On this page
CWE-285: Improper Authorization
Weakness Summary
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
- Canonical source: MITRE CWE-285 (opens in a new tab)
- Published Atomicorp CVE observations: 11
- Distinct affected products in those observations: 11
- Active Atomicorp rules associated with this weakness: 41
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2026-55166 | Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and cr | lemur | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2021-28799 | QNAP HBS 3 - Broken Access Control | hybrid backup sync | Attack Blocked by Atomicorp | 344360 , 390904 |
| CVE-2024-34257 | TOTOLINK EX1800T TOTOLINK EX1800T - Command Injection | a3700r firmware | Attack Blocked by Atomicorp | 392301 |
| CVE-2026-10580 | Hippoo Mobile App for WooCommerce <= 1.9.4 - Authentication Bypass to Admin Account Takeover | Hippoo Mobile App for WooCommerce | Attack Blocked by Atomicorp | 320008 , 330919 |
| CVE-2017-11398 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | Attack Blocked by Atomicorp | 330791 , 340007 , 340152 |
| CVE-2024-26291 | Avid NEXIS Agent - Arbitrary File Read | nexis | Attack Blocked by Atomicorp | 344360 , 344365 , 347009 , 390709 |
| CVE-2026-46484 | Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/user | headplane | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2016-5676 | NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities | readynas surveillance | Attack Blocked by Atomicorp | 392301 |
| CVE-2023-48241 | XWiki < 4.10.15 - Information Disclosure | xwiki | Attack Blocked by Atomicorp | 390722 |
| CVE-2026-34239 | Chamilo Authenticated Remote Code Execution | chamilo-lms | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-11476 | Kushan2k student-management-system Profile Update Endpoint AdminController.php edit-admin improper authorization | student-management-system | Attack Blocked by Atomicorp | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 320008 | Active | disruptive (deny) |
| 330791 | Active | disruptive (deny) |
| 330919 | Active | disruptive (deny) |
| 337109 | Active | disruptive (deny) |
| 337110 | Active | disruptive (deny) |
| 340007 | Active | disruptive (deny) |
| 340014 | Active | disruptive (deny) |
| 340016 | Active | disruptive (deny) |
| 340017 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340144 | Active | disruptive (deny) |
| 340145 | Active | disruptive (deny) |
| 340152 | Active | disruptive (deny) |
| 340156 | Active | disruptive (deny) |
| 340157 | Active | disruptive (deny) |
| 340162 | Active | disruptive (deny) |
| 340163 | Active | disruptive (deny) |
| 340193 | Active | disruptive (deny) |
| 341145 | Active | disruptive (deny) |
| 341245 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344364 | Active | disruptive (deny) |
| 344365 | Active | disruptive (deny) |
| 344366 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 347009 | Active | disruptive (deny) |
| 360147 | Active | disruptive (deny) |
| 360148 | Active | disruptive (deny) |
| 380026 | Active | disruptive (deny) |
| 380122 | Active | disruptive (deny) |
| 390572 | Active | disruptive (deny) |
| 390709 | Active | disruptive (deny) |
| 390722 | Active | disruptive (deny) |
| 390904 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 393655 | Active | disruptive (deny) |
| 398021 | Active | disruptive (deny) |
| 398022 | Active | disruptive (deny) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:
CAPEC-1 (opens in a new tab) , CAPEC-104 (opens in a new tab) , CAPEC-127 (opens in a new tab) , CAPEC-13 (opens in a new tab) , CAPEC-17 (opens in a new tab) , CAPEC-39 (opens in a new tab) , CAPEC-402 (opens in a new tab) , CAPEC-45 (opens in a new tab) , CAPEC-5 (opens in a new tab) , CAPEC-51 (opens in a new tab) , CAPEC-59 (opens in a new tab) , CAPEC-60 (opens in a new tab) , CAPEC-647 (opens in a new tab) , CAPEC-668 (opens in a new tab) , CAPEC-76 (opens in a new tab) , CAPEC-77 (opens in a new tab) , CAPEC-87 (opens in a new tab)