Threadlinqs IntelligenceStart free

Weakness · PillarCWE-284

CWE-284: Improper Access Control

KEV-linkedPillar

As of 2026-10-05, CWE-284 (Improper Access Control) underlies 60 CVEs tracked by Threadlinqs, 6 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 199 tracked threats.

CVEs
60Mapped to CWE-284
CISA KEV
6Exploited in the wild
Critical
23CVSS v3 critical CVEs
Threats
199Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-284?

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Access control involves the use of several protection mechanisms such as: Authentication (proving the identity of an actor) Authorization (ensuring that a given actor can access a resource), and Accountability (tracking of activities that were performed) When any mechanism is not applied or otherwise fails, attackers can compromise the security of the product by gaining privileges, reading sensitive information, executing commands, evading detection, etc. There are two distinct behaviors that can introduce access control weaknesses: Specification: incorrect privileges, permissions, ownership, etc. are explicitly specified for either the user or the resource (for example, setting a password file to be world-writable, or giving administrator capabilities to a guest user). This action could be performed by the program or the administrator. Enforcement: the mechanism contains errors that prevent it from properly enforcing the specified access control requirements (e.g., allowing the user to specify their own privileges, or allowing a syntactically-incorrect ACL to produce insecure settings). This problem occurs within the program itself, in that it does not actually enforce the intended security policy that the administrator specifies.

CWE-284 is a pillar-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Not Technology-Specific; Technology: ICS/OT; Technology: Web Based.

Source: MITRE CWE (CWE-284 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Other — Varies by Context

Source: MITRE CWE, common consequences.

How CWE-284 is exploited in the wild

Threadlinqs maps 60 CVEs to CWE-284, published between 2023-04-20 and 2026-10-01. 6 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 3 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 23 critical, 18 high, 15 medium, 1 low. The highest EPSS score in the set is 94.2% (CVE-2023-27350), the modelled probability of exploitation in the next 30 days. 199 tracked threats reference CWE-284 directly or through a CVE it covers; the most recent is “The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)” (2026-10-03). Affected products concentrate in Microsoft (9), Oracle Corporation (7), Fortinet (2), among 36 vendors in total.

Vulnerabilities (CVEs)

Showing 40 of 60 CVEs mapped to CWE-284, CISA KEV first, then by CVSS score.

  • CVE-2023-27350 — CISA KEV · CVSS 9.8 critical · EPSS 94.2% · published 2023-04-20
  • CVE-2026-48907 — CISA KEV · CVSS 9.8 critical · EPSS 80.4% · published 2026-06-05
  • CVE-2026-35616 — CISA KEV · CVSS 9.8 critical · EPSS 25.2% · published 2026-04-04
  • CVE-2024-40766 — CISA KEV · CVSS 9.3 critical · EPSS 3.5% · published 2024-08-23
  • CVE-2025-33073 — CISA KEV · CVSS 8.8 high · EPSS 37.1% · published 2025-06-10
  • CVE-2026-81963 — CISA KEV · CVSS 7.8 high · published 2026-09-08
  • CVE-2026-66803 — CVSS 10 critical · EPSS 0.4% · published 2026-07-30
  • CVE-2026-83944 — CVSS 10 critical · EPSS 0.4% · published 2026-09-17
  • CVE-2026-21636 — CVSS 10 critical · EPSS 0.0% · published 2026-01-20
  • CVE-2026-34908 — CVSS 10 critical · EPSS 0.0% · published 2026-05-22
  • CVE-2026-60366 — CVSS 10 critical · published 2026-07-22
  • CVE-2026-60369 — CVSS 9.9 critical · EPSS 0.4% · published 2026-07-22
  • CVE-2026-21666 — CVSS 9.9 critical · EPSS 0.3% · published 2026-03-12
  • CVE-2026-21667 — CVSS 9.9 critical · EPSS 0.3% · published 2026-03-12
  • CVE-2026-33109 — CVSS 9.9 critical · EPSS 0.0% · published 2026-05-07
  • CVE-2026-2699 — CVSS 9.8 critical · EPSS 9.8% · published 2026-04-02
  • CVE-2026-20896 — CVSS 9.8 critical · EPSS 0.7% · published 2026-07-03
  • CVE-2026-60372 — CVSS 9.8 critical · EPSS 0.5% · published 2026-07-22
  • CVE-2026-24300 — CVSS 9.8 critical · EPSS 0.0% · published 2026-02-05
  • CVE-2026-21962 — CVSS 9.8 critical · EPSS 0.0% · published 2026-01-20
  • CVE-2026-75338 — CVSS 9.8 critical · published 2026-08-26
  • CVE-2026-65182 — CVSS 9.1 critical · EPSS 0.4% · published 2026-08-25
  • CVE-2026-60168 — CVSS 9.1 critical · EPSS 0.4% · published 2026-07-21
  • CVE-2026-64863 — CVSS 9.1 critical · EPSS 0.3% · published 2026-07-28
  • CVE-2026-44277 — CVSS 9.1 critical · EPSS 0.1% · published 2026-05-12
  • CVE-2026-81941 — CVSS 8.8 high · EPSS 0.8% · published 2026-09-10
  • CVE-2026-57855 — CVSS 8.8 high · EPSS 0.2% · published 2026-07-13
  • CVE-2026-21262 — CVSS 8.8 high · EPSS 0.1% · published 2026-03-10
  • CVE-2026-35271 — CVSS 8.7 high · EPSS 0.3% · published 2026-06-16
  • CVE-2026-43760 — CVSS 8.6 high · EPSS 0.2% · published 2026-07-27
  • CVE-2026-24302 — CVSS 8.6 high · EPSS 0.1% · published 2026-02-05
  • CVE-2026-55234 — CVSS 8.5 high · EPSS 0.2% · published 2026-07-15
  • CVE-2026-60371 — CVSS 8 high · EPSS 0.2% · published 2026-07-22
  • CVE-2026-55544 — CVSS 7.6 high · EPSS 0.1% · published 2026-07-20
  • CVE-2026-60170 — CVSS 7.5 high · EPSS 0.3% · published 2026-07-21
  • CVE-2026-51221 — CVSS 7.5 high · EPSS 0.1% · published 2026-06-29
  • CVE-2026-58043 — CVSS 7.5 high · EPSS 0.1% · published 2026-07-30
  • CVE-2026-90603 — CVSS 7.3 high · EPSS 0.4% · published 2026-09-13
  • CVE-2026-82921 — CVSS 7.3 high · EPSS 0.2% · published 2026-08-31
  • CVE-2026-41641 — CVSS 7.2 high · EPSS 1.8% · published 2026-05-07

Affected vendors

Threat activity

199 tracked threats cite CWE-284; the 25 most recent are listed.

Mitigations

  • Architecture and Design, Operation: Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
  • Architecture and Design / Separation of Privilege: Compartmentalize the system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area. Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separation functionality. Architects and designers should rely on the principle of least privilege to decide the appropriate time to use privileges and the time to drop privileges.

Source: MITRE CWE, potential mitigations.