing the /cgi-...

Nov 19, 2025
CVE-2025-63225
9.8

The Eurolab ELTS100_UBX device with firmware ELTS100v1.UBX has critical administrative endpoints that lack any authentication. Attackers can remotely ...

Nov 18, 2025
CVE-2025-63353
9.8

This vulnerability allows attackers to predict the default Wi-Fi password on FiberHome GPON ONU HG6145F1 routers by observing the SSID, using a determ...

Nov 12, 2025
CVE-2025-63666
9.8

The Tenda AC15 router firmware exposes password hashes in authentication cookies and uses weak session identifiers, allowing attackers to steal and re...

Nov 12, 2025
CVE-2025-43027
9.8

A critical vulnerability in the ALPR Manager role of Genetec Security Center allows attackers to gain administrative access to the system. This affect...

Oct 30, 2025
CVE-2025-27258
9.8

Ericsson Network Manager (ENM) versions before 25.1 GA contain an improper access control vulnerability that allows attackers to escalate privileges. ...

Oct 13, 2025
CVE-2025-57266
9.8

This vulnerability allows unauthenticated attackers to access sensitive information like API keys through the /api/assistant/list endpoint in ThriveX ...

Sep 29, 2025
CVE-2025-50900
9.8

This vulnerability in rebuild 4.0.4 allows unauthenticated attackers to bypass authentication by manipulating URL paths. Attackers can access sensitiv...

Aug 25, 2025
CVE-2025-29514
9.8

This vulnerability allows unauthenticated attackers to download the configuration file of D-Link DSL-7740C routers by sending a specially crafted web ...

Aug 25, 2025
CVE-2024-53496
9.8

This vulnerability allows unauthenticated attackers to bypass access controls in my-site v1.0.2.RELEASE, potentially accessing sensitive components wi...

Aug 22, 2025
CVE-2025-53763
9.8

An improper access control vulnerability in Azure Databricks allows unauthorized attackers to elevate privileges remotely. This affects organizations ...

Aug 21, 2025
CVE-2024-57155
9.8

CVE-2024-57155 is an authentication bypass vulnerability in radar v1.0.8 that allows attackers to access sensitive APIs without valid authentication t...

Aug 20, 2025
CVE-2024-57154
9.8

This vulnerability allows unauthenticated attackers to bypass authentication in dts-shop v0.0.1-SNAPSHOT by sending a crafted payload to the /admin/au...

Aug 20, 2025
CVE-2025-50870
9.8

Institute-of-Current-Students 1.0 has an access control vulnerability in the mydetailsstudent.php endpoint that allows attackers to retrieve any stude...

Aug 1, 2025
CVE-2025-43232
9.8

This CVE describes a permissions vulnerability in macOS that allows applications to bypass certain Privacy preferences. Attackers could potentially ac...

Jul 30, 2025
CVE-2025-43192
9.8

This CVE describes a configuration bypass vulnerability in macOS that allows account-driven User Enrollment even when Lockdown Mode is enabled. This a...

Jul 30, 2025
CVE-2025-43194
9.8

This CVE describes a macOS vulnerability where an application can bypass file system protections and modify restricted areas. It affects macOS Ventura...

Jul 30, 2025
CVE-2025-43198
9.8

This vulnerability allows malicious applications to bypass macOS security protections and access sensitive user data they shouldn't have permission to...

Jul 30, 2025
CVE-2025-30133
9.8

This vulnerability allows attackers to bypass the pairing/registration requirement on IROAD Dashcam FX2 devices by connecting to the dashcam's Wi-Fi n...

Jul 28, 2025
CVE-2025-44654
9.8

This vulnerability in Linksys E2500 routers with vsftpd configuration allows attackers to bypass chroot restrictions and access system files. Attacker...

Jul 21, 2025
CVE-2023-47031
9.8

This vulnerability allows remote attackers to escalate privileges in NCR Terminal Handler v1.5.1 by sending crafted POST requests to specific SOAP API...

Jun 23, 2025
CVE-2023-47297
9.8

A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands with elevated privileges, includin...

Jun 23, 2025
CVE-2024-57190
9.8

CVE-2024-57190 is an authentication bypass vulnerability in Erxes that allows attackers to impersonate any user by sending a malicious HTTP header. Th...

Jun 10, 2025
CVE-2025-45343
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda W18E routers by exploiting improper access control in the account module...

May 28, 2025

About Improper Access Control (CWE-284)

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Our database tracks 1,295 CVEs classified as CWE-284, with 213 rated critical and 547 rated high severity. The average CVSS score for Improper Access Control vulnerabilities is 7.2.

External reference: View CWE-284 on MITRE CWE →

Monitor Improper Access Control Vulnerabilities

Get alerted when new Improper Access Control CVEs affect your infrastructure.

Start Monitoring Free