CWE-28418 advisories

Improper Access Control

What it is

Access-control restrictions are missing or wrong, letting actors reach resources or actions they shouldn't.

How to fix it

Upgrade and enforce correct, default-deny access checks.

How to avoid it

Centralize authorization, default-deny, and test every access boundary.

Known Improper Access Control vulnerabilities

Stateward flags Improper Access Control in your own code and dependencies on every pull request.

Scan my repo

Summarize with AI

ChatGPTClaudePerplexity

Sources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.