CWE-284Pillar25 in KEV

Improper Access Control

Incomplete in the CWE catalog · 4,853 CVEs mapped

4,853
CVEs mapped
25
In KEV
6.9
Median CVSS
What it is

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Recent examples
5.3cvss
CVE-2026-86239

liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload

A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

MEDIUMno explanation yet
epss
4.3cvss
CVE-2026-86228

JeecgBoot AiragModelController.java exportXls access control

A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the argument credential leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 3.9.5 is able to resolve this issue. The name of the patch is a2be896f753936956ee6863b632b8e5a0231345c. You should upgrade the affected component.

MEDIUMno explanation yet
epss
5.3cvss
CVE-2026-86217

code-projects Hotel and Tourism Reservation in PHP Database Backup hotel_db%20(1).sql information disclosure

A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used.

MEDIUMno explanation yet
epss
The record
Technical detail
CWE ID
CWE-284
Abstraction
Pillar
Structure
Simple
Status
Incomplete
References (3)