On this page

CWE-285: Improper Authorization

Weakness Summary

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

  • Canonical source: MITRE CWE-285 (opens in a new tab)
  • Published Atomicorp CVE observations: 11
  • Distinct affected products in those observations: 11
  • Active Atomicorp rules associated with this weakness: 41

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2026-55166Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and crlemurAttack Blocked by Atomicorp337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2021-28799QNAP HBS 3 - Broken Access Controlhybrid backup syncAttack Blocked by Atomicorp344360 , 390904
CVE-2024-34257TOTOLINK EX1800T TOTOLINK EX1800T - Command Injectiona3700r firmwareAttack Blocked by Atomicorp392301
CVE-2026-10580Hippoo Mobile App for WooCommerce <= 1.9.4 - Authentication Bypass to Admin Account TakeoverHippoo Mobile App for WooCommerceAttack Blocked by Atomicorp320008 , 330919
CVE-2017-11398Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Controlsmart protection serverAttack Blocked by Atomicorp330791 , 340007 , 340152
CVE-2024-26291Avid NEXIS Agent - Arbitrary File ReadnexisAttack Blocked by Atomicorp344360 , 344365 , 347009 , 390709
CVE-2026-46484Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/userheadplaneAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2016-5676NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilitiesreadynas surveillanceAttack Blocked by Atomicorp392301
CVE-2023-48241XWiki < 4.10.15 - Information DisclosurexwikiAttack Blocked by Atomicorp390722
CVE-2026-34239Chamilo Authenticated Remote Code Executionchamilo-lmsAttack Blocked by Atomicorp340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-11476Kushan2k student-management-system Profile Update Endpoint AdminController.php edit-admin improper authorizationstudent-management-systemAttack Blocked by Atomicorp340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572

Associated Atomicorp WAF Rules

RuleStatusBehavior
320008Activedisruptive (deny)
330791Activedisruptive (deny)
330919Activedisruptive (deny)
337109Activedisruptive (deny)
337110Activedisruptive (deny)
340007Activedisruptive (deny)
340014Activedisruptive (deny)
340016Activedisruptive (deny)
340017Activedisruptive (deny)
340023Activedisruptive (deny)
340029Activedisruptive (deny)
340144Activedisruptive (deny)
340145Activedisruptive (deny)
340152Activedisruptive (deny)
340156Activedisruptive (deny)
340157Activedisruptive (deny)
340162Activedisruptive (deny)
340163Activedisruptive (deny)
340193Activedisruptive (deny)
341145Activedisruptive (deny)
341245Activedisruptive (deny)
344360Activedisruptive (deny)
344361Activedisruptive (deny)
344363Activedisruptive (deny)
344364Activedisruptive (deny)
344365Activedisruptive (deny)
344366Activedisruptive (deny)
344370Activedisruptive (deny)
347009Activedisruptive (deny)
360147Activedisruptive (deny)
360148Activedisruptive (deny)
380026Activedisruptive (deny)
380122Activedisruptive (deny)
390572Activedisruptive (deny)
390709Activedisruptive (deny)
390722Activedisruptive (deny)
390904Activedisruptive (deny)
392301Activedisruptive (deny)
393655Activedisruptive (deny)
398021Activedisruptive (deny)
398022Activedisruptive (deny)

MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:

CAPEC-1 (opens in a new tab) , CAPEC-104 (opens in a new tab) , CAPEC-127 (opens in a new tab) , CAPEC-13 (opens in a new tab) , CAPEC-17 (opens in a new tab) , CAPEC-39 (opens in a new tab) , CAPEC-402 (opens in a new tab) , CAPEC-45 (opens in a new tab) , CAPEC-5 (opens in a new tab) , CAPEC-51 (opens in a new tab) , CAPEC-59 (opens in a new tab) , CAPEC-60 (opens in a new tab) , CAPEC-647 (opens in a new tab) , CAPEC-668 (opens in a new tab) , CAPEC-76 (opens in a new tab) , CAPEC-77 (opens in a new tab) , CAPEC-87 (opens in a new tab)