On this page

CWE-284: Improper Access Control

Weakness Summary

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

  • Canonical source: MITRE CWE-284 (opens in a new tab)
  • Published Atomicorp CVE observations: 51
  • Distinct affected products in those observations: 45
  • Active Atomicorp rules associated with this weakness: 55

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2026-34234CtrlPanel: Unauthenticated RCE using installer scriptpanelAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-48907Joomla! JCE extension < 2.9.99.5 unauthenticated RCEjceAttack Blocked by Atomicorp333360 , 383871
CVE-2026-54745Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABpipelinesAttack Blocked by Atomicorp337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022
CVE-2014-9148Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cmsAttack Blocked by Atomicorp340007 , 340156 , 341145 , 344360 , 380026 , 380122 , 390709 , 390720 , 390726 , 392647
CVE-2019-2729Oracle WebLogic Server Administration Console - Remote Code Executioncommunications diameter signaling routerAttack Blocked by Atomicorp344361 , 344370 , 393655
CVE-2021-24215Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access Control & Privilege Escalationcontrolled admin accessDetected by Atomicorp377360
CVE-2023-27350PaperCut - Unauthenticated Remote Code Executionpapercut mfAttack Blocked by Atomicorp390727 , 392648
CVE-2024-27348Apache HugeGraph-Server - Remote Command ExecutionhugegraphAttack Blocked by Atomicorp380026
CVE-2026-35616FortiClient EMS - Authentication Bypassforticlient emsAttack Blocked by Atomicorp392301
CVE-2026-65760Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0Easy Store extension for JoomlaAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2026-43945FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration InjectionFUXAAttack Blocked by Atomicorp340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2015-0104IBM Tivoli Service Automation Manager 7.2.4 - Remote Code Executionchange and configuration management databaseAttack Blocked by Atomicorp392301
CVE-2018-5406KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilitieskace systems management appliance firmwareAttack Blocked by Atomicorp390727 , 392301 , 392648
CVE-2023-0916Auto Dealer Management System 1.0 - Broken Access Control Exploitauto dealer management systemDetected by Atomicorp345493
CVE-2023-4169Ruijie RG-EW1200G Router - Password Resetrg-ew1200g firmwareAttack Blocked by Atomicorp392301
CVE-2026-65759Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1Easy Store extension for JoomlaAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2023-26360Adobe ColdFusion - Local File ReadcoldfusionAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2026-73664FreePBX: Authenticated Arbitrary SSH Key Injection via Backup ModulebackupAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-39364Vite Dev Server - Directory TraversalviteAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2014-3120ElasticSearch v1.1.1/1.2 RCEelasticsearchAttack Blocked by Atomicorp344360 , 344370 , 380026 , 390724
CVE-2015-1000010WordPress Simple Image Manipulator < 1.0 - Local File Inclusionsimple-image-manipulatorAttack Blocked by Atomicorp337473 , 344360 , 347009 , 390709
CVE-2025-30208Vite - Arbitrary File ReadviteAttack Blocked by Atomicorp347009 , 390709
CVE-2025-31125Vite Development Server - Path TraversalviteAttack Blocked by Atomicorp347009 , 390709 , 390716
CVE-2025-28367mojoPortal <=2.9.0.1 - Directory TraversalmojoportalAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2025-14528D-Link DIR-803 - Authentication Bypassdir-803 firmwareAttack Blocked by Atomicorp390722
CVE-2026-11474Kushan2k student-management-system Registration Endpoint RegisterService.php unrestricted uploadstudent-management-systemAttack Blocked by Atomicorp351000 , 393655
CVE-2026-18788Trippo ResponsiveFilemanager dialog.php unrestricted uploadResponsiveFilemanagerAttack Blocked by Atomicorp351000
CVE-2026-5573Technostrobe HI-LED-WR120-G2 fs unrestricted uploadhi-led-wr120-g2 firmwareAttack Blocked by Atomicorp351000
CVE-2026-78202itsourcecode Payroll System admin_class.php save_settings unrestricted uploadPayroll SystemAttack Blocked by Atomicorp351000
CVE-2026-78245itsourcecode Online Pharmacy System User Registration register.php move_uploaded_file unrestricted uploadOnline Pharmacy SystemAttack Blocked by Atomicorp351000
CVE-2026-85208itsourcecode Online Medicine Delivery System Order Management Controller controller.php doInsert unrestricted uploadOnline Medicine Delivery SystemAttack Blocked by Atomicorp351000
CVE-2026-86239liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted uploadFeehiCMSAttack Blocked by Atomicorp351000
CVE-2026-86305light0011 cms Upload.class.php upload unrestricted uploadcmsAttack Blocked by Atomicorp351000
CVE-2026-86666aircheng-org iWebShop-5 pic.php uploadFile unrestricted uploadiWebShop-5Attack Blocked by Atomicorp351000
CVE-2014-8677SO Planning 1.32 - Multiple VulnerabilitiessoplanningAttack Blocked by Atomicorp331028 , 340016 , 340017 , 340144 , 340155 , 340156 , 340157 , 340159 , 341155 , 341245 , 344363 , 344370 , 360147 , 360148 , 360153 , 390726 , 392647
CVE-2025-31486Vite server.fs.deny Bypass - Local File InclusionviteAttack Blocked by Atomicorp347009 , 390709
CVE-2024-14046OpenBoxes Document Upload Controller DocumentController.groovy DocumentController unrestricted uploadOpenBoxesAttack Blocked by Atomicorp351000
CVE-2025-13815moxi159753 Mogu Blog v2 pictures unrestricted uploadmogublogAttack Blocked by Atomicorp351000
CVE-2026-10172Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted uploadMulti-Store Inventory Management SystemAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-10806mjperpinosa stumasy add_post.php unrestricted uploadstumasyAttack Blocked by Atomicorp351000
CVE-2026-10807mjperpinosa stumasy change_profile_image.php unrestricted uploadstumasyAttack Blocked by Atomicorp351000
CVE-2026-16451zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted uploadZS-AdminAttack Blocked by Atomicorp351000
CVE-2026-19210SourceCodester Photo Share Website ajax.php save_upload unrestricted uploadPhoto Share WebsiteAttack Blocked by Atomicorp351000
CVE-2026-77681CodeAstro Online Job Portal update-profile.php unrestricted uploadOnline Job PortalAttack Blocked by Atomicorp351000
CVE-2026-82679diem-project diem Widget Editor dmWidgetContentBaseMediaForm.php unrestricted uploaddiemAttack Blocked by Atomicorp351000
CVE-2026-85186itsourcecode Online Medicine Delivery System Customer Controller controller.php doupdateimage unrestricted uploadOnline Medicine Delivery SystemAttack Blocked by Atomicorp351000
CVE-2026-19383saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted uploadSaiAdminAttack Blocked by Atomicorp351000
CVE-2026-19839SourceCodester Simple Doctors Appointment System save_file.php save_doctor unrestricted uploadSimple Doctors Appointment SystemAttack Blocked by Atomicorp351000
CVE-2026-5576SourceCodester/jkev Record Management System Add Employee save_emp.php unrestricted uploadRecord Management SystemAttack Blocked by Atomicorp340156 , 341245 , 351000 , 390501
CVE-2026-76995SourceCodester Simple Online Food Ordering System ajax.php save_menu unrestricted uploadSimple Online Food Ordering SystemAttack Blocked by Atomicorp351000
CVE-2026-82629jeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwid3Controller.doUpload unrestricted uploadjeewx-bootAttack Blocked by Atomicorp351000

Associated Atomicorp WAF Rules

RuleStatusBehavior
331028Activedisruptive (deny)
333360Activedisruptive (deny)
337109Activedisruptive (deny)
337110Activedisruptive (deny)
337473Activedisruptive (deny)
340007Activedisruptive (deny)
340014Activedisruptive (deny)
340016Activedisruptive (deny)
340017Activedisruptive (deny)
340023Activedisruptive (deny)
340029Activedisruptive (deny)
340144Activedisruptive (deny)
340155Activedisruptive (deny)
340156Activedisruptive (deny)
340157Activedisruptive (deny)
340159Activedisruptive (deny)
340162Activedisruptive (deny)
340163Activedisruptive (deny)
340165Activedisruptive (deny)
340193Activedisruptive (deny)
341145Activedisruptive (deny)
341155Activedisruptive (deny)
341245Activedisruptive (deny)
344360Activedisruptive (deny)
344361Activedisruptive (deny)
344363Activedisruptive (deny)
344364Activedisruptive (deny)
344366Activedisruptive (deny)
344370Activedisruptive (deny)
345493Activenon-disruptive (pass)
347009Activedisruptive (deny)
351000Activedisruptive (deny)
360147Activedisruptive (deny)
360148Activedisruptive (deny)
360153Activedisruptive (deny)
377360Activenon-disruptive (pass)
380026Activedisruptive (deny)
380122Activedisruptive (deny)
383871Activedisruptive (deny)
390501Activedisruptive (deny)
390709Activedisruptive (deny)
390716Activedisruptive (deny)
390720Activedisruptive (deny)
390722Activedisruptive (deny)
390724Activedisruptive (deny)
390726Activedisruptive (deny)
390727Activedisruptive (deny)
392301Activedisruptive (deny)
392647Activedisruptive (deny)
392648Activedisruptive (deny)
393655Activedisruptive (deny)
398001Activenon-disruptive (pass)
398008Activenon-disruptive (pass)
398021Activedisruptive (deny)
398022Activedisruptive (deny)

MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:

CAPEC-19 (opens in a new tab) , CAPEC-441 (opens in a new tab) , CAPEC-478 (opens in a new tab) , CAPEC-479 (opens in a new tab) , CAPEC-502 (opens in a new tab) , CAPEC-503 (opens in a new tab) , CAPEC-536 (opens in a new tab) , CAPEC-546 (opens in a new tab) , CAPEC-550 (opens in a new tab) , CAPEC-551 (opens in a new tab) , CAPEC-552 (opens in a new tab) , CAPEC-556 (opens in a new tab) , CAPEC-558 (opens in a new tab) , CAPEC-562 (opens in a new tab) , CAPEC-563 (opens in a new tab) , CAPEC-564 (opens in a new tab) , CAPEC-578 (opens in a new tab)