The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.

Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.

Improper Access Control CWE-284 CWE-284 at MITRE

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Improper Authorization: 10 CVEs (47.6%) — click to drill down Improper Authentication: 9 CVEs (42.9%) — click to drill down Origin Validation Error: 1 CVEs (4.8%) — click to drill down Improper Restriction of Communication Channel to Intended Endpoints: 1 CVEs (4.8%) — click to drill down Improper Privilege Management: 0 CVEs (0.0%) — click to drill down Improper Ownership Management: 0 CVEs (0.0%) — click to drill down Incorrect User Management: 0 CVEs (0.0%) — click to drill down Exposed Dangerous Method or Function: 0 CVEs (0.0%) — click to drill down On-Chip Debug and Test Interface With Improper Access Control: 0 CVEs (0.0%) — click to drill down Insufficient Granularity of Access Control: 0 CVEs (0.0%) — click to drill down Improper Restriction of Write-Once Bit Fields: 0 CVEs (0.0%) — click to drill down Improper Prevention of Lock Bit Modification: 0 CVEs (0.0%) — click to drill down Security-Sensitive Hardware Controls with Missing Lock Bit Protection: 0 CVEs (0.0%) — click to drill down CPU Hardware Not Configured to Support Exclusivity of Write and Execute Operations: 0 CVEs (0.0%) — click to drill down Improper Access Control Applied to Mirrored or Aliased Memory Regions: 0 CVEs (0.0%) — click to drill down Improper Restriction of Security Token Assignment: 0 CVEs (0.0%) — click to drill down Improper Handling of Overlap Between Protected Memory Ranges: 0 CVEs (0.0%) — click to drill down Improper Access Control for Register Interface: 0 CVEs (0.0%) — click to drill down Improper Physical Access Control: 0 CVEs (0.0%) — click to drill down Policy Uses Obsolete Encoding: 0 CVEs (0.0%) — click to drill down Generation of Incorrect Security Tokens: 0 CVEs (0.0%) — click to drill down Improper Access Control for Volatile Memory Containing Boot Code: 0 CVEs (0.0%) — click to drill down Hardware Child Block Incorrectly Connected to Parent System: 0 CVEs (0.0%) — click to drill down Access Control Check Implemented After Asset is Accessed: 0 CVEs (0.0%) — click to drill down Mutable Attestation or Measurement Reporting Data: 0 CVEs (0.0%) — click to drill down Incorrect Decoding of Security Identifiers: 0 CVEs (0.0%) — click to drill down Incorrect Conversion of Security Identifiers: 0 CVEs (0.0%) — click to drill down Insecure Security Identifier Mechanism: 0 CVEs (0.0%) — click to drill down Incorrect Chaining or Granularity of Debug Components: 0 CVEs (0.0%) — click to drill down Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation: 0 CVEs (0.0%) — click to drill down Improper Translation of Security Attributes by Fabric Bridge: 0 CVEs (0.0%) — click to drill down Missing Protection for Mirrored Regions in On-Chip Fabric Firewall: 0 CVEs (0.0%) — click to drill down Hardware Allows Activation of Test or Debug Logic at Runtime: 0 CVEs (0.0%) — click to drill down Improper Setting of Bus Controlling Capability in Fabric End-point: 0 CVEs (0.0%) — click to drill down Fabric-Address Map Allows Programming of Unwarranted Overlaps of Protected and Unprotected Ranges: 0 CVEs (0.0%) — click to drill down Improper Access Control in Fabric Bridge: 0 CVEs (0.0%) — click to drill down Improper Protection for Outbound Error Messages and Alert Signals: 0 CVEs (0.0%) — click to drill down Improper Management of Sensitive Trace Data: 0 CVEs (0.0%) — click to drill down Unauthorized Error Injection Can Degrade Hardware Redundancy: 0 CVEs (0.0%) — click to drill down Total 20
Improper Authorization CWE-285 10 (47.6%) Improper Authentication CWE-287 9 (42.9%) Origin Validation Error CWE-346 1 (4.8%) Improper Restriction of Communication Channel to Intended Endpoints CWE-923 1 (4.8%) Improper Privilege Management CWE-269 0 (0.0%) Improper Ownership Management CWE-282 0 (0.0%) Incorrect User Management CWE-286 0 (0.0%) Exposed Dangerous Method or Function CWE-749 0 (0.0%) On-Chip Debug and Test Interface With Improper Access Control CWE-1191 0 (0.0%) Insufficient Granularity of Access Control CWE-1220 0 (0.0%) Improper Restriction of Write-Once Bit Fields CWE-1224 0 (0.0%) Improper Prevention of Lock Bit Modification CWE-1231 0 (0.0%) Security-Sensitive Hardware Controls with Missing Lock Bit Protection CWE-1233 0 (0.0%) CPU Hardware Not Configured to Support Exclusivity of Write and Execute Operations CWE-1252 0 (0.0%) Improper Access Control Applied to Mirrored or Aliased Memory Regions CWE-1257 0 (0.0%) Improper Restriction of Security Token Assignment CWE-1259 0 (0.0%) Improper Handling of Overlap Between Protected Memory Ranges CWE-1260 0 (0.0%) Improper Access Control for Register Interface CWE-1262 0 (0.0%) Improper Physical Access Control CWE-1263 0 (0.0%) Policy Uses Obsolete Encoding CWE-1267 0 (0.0%) Generation of Incorrect Security Tokens CWE-1270 0 (0.0%) Improper Access Control for Volatile Memory Containing Boot Code CWE-1274 0 (0.0%) Hardware Child Block Incorrectly Connected to Parent System CWE-1276 0 (0.0%) Access Control Check Implemented After Asset is Accessed CWE-1280 0 (0.0%) Mutable Attestation or Measurement Reporting Data CWE-1283 0 (0.0%) Incorrect Decoding of Security Identifiers CWE-1290 0 (0.0%) Incorrect Conversion of Security Identifiers CWE-1292 0 (0.0%) Insecure Security Identifier Mechanism CWE-1294 0 (0.0%) Incorrect Chaining or Granularity of Debug Components CWE-1296 0 (0.0%) Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation CWE-1304 0 (0.0%) Improper Translation of Security Attributes by Fabric Bridge CWE-1311 0 (0.0%) Missing Protection for Mirrored Regions in On-Chip Fabric Firewall CWE-1312 0 (0.0%) Hardware Allows Activation of Test or Debug Logic at Runtime CWE-1313 0 (0.0%) Improper Setting of Bus Controlling Capability in Fabric End-point CWE-1315 0 (0.0%) Fabric-Address Map Allows Programming of Unwarranted Overlaps of Protected and Unprotected Ranges CWE-1316 0 (0.0%) Improper Access Control in Fabric Bridge CWE-1317 0 (0.0%) Improper Protection for Outbound Error Messages and Alert Signals CWE-1320 0 (0.0%) Improper Management of Sensitive Trace Data CWE-1323 0 (0.0%) Unauthorized Error Injection Can Degrade Hardware Redundancy CWE-1334 0 (0.0%)

CVEs

CVEs for Improper Access Control CWE-284

Summary Publication CVE ID Published
Boruta accepts expired JWT client assertions due to missing exp claim validation CVE-2026-53431 2026-07-30
Missing ID token claim validation in ueberauth_apple allows account takeover CVE-2026-55954 2026-07-14
DTLS server cookie bypass during startup window due to empty initial cookie secret
pkg:otp/ssl
CVE-2026-54887 2026-07-02
Authorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding CVE-2026-48599 2026-06-15
OAuth2/OIDC account takeover in AshAuthentication via email-based user matching CVE-2026-49757 2026-06-15
Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist
pkg:otp/ssl
CVE-2026-48860 2026-06-10
gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection CVE-2026-43972 2026-06-08
ex_aws_sns SigningCertURL not validated in verify_message/1 CVE-2026-47074 2026-05-28
nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification
pkg:otp/public_key
CVE-2026-42790 2026-05-27
OCSP responder certificate validity period not checked in public_key
pkg:otp/public_key
CVE-2026-42791 2026-05-27
Non-CA certificate accepted as intermediate issuer in public_key path validation
pkg:otp/public_key
CVE-2026-42789 2026-05-27
Missing authorization check on save-job event handler in oban_web CVE-2026-48592 2026-05-26
Cross-session PubSub topic injection via URL parameter in phoenix_storybook CVE-2026-47068 2026-05-20
ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)
pkg:otp/inets
CVE-2026-28808 2026-04-07
OCSP designated-responder authorization bypass via missing signature verification
pkg:otp/public_key
pkg:otp/ssl
CVE-2026-32144 2026-04-07
Improper authorization in device bulk actions and device update API allows cross-organization device control
pkg:otp/nerves_hub
pkg:oci/nerves-hub
CVE-2026-28806 2026-03-10
Improper Scope Enforcement in OAuth client_credentials Flow Allows Read-Only API Key to Escalate to Full Access CVE-2026-21621 2026-03-05
Authorization bypass when bypass policy condition evaluates to true CVE-2025-48044 2025-10-17
Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization CVE-2025-48043 2025-10-10
Before action hooks may execute in certain scenarios despite a request being forbidden CVE-2025-48042 2025-09-07
20 CVEs