Skip to main content

About CWE-284

MITRE lists the consequence as varying by context. When any access control mechanism fails, attackers may gain privileges, read sensitive information, execute commands or evade detection.

MITRE marks CWE-284 as DISCOURAGED for mapping real-world vulnerabilities because it is a Pillar; descendants such as CWE-862 or CWE-863 are suggested.

MITRE name
Improper Access Control
Abstraction
Pillar: the highest-level weakness, which cannot be made more abstract
Status
Incomplete
Also known as
Authorization

Mitigations

  • +Manage the setting and handling of privileges carefully and define trust zones explicitly.
  • +Compartmentalize the system so trust boundaries are unambiguous and sensitive data does not leave them.
  • +Apply the principle of least privilege when deciding when to use and when to drop privileges.
  • +Map findings to a specific descendant such as Missing Authorization (CWE-862) or Incorrect Authorization (CWE-863).

CWE-284 Vulnerabilities

23 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-81963
Windows Update Stack Elevation of Privilege Vulnerability
Microsoft7.80.4%KEV2026-09-08
CVE-2026-34908
Ubiquiti UniFi OS Improper Access Control Vulnerability
Ubiquiti Inc10.015.2%KEV2026-05-22
CVE-2026-48907
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
joomlacontenteditor.net10.016.2%KEV2026-06-05
CVE-2026-35616
Fortinet FortiClient EMS Improper Access Control Vulnerability
Fortinet9.19.1%KEV2026-04-04
CVE-2025-31125
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
vitejs5.365.2%KEV2025-03-31
CVE-2025-12480
Gladinet Triofox Improper Access Control Vulnerability
TrioFox9.195.4%KEV2025-11-10
CVE-2025-33073
Windows SMB Client Elevation of Privilege Vulnerability
Microsoft8.882.7%KEV2025-06-10
CVE-2025-59230
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Microsoft7.82.7%KEV2025-10-14
CVE-2025-24989
Microsoft Power Pages Elevation of Privilege Vulnerability
Microsoft8.21.6%KEV2025-02-19
CVE-2024-20767
ColdFusion | Improper Access Control (CWE-284)
Adobe7.498.5%KEV2024-03-18
CVE-2024-40766
SonicWall SonicOS Improper Access Control Vulnerability
SonicWall9.318.4%KEV2024-08-23
CVE-2023-24489
Citrix Content Collaboration ShareFile Improper Access Control Vulnerability
Citrix9.897.3%KEV2023-07-10
CVE-2023-29298
Adobe ColdFusion Improper Access Control Security feature bypass
Adobe7.599.8%KEV2023-07-12
CVE-2023-38205
ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298
Adobe7.599.8%KEV2023-09-14
CVE-2023-27350
PaperCut MF/NG Improper Access Control Vulnerability
PaperCut9.8100.0%KEV2023-04-20
CVE-2023-26360
Adobe ColdFusion Improper Access Control Arbitrary code execution
Adobe8.697.3%KEV2023-03-23
CVE-2021-22941
Citrix ShareFile Improper Access Control Vulnerability
-9.853.6%KEV2021-09-23
CVE-2020-2506
improper access control vulnerability in Helpdesk
QNAP Systems Inc.7.32.0%KEV2021-02-03
CVE-2022-23134
Possible view of the setup pages by unauthenticated users if config file already exists
Zabbix3.795.3%KEV2022-01-13
CVE-2019-1653
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
Cisco7.599.9%KEV2019-01-24
CVE-2020-8193
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability
-6.588.4%KEV2020-07-10
CVE-2020-8196
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
-4.326.3%KEV2020-07-10
CVE-2026-33478
AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection
WWBN10.011.2%2026-03-23

Frequently Asked Questions

What is CWE-284?→

CWE-284 is MITRE's Pillar for improper access control. It sits above authentication, authorization and permission weaknesses.

Why is CWE-284 discouraged for mapping?→

MITRE calls it extremely high-level and says it is often used in low-information reports. It is not useful for trend analysis, so a more specific descendant should be chosen.

How many exploited vulnerabilities are classified as CWE-284?→

This database lists 23 CVE records mapped to CWE-284 by their CVE Numbering Authority. 22 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 3 to known ransomware campaigns. Examples include CVE-2026-81963, CVE-2026-34908, CVE-2026-48907.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.