On this page
CWE-284: Improper Access Control
Weakness Summary
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- Canonical source: MITRE CWE-284 (opens in a new tab)
- Published Atomicorp CVE observations: 51
- Distinct affected products in those observations: 45
- Active Atomicorp rules associated with this weakness: 55
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2026-34234 | CtrlPanel: Unauthenticated RCE using installer script | panel | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-48907 | Joomla! JCE extension < 2.9.99.5 unauthenticated RCE | jce | Attack Blocked by Atomicorp | 333360 , 383871 |
| CVE-2026-54745 | Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENAB | pipelines | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022 |
| CVE-2014-9148 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | Attack Blocked by Atomicorp | 340007 , 340156 , 341145 , 344360 , 380026 , 380122 , 390709 , 390720 , 390726 , 392647 |
| CVE-2019-2729 | Oracle WebLogic Server Administration Console - Remote Code Execution | communications diameter signaling router | Attack Blocked by Atomicorp | 344361 , 344370 , 393655 |
| CVE-2021-24215 | Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access Control & Privilege Escalation | controlled admin access | Detected by Atomicorp | 377360 |
| CVE-2023-27350 | PaperCut - Unauthenticated Remote Code Execution | papercut mf | Attack Blocked by Atomicorp | 390727 , 392648 |
| CVE-2024-27348 | Apache HugeGraph-Server - Remote Command Execution | hugegraph | Attack Blocked by Atomicorp | 380026 |
| CVE-2026-35616 | FortiClient EMS - Authentication Bypass | forticlient ems | Attack Blocked by Atomicorp | 392301 |
| CVE-2026-65760 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0 | Easy Store extension for Joomla | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-43945 | FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection | FUXA | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2015-0104 | IBM Tivoli Service Automation Manager 7.2.4 - Remote Code Execution | change and configuration management database | Attack Blocked by Atomicorp | 392301 |
| CVE-2018-5406 | KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities | kace systems management appliance firmware | Attack Blocked by Atomicorp | 390727 , 392301 , 392648 |
| CVE-2023-0916 | Auto Dealer Management System 1.0 - Broken Access Control Exploit | auto dealer management system | Detected by Atomicorp | 345493 |
| CVE-2023-4169 | Ruijie RG-EW1200G Router - Password Reset | rg-ew1200g firmware | Attack Blocked by Atomicorp | 392301 |
| CVE-2026-65759 | Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 | Easy Store extension for Joomla | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2023-26360 | Adobe ColdFusion - Local File Read | coldfusion | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2026-73664 | FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module | backup | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-39364 | Vite Dev Server - Directory Traversal | vite | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2014-3120 | ElasticSearch v1.1.1/1.2 RCE | elasticsearch | Attack Blocked by Atomicorp | 344360 , 344370 , 380026 , 390724 |
| CVE-2015-1000010 | WordPress Simple Image Manipulator < 1.0 - Local File Inclusion | simple-image-manipulator | Attack Blocked by Atomicorp | 337473 , 344360 , 347009 , 390709 |
| CVE-2025-30208 | Vite - Arbitrary File Read | vite | Attack Blocked by Atomicorp | 347009 , 390709 |
| CVE-2025-31125 | Vite Development Server - Path Traversal | vite | Attack Blocked by Atomicorp | 347009 , 390709 , 390716 |
| CVE-2025-28367 | mojoPortal <=2.9.0.1 - Directory Traversal | mojoportal | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2025-14528 | D-Link DIR-803 - Authentication Bypass | dir-803 firmware | Attack Blocked by Atomicorp | 390722 |
| CVE-2026-11474 | Kushan2k student-management-system Registration Endpoint RegisterService.php unrestricted upload | student-management-system | Attack Blocked by Atomicorp | 351000 , 393655 |
| CVE-2026-18788 | Trippo ResponsiveFilemanager dialog.php unrestricted upload | ResponsiveFilemanager | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-5573 | Technostrobe HI-LED-WR120-G2 fs unrestricted upload | hi-led-wr120-g2 firmware | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-78202 | itsourcecode Payroll System admin_class.php save_settings unrestricted upload | Payroll System | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-78245 | itsourcecode Online Pharmacy System User Registration register.php move_uploaded_file unrestricted upload | Online Pharmacy System | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-85208 | itsourcecode Online Medicine Delivery System Order Management Controller controller.php doInsert unrestricted upload | Online Medicine Delivery System | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-86239 | liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload | FeehiCMS | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-86305 | light0011 cms Upload.class.php upload unrestricted upload | cms | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-86666 | aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload | iWebShop-5 | Attack Blocked by Atomicorp | 351000 |
| CVE-2014-8677 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | Attack Blocked by Atomicorp | 331028 , 340016 , 340017 , 340144 , 340155 , 340156 , 340157 , 340159 , 341155 , 341245 , 344363 , 344370 , 360147 , 360148 , 360153 , 390726 , 392647 |
| CVE-2025-31486 | Vite server.fs.deny Bypass - Local File Inclusion | vite | Attack Blocked by Atomicorp | 347009 , 390709 |
| CVE-2024-14046 | OpenBoxes Document Upload Controller DocumentController.groovy DocumentController unrestricted upload | OpenBoxes | Attack Blocked by Atomicorp | 351000 |
| CVE-2025-13815 | moxi159753 Mogu Blog v2 pictures unrestricted upload | mogublog | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-10172 | Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted upload | Multi-Store Inventory Management System | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-10806 | mjperpinosa stumasy add_post.php unrestricted upload | stumasy | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-10807 | mjperpinosa stumasy change_profile_image.php unrestricted upload | stumasy | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-16451 | zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted upload | ZS-Admin | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-19210 | SourceCodester Photo Share Website ajax.php save_upload unrestricted upload | Photo Share Website | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-77681 | CodeAstro Online Job Portal update-profile.php unrestricted upload | Online Job Portal | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-82679 | diem-project diem Widget Editor dmWidgetContentBaseMediaForm.php unrestricted upload | diem | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-85186 | itsourcecode Online Medicine Delivery System Customer Controller controller.php doupdateimage unrestricted upload | Online Medicine Delivery System | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-19383 | saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted upload | SaiAdmin | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-19839 | SourceCodester Simple Doctors Appointment System save_file.php save_doctor unrestricted upload | Simple Doctors Appointment System | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-5576 | SourceCodester/jkev Record Management System Add Employee save_emp.php unrestricted upload | Record Management System | Attack Blocked by Atomicorp | 340156 , 341245 , 351000 , 390501 |
| CVE-2026-76995 | SourceCodester Simple Online Food Ordering System ajax.php save_menu unrestricted upload | Simple Online Food Ordering System | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-82629 | jeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwid3Controller.doUpload unrestricted upload | jeewx-boot | Attack Blocked by Atomicorp | 351000 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 331028 | Active | disruptive (deny) |
| 333360 | Active | disruptive (deny) |
| 337109 | Active | disruptive (deny) |
| 337110 | Active | disruptive (deny) |
| 337473 | Active | disruptive (deny) |
| 340007 | Active | disruptive (deny) |
| 340014 | Active | disruptive (deny) |
| 340016 | Active | disruptive (deny) |
| 340017 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340144 | Active | disruptive (deny) |
| 340155 | Active | disruptive (deny) |
| 340156 | Active | disruptive (deny) |
| 340157 | Active | disruptive (deny) |
| 340159 | Active | disruptive (deny) |
| 340162 | Active | disruptive (deny) |
| 340163 | Active | disruptive (deny) |
| 340165 | Active | disruptive (deny) |
| 340193 | Active | disruptive (deny) |
| 341145 | Active | disruptive (deny) |
| 341155 | Active | disruptive (deny) |
| 341245 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344364 | Active | disruptive (deny) |
| 344366 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 345493 | Active | non-disruptive (pass) |
| 347009 | Active | disruptive (deny) |
| 351000 | Active | disruptive (deny) |
| 360147 | Active | disruptive (deny) |
| 360148 | Active | disruptive (deny) |
| 360153 | Active | disruptive (deny) |
| 377360 | Active | non-disruptive (pass) |
| 380026 | Active | disruptive (deny) |
| 380122 | Active | disruptive (deny) |
| 383871 | Active | disruptive (deny) |
| 390501 | Active | disruptive (deny) |
| 390709 | Active | disruptive (deny) |
| 390716 | Active | disruptive (deny) |
| 390720 | Active | disruptive (deny) |
| 390722 | Active | disruptive (deny) |
| 390724 | Active | disruptive (deny) |
| 390726 | Active | disruptive (deny) |
| 390727 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 392647 | Active | disruptive (deny) |
| 392648 | Active | disruptive (deny) |
| 393655 | Active | disruptive (deny) |
| 398001 | Active | non-disruptive (pass) |
| 398008 | Active | non-disruptive (pass) |
| 398021 | Active | disruptive (deny) |
| 398022 | Active | disruptive (deny) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:
CAPEC-19 (opens in a new tab) , CAPEC-441 (opens in a new tab) , CAPEC-478 (opens in a new tab) , CAPEC-479 (opens in a new tab) , CAPEC-502 (opens in a new tab) , CAPEC-503 (opens in a new tab) , CAPEC-536 (opens in a new tab) , CAPEC-546 (opens in a new tab) , CAPEC-550 (opens in a new tab) , CAPEC-551 (opens in a new tab) , CAPEC-552 (opens in a new tab) , CAPEC-556 (opens in a new tab) , CAPEC-558 (opens in a new tab) , CAPEC-562 (opens in a new tab) , CAPEC-563 (opens in a new tab) , CAPEC-564 (opens in a new tab) , CAPEC-578 (opens in a new tab)