Improper Access Control is a vulnerability tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed November 28, 2025; most recent activity December 12, 2025.
Improper Access Control is a vulnerability class where systems fail to enforce proper permissions, allowing unauthorized access, actions, or resource creation. It is a critical and widespread risk across applications and APIs, highlighted in 2025 as one of the top 25 most dangerous software weaknesses by MITRE, underscoring its high impact and prevalence.
A design flaw in Microsoft Azure's API Management Developer Portal enables unauthorized account creation across different tenants. Microsoft has classified this behavior as 'by design', despite the significant security…
The 2025 CWE Top 25 Most Dangerous Software Weaknesses list has been published, identifying critical vulnerabilities that pose significant risks to software security. This list is intended for developers and…