# CWE-284: Improper Access Control

**KEV-linked**

> As of 2026-10-05, CWE-284 (Improper Access Control) underlies 60 CVEs tracked by Threadlinqs, 6 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 199 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-284?

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Access control involves the use of several protection mechanisms such as: Authentication (proving the identity of an actor) Authorization (ensuring that a given actor can access a resource), and Accountability (tracking of activities that were performed) When any mechanism is not applied or otherwise fails, attackers can compromise the security of the product by gaining privileges, reading sensitive information, executing commands, evading detection, etc. There are two distinct behaviors that can introduce access control weaknesses: Specification: incorrect privileges, permissions, ownership, etc. are explicitly specified for either the user or the resource (for example, setting a password file to be world-writable, or giving administrator capabilities to a guest user). This action could be performed by the program or the administrator. Enforcement: the mechanism contains errors that prevent it from properly enforcing the specified access control requirements (e.g., allowing the user to specify their own privileges, or allowing a syntactically-incorrect ACL to produce insecure settings). This problem occurs within the program itself, in that it does not actually enforce the intended security policy that the administrator specifies.

CWE-284 is a pillar-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Not Technology-Specific; Technology: ICS/OT; Technology: Web Based.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/284.html) (CWE-284 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Other** — Varies by Context

_Source: MITRE CWE, common consequences._

## How CWE-284 is exploited in the wild

Threadlinqs maps 60 CVEs to CWE-284, published between 2023-04-20 and 2026-10-01. 6 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 3 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 23 critical, 18 high, 15 medium, 1 low. The highest EPSS score in the set is 94.2% (CVE-2023-27350), the modelled probability of exploitation in the next 30 days. 199 tracked threats reference CWE-284 directly or through a CVE it covers; the most recent is “The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)” (2026-10-03). Affected products concentrate in Microsoft (9), Oracle Corporation (7), Fortinet (2), among 36 vendors in total.

## Vulnerabilities (CVEs)

Showing 40 of 60 CVEs mapped to CWE-284, CISA KEV first, then by CVSS score.

- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350) — CISA KEV · CVSS 9.8 critical · EPSS 94.2% · published 2023-04-20
- [CVE-2026-48907](https://intel.threadlinqs.com/cve/CVE-2026-48907) — CISA KEV · CVSS 9.8 critical · EPSS 80.4% · published 2026-06-05
- [CVE-2026-35616](https://intel.threadlinqs.com/cve/CVE-2026-35616) — CISA KEV · CVSS 9.8 critical · EPSS 25.2% · published 2026-04-04
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766) — CISA KEV · CVSS 9.3 critical · EPSS 3.5% · published 2024-08-23
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073) — CISA KEV · CVSS 8.8 high · EPSS 37.1% · published 2025-06-10
- [CVE-2026-81963](https://intel.threadlinqs.com/cve/CVE-2026-81963) — CISA KEV · CVSS 7.8 high · published 2026-09-08
- [CVE-2026-66803](https://intel.threadlinqs.com/cve/CVE-2026-66803) — CVSS 10 critical · EPSS 0.4% · published 2026-07-30
- [CVE-2026-83944](https://intel.threadlinqs.com/cve/CVE-2026-83944) — CVSS 10 critical · EPSS 0.4% · published 2026-09-17
- [CVE-2026-21636](https://intel.threadlinqs.com/cve/CVE-2026-21636) — CVSS 10 critical · EPSS 0.0% · published 2026-01-20
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908) — CVSS 10 critical · EPSS 0.0% · published 2026-05-22
- [CVE-2026-60366](https://intel.threadlinqs.com/cve/CVE-2026-60366) — CVSS 10 critical · published 2026-07-22
- [CVE-2026-60369](https://intel.threadlinqs.com/cve/CVE-2026-60369) — CVSS 9.9 critical · EPSS 0.4% · published 2026-07-22
- [CVE-2026-21666](https://intel.threadlinqs.com/cve/CVE-2026-21666) — CVSS 9.9 critical · EPSS 0.3% · published 2026-03-12
- [CVE-2026-21667](https://intel.threadlinqs.com/cve/CVE-2026-21667) — CVSS 9.9 critical · EPSS 0.3% · published 2026-03-12
- [CVE-2026-33109](https://intel.threadlinqs.com/cve/CVE-2026-33109) — CVSS 9.9 critical · EPSS 0.0% · published 2026-05-07
- [CVE-2026-2699](https://intel.threadlinqs.com/cve/CVE-2026-2699) — CVSS 9.8 critical · EPSS 9.8% · published 2026-04-02
- [CVE-2026-20896](https://intel.threadlinqs.com/cve/CVE-2026-20896) — CVSS 9.8 critical · EPSS 0.7% · published 2026-07-03
- [CVE-2026-60372](https://intel.threadlinqs.com/cve/CVE-2026-60372) — CVSS 9.8 critical · EPSS 0.5% · published 2026-07-22
- [CVE-2026-24300](https://intel.threadlinqs.com/cve/CVE-2026-24300) — CVSS 9.8 critical · EPSS 0.0% · published 2026-02-05
- [CVE-2026-21962](https://intel.threadlinqs.com/cve/CVE-2026-21962) — CVSS 9.8 critical · EPSS 0.0% · published 2026-01-20
- [CVE-2026-75338](https://intel.threadlinqs.com/cve/CVE-2026-75338) — CVSS 9.8 critical · published 2026-08-26
- [CVE-2026-65182](https://intel.threadlinqs.com/cve/CVE-2026-65182) — CVSS 9.1 critical · EPSS 0.4% · published 2026-08-25
- [CVE-2026-60168](https://intel.threadlinqs.com/cve/CVE-2026-60168) — CVSS 9.1 critical · EPSS 0.4% · published 2026-07-21
- [CVE-2026-64863](https://intel.threadlinqs.com/cve/CVE-2026-64863) — CVSS 9.1 critical · EPSS 0.3% · published 2026-07-28
- [CVE-2026-44277](https://intel.threadlinqs.com/cve/CVE-2026-44277) — CVSS 9.1 critical · EPSS 0.1% · published 2026-05-12
- [CVE-2026-81941](https://intel.threadlinqs.com/cve/CVE-2026-81941) — CVSS 8.8 high · EPSS 0.8% · published 2026-09-10
- [CVE-2026-57855](https://intel.threadlinqs.com/cve/CVE-2026-57855) — CVSS 8.8 high · EPSS 0.2% · published 2026-07-13
- [CVE-2026-21262](https://intel.threadlinqs.com/cve/CVE-2026-21262) — CVSS 8.8 high · EPSS 0.1% · published 2026-03-10
- [CVE-2026-35271](https://intel.threadlinqs.com/cve/CVE-2026-35271) — CVSS 8.7 high · EPSS 0.3% · published 2026-06-16
- [CVE-2026-43760](https://intel.threadlinqs.com/cve/CVE-2026-43760) — CVSS 8.6 high · EPSS 0.2% · published 2026-07-27
- [CVE-2026-24302](https://intel.threadlinqs.com/cve/CVE-2026-24302) — CVSS 8.6 high · EPSS 0.1% · published 2026-02-05
- [CVE-2026-55234](https://intel.threadlinqs.com/cve/CVE-2026-55234) — CVSS 8.5 high · EPSS 0.2% · published 2026-07-15
- [CVE-2026-60371](https://intel.threadlinqs.com/cve/CVE-2026-60371) — CVSS 8 high · EPSS 0.2% · published 2026-07-22
- [CVE-2026-55544](https://intel.threadlinqs.com/cve/CVE-2026-55544) — CVSS 7.6 high · EPSS 0.1% · published 2026-07-20
- [CVE-2026-60170](https://intel.threadlinqs.com/cve/CVE-2026-60170) — CVSS 7.5 high · EPSS 0.3% · published 2026-07-21
- [CVE-2026-51221](https://intel.threadlinqs.com/cve/CVE-2026-51221) — CVSS 7.5 high · EPSS 0.1% · published 2026-06-29
- [CVE-2026-58043](https://intel.threadlinqs.com/cve/CVE-2026-58043) — CVSS 7.5 high · EPSS 0.1% · published 2026-07-30
- [CVE-2026-90603](https://intel.threadlinqs.com/cve/CVE-2026-90603) — CVSS 7.3 high · EPSS 0.4% · published 2026-09-13
- [CVE-2026-82921](https://intel.threadlinqs.com/cve/CVE-2026-82921) — CVSS 7.3 high · EPSS 0.2% · published 2026-08-31
- [CVE-2026-41641](https://intel.threadlinqs.com/cve/CVE-2026-41641) — CVSS 7.2 high · EPSS 1.8% · published 2026-05-07

## Affected vendors

- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 9 CVEs
- **Oracle Corporation** — 7 CVEs
- [Fortinet](https://intel.threadlinqs.com/vendors/fortinet) — 2 CVEs
- [SourceCodester](https://intel.threadlinqs.com/vendors/sourcecodester) — 2 CVEs
- [Veeam](https://intel.threadlinqs.com/vendors/veeam) — 2 CVEs
- [nodejs](https://intel.threadlinqs.com/vendors/nodejs) — 2 CVEs
- **pdovhomilja** — 2 CVEs
- **Acer** — 1 CVE
- **Anil-matcha** — 1 CVE
- [Apache Software Foundation](https://intel.threadlinqs.com/vendors/apache-software-foundation) — 1 CVE
- [Apple](https://intel.threadlinqs.com/vendors/apple) — 1 CVE
- **Cockpit HQ** — 1 CVE

## Threat activity

199 tracked threats cite CWE-284; the 25 most recent are listed.

- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)](https://intel.threadlinqs.com/threat/TL-2026-2852) — HIGH · 2026-10-03
- [Multiple High-Severity Vulnerabilities in TeamViewer Client (CVE-2026-92370, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371, CVE-2026-19743)](https://intel.threadlinqs.com/threat/TL-2026-2905) — HIGH · 2026-10-02
- [WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)](https://intel.threadlinqs.com/threat/TL-2026-2813) — CRITICAL · 2026-09-30
- [CVE-2026-50610: Acer System Monitor (NitroSense/PredatorSense) local privilege escalation from standard user to SYSTEM via unauthenticated named pipe registry write](https://intel.threadlinqs.com/threat/TL-2026-2786) — HIGH · 2026-09-29
- [CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft](https://intel.threadlinqs.com/threat/TL-2026-2689) — HIGH · 2026-09-27
- [Critical ServiceNow AI Platform Vulnerabilities: Unauthenticated SQL Injection and Authorization Bypasses (CVE-2026-13016, CVE-2026-86857-86860)](https://intel.threadlinqs.com/threat/TL-2026-2653) — CRITICAL · 2026-09-25
- [Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government Data](https://intel.threadlinqs.com/threat/TL-2026-2619) — CRITICAL · 2026-09-22
- [Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing Flaws Across Azure and Copilot AI Products, Plus a Windows Secure Kernel EoP (CVE-2026-85921)](https://intel.threadlinqs.com/threat/TL-2026-2563) — CRITICAL · 2026-09-18
- [Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+ Websites via ClickFix and a Rogue WordPress Plugin](https://intel.threadlinqs.com/threat/TL-2026-2573) — CRITICAL · 2026-09-18
- [Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operators](https://intel.threadlinqs.com/threat/TL-2026-2532) — MEDIUM · 2026-09-16
- [Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2517) — HIGH · 2026-09-15
- [Apple Ships 273-CVE Coordinated Security Update Across iOS 27, macOS, watchOS, tvOS, visionOS, Safari, and Xcode — Bundles a Previously KEV-Listed Pre-Auth Screen Sharing RCE](https://intel.threadlinqs.com/threat/TL-2026-2522) — CRITICAL · 2026-09-15
- [CVE-2025-59201: Windows Network Connection Status Indicator (NCSI) Elevation of Privilege via Registry Symbolic Link Abuse](https://intel.threadlinqs.com/threat/TL-2026-2480) — HIGH · 2026-09-13
- [Trezor, BitBox, and CoinTracking Subscribers Targeted by Phishing After Brevo SAML SSO Authorization-Boundary Breach](https://intel.threadlinqs.com/threat/TL-2026-2445) — HIGH · 2026-09-11
- [Endor Labs Discloses 14 Critical/High Vulnerabilities Across Seven AI Orchestration Platforms (NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, Apache Airflow)](https://intel.threadlinqs.com/threat/TL-2026-2438) — CRITICAL · 2026-09-10
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days (CVE-2026-81963, CVE-2026-85880) and Multiple Critical Wormable RCEs](https://intel.threadlinqs.com/threat/TL-2026-2398) — CRITICAL · 2026-09-08
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046)](https://intel.threadlinqs.com/threat/TL-2026-2407) — CRITICAL · 2026-09-08
- [HPE Patches Critical ArubaOS-CX Buffer Overflow (CVE-2026-73749) Enabling Unauthenticated Remote Code Execution](https://intel.threadlinqs.com/threat/TL-2026-2314) — CRITICAL · 2026-09-03
- [MoiClient Backdoor: Multi-Stage Evasion via DLL Side-Loading, RPC UAC Bypass, and BYOVD Driver Abuse](https://intel.threadlinqs.com/threat/TL-2026-2288) — HIGH · 2026-09-02
- [Threat Actors Impersonate OpenAI, Anthropic, and DeepSeek AI Crawlers to Harvest Credentials and Secrets](https://intel.threadlinqs.com/threat/TL-2026-2204) — MEDIUM · 2026-08-29
- [ServiceNow Patches Four Critical Flaws Including Three CVSS 10.0 Unauthenticated RCE/SQLi Bugs (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, CVE-2026-6876)](https://intel.threadlinqs.com/threat/TL-2026-2195) — CRITICAL · 2026-08-28
- [ADCS ESC1 Privilege Escalation: CISA AA26-237A Red Team Findings and CA Database Hunting Methodology](https://intel.threadlinqs.com/threat/TL-2026-2168) — HIGH · 2026-08-27
- [Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Including HTTP/2 DoS, Authorization Bypass, and Auth Fail-Open Flaws — NVD Scores 5 of 11 CRITICAL/HIGH Despite Apache's Low/Moderate Ratings](https://intel.threadlinqs.com/threat/TL-2026-2159) — CRITICAL · 2026-08-26
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — HIGH · 2026-08-21
- [Gogs Critical RCE via Path Traversal in Organization Names (CVE-2026-52813)](https://intel.threadlinqs.com/threat/TL-2026-2092) — CRITICAL · 2026-08-20

## Mitigations

- **Architecture and Design, Operation**: Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
- **Architecture and Design / Separation of Privilege**: Compartmentalize the system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area. Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separation functionality. Architects and designers should rely on the principle of least privilege to decide the appropriate time to use privileges and the time to drop privileges.

_Source: MITRE CWE, potential mitigations._

Canonical: https://intel.threadlinqs.com/cwe/CWE-284
Source definition: https://cwe.mitre.org/data/definitions/284.html
Detection rules and IOCs for threats exploiting CWE-284 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
