Improper Access Control (CWE-284)
CWE-284 is a Pillar, the top level of MITRE's hierarchy, for products that fail to restrict or wrongly restrict access to a resource. Access control here spans authentication, authorization and accountability. MITRE discourages mapping vulnerabilities to it and points to more specific entries such as CWE-862 and CWE-863.
About CWE-284
MITRE lists the consequence as varying by context. When any access control mechanism fails, attackers may gain privileges, read sensitive information, execute commands or evade detection.
MITRE marks CWE-284 as DISCOURAGED for mapping real-world vulnerabilities because it is a Pillar; descendants such as CWE-862 or CWE-863 are suggested.
Mitigations
- +Manage the setting and handling of privileges carefully and define trust zones explicitly.
- +Compartmentalize the system so trust boundaries are unambiguous and sensitive data does not leave them.
- +Apply the principle of least privilege when deciding when to use and when to drop privileges.
- +Map findings to a specific descendant such as Missing Authorization (CWE-862) or Incorrect Authorization (CWE-863).
CWE-284 Vulnerabilities
23 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack Elevation of Privilege Vulnerability | Microsoft | 7.8 | 0.4% | KEV | 2026-09-08 |
| CVE-2026-34908 | Ubiquiti UniFi OS Improper Access Control Vulnerability | Ubiquiti Inc | 10.0 | 15.2% | KEV | 2026-05-22 |
| CVE-2026-48907 | Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5 | joomlacontenteditor.net | 10.0 | 16.2% | KEV | 2026-06-05 |
| CVE-2026-35616 | Fortinet FortiClient EMS Improper Access Control Vulnerability | Fortinet | 9.1 | 9.1% | KEV | 2026-04-04 |
| CVE-2025-31125 | Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query | vitejs | 5.3 | 65.2% | KEV | 2025-03-31 |
| CVE-2025-12480 | Gladinet Triofox Improper Access Control Vulnerability | TrioFox | 9.1 | 95.4% | KEV | 2025-11-10 |
| CVE-2025-33073 | Windows SMB Client Elevation of Privilege Vulnerability | Microsoft | 8.8 | 82.7% | KEV | 2025-06-10 |
| CVE-2025-59230 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Microsoft | 7.8 | 2.7% | KEV | 2025-10-14 |
| CVE-2025-24989 | Microsoft Power Pages Elevation of Privilege Vulnerability | Microsoft | 8.2 | 1.6% | KEV | 2025-02-19 |
| CVE-2024-20767 | ColdFusion | Improper Access Control (CWE-284) | Adobe | 7.4 | 98.5% | KEV | 2024-03-18 |
| CVE-2024-40766 | SonicWall SonicOS Improper Access Control Vulnerability | SonicWall | 9.3 | 18.4% | KEV | 2024-08-23 |
| CVE-2023-24489 | Citrix Content Collaboration ShareFile Improper Access Control Vulnerability | Citrix | 9.8 | 97.3% | KEV | 2023-07-10 |
| CVE-2023-29298 | Adobe ColdFusion Improper Access Control Security feature bypass | Adobe | 7.5 | 99.8% | KEV | 2023-07-12 |
| CVE-2023-38205 | ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298 | Adobe | 7.5 | 99.8% | KEV | 2023-09-14 |
| CVE-2023-27350 | PaperCut MF/NG Improper Access Control Vulnerability | PaperCut | 9.8 | 100.0% | KEV | 2023-04-20 |
| CVE-2023-26360 | Adobe ColdFusion Improper Access Control Arbitrary code execution | Adobe | 8.6 | 97.3% | KEV | 2023-03-23 |
| CVE-2021-22941 | Citrix ShareFile Improper Access Control Vulnerability | - | 9.8 | 53.6% | KEV | 2021-09-23 |
| CVE-2020-2506 | improper access control vulnerability in Helpdesk | QNAP Systems Inc. | 7.3 | 2.0% | KEV | 2021-02-03 |
| CVE-2022-23134 | Possible view of the setup pages by unauthenticated users if config file already exists | Zabbix | 3.7 | 95.3% | KEV | 2022-01-13 |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability | Cisco | 7.5 | 99.9% | KEV | 2019-01-24 |
| CVE-2020-8193 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability | - | 6.5 | 88.4% | KEV | 2020-07-10 |
| CVE-2020-8196 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability | - | 4.3 | 26.3% | KEV | 2020-07-10 |
| CVE-2026-33478 | AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection | WWBN | 10.0 | 11.2% | 2026-03-23 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-284?→
CWE-284 is MITRE's Pillar for improper access control. It sits above authentication, authorization and permission weaknesses.
Why is CWE-284 discouraged for mapping?→
MITRE calls it extremely high-level and says it is often used in low-information reports. It is not useful for trend analysis, so a more specific descendant should be chosen.
How many exploited vulnerabilities are classified as CWE-284?→
This database lists 23 CVE records mapped to CWE-284 by their CVE Numbering Authority. 22 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 3 to known ransomware campaigns. Examples include CVE-2026-81963, CVE-2026-34908, CVE-2026-48907.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.