The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.

Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.

Improper Access Control CWE-284 CWE-284 at MITRE

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Improper Authorization: 30 CVEs (52.6%) — click to drill down Improper Authentication: 20 CVEs (35.1%) — click to drill down Origin Validation Error: 3 CVEs (5.3%) — click to drill down Insufficient Granularity of Access Control: 3 CVEs (5.3%) — click to drill down Improper Restriction of Communication Channel to Intended Endpoints: 1 CVEs (1.8%) — click to drill down Improper Privilege Management: 0 CVEs (0.0%) — click to drill down Improper Ownership Management: 0 CVEs (0.0%) — click to drill down Incorrect User Management: 0 CVEs (0.0%) — click to drill down Exposed Dangerous Method or Function: 0 CVEs (0.0%) — click to drill down On-Chip Debug and Test Interface With Improper Access Control: 0 CVEs (0.0%) — click to drill down Improper Restriction of Write-Once Bit Fields: 0 CVEs (0.0%) — click to drill down Improper Prevention of Lock Bit Modification: 0 CVEs (0.0%) — click to drill down Security-Sensitive Hardware Controls with Missing Lock Bit Protection: 0 CVEs (0.0%) — click to drill down CPU Hardware Not Configured to Support Exclusivity of Write and Execute Operations: 0 CVEs (0.0%) — click to drill down Improper Access Control Applied to Mirrored or Aliased Memory Regions: 0 CVEs (0.0%) — click to drill down Improper Restriction of Security Token Assignment: 0 CVEs (0.0%) — click to drill down Improper Handling of Overlap Between Protected Memory Ranges: 0 CVEs (0.0%) — click to drill down Improper Access Control for Register Interface: 0 CVEs (0.0%) — click to drill down Improper Physical Access Control: 0 CVEs (0.0%) — click to drill down Policy Uses Obsolete Encoding: 0 CVEs (0.0%) — click to drill down Generation of Incorrect Security Tokens: 0 CVEs (0.0%) — click to drill down Improper Access Control for Volatile Memory Containing Boot Code: 0 CVEs (0.0%) — click to drill down Hardware Child Block Incorrectly Connected to Parent System: 0 CVEs (0.0%) — click to drill down Access Control Check Implemented After Asset is Accessed: 0 CVEs (0.0%) — click to drill down Mutable Attestation or Measurement Reporting Data: 0 CVEs (0.0%) — click to drill down Incorrect Decoding of Security Identifiers: 0 CVEs (0.0%) — click to drill down Incorrect Conversion of Security Identifiers: 0 CVEs (0.0%) — click to drill down Insecure Security Identifier Mechanism: 0 CVEs (0.0%) — click to drill down Incorrect Chaining or Granularity of Debug Components: 0 CVEs (0.0%) — click to drill down Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation: 0 CVEs (0.0%) — click to drill down Improper Translation of Security Attributes by Fabric Bridge: 0 CVEs (0.0%) — click to drill down Missing Protection for Mirrored Regions in On-Chip Fabric Firewall: 0 CVEs (0.0%) — click to drill down Hardware Allows Activation of Test or Debug Logic at Runtime: 0 CVEs (0.0%) — click to drill down Improper Setting of Bus Controlling Capability in Fabric End-point: 0 CVEs (0.0%) — click to drill down Fabric-Address Map Allows Programming of Unwarranted Overlaps of Protected and Unprotected Ranges: 0 CVEs (0.0%) — click to drill down Improper Access Control in Fabric Bridge: 0 CVEs (0.0%) — click to drill down Improper Protection for Outbound Error Messages and Alert Signals: 0 CVEs (0.0%) — click to drill down Improper Management of Sensitive Trace Data: 0 CVEs (0.0%) — click to drill down Unauthorized Error Injection Can Degrade Hardware Redundancy: 0 CVEs (0.0%) — click to drill down Total 56
Improper Authorization CWE-285 30 (52.6%) Improper Authentication CWE-287 20 (35.1%) Origin Validation Error CWE-346 3 (5.3%) Insufficient Granularity of Access Control CWE-1220 3 (5.3%) Improper Restriction of Communication Channel to Intended Endpoints CWE-923 1 (1.8%) Improper Privilege Management CWE-269 0 (0.0%) Improper Ownership Management CWE-282 0 (0.0%) Incorrect User Management CWE-286 0 (0.0%) Exposed Dangerous Method or Function CWE-749 0 (0.0%) On-Chip Debug and Test Interface With Improper Access Control CWE-1191 0 (0.0%) Improper Restriction of Write-Once Bit Fields CWE-1224 0 (0.0%) Improper Prevention of Lock Bit Modification CWE-1231 0 (0.0%) Security-Sensitive Hardware Controls with Missing Lock Bit Protection CWE-1233 0 (0.0%) CPU Hardware Not Configured to Support Exclusivity of Write and Execute Operations CWE-1252 0 (0.0%) Improper Access Control Applied to Mirrored or Aliased Memory Regions CWE-1257 0 (0.0%) Improper Restriction of Security Token Assignment CWE-1259 0 (0.0%) Improper Handling of Overlap Between Protected Memory Ranges CWE-1260 0 (0.0%) Improper Access Control for Register Interface CWE-1262 0 (0.0%) Improper Physical Access Control CWE-1263 0 (0.0%) Policy Uses Obsolete Encoding CWE-1267 0 (0.0%) Generation of Incorrect Security Tokens CWE-1270 0 (0.0%) Improper Access Control for Volatile Memory Containing Boot Code CWE-1274 0 (0.0%) Hardware Child Block Incorrectly Connected to Parent System CWE-1276 0 (0.0%) Access Control Check Implemented After Asset is Accessed CWE-1280 0 (0.0%) Mutable Attestation or Measurement Reporting Data CWE-1283 0 (0.0%) Incorrect Decoding of Security Identifiers CWE-1290 0 (0.0%) Incorrect Conversion of Security Identifiers CWE-1292 0 (0.0%) Insecure Security Identifier Mechanism CWE-1294 0 (0.0%) Incorrect Chaining or Granularity of Debug Components CWE-1296 0 (0.0%) Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation CWE-1304 0 (0.0%) Improper Translation of Security Attributes by Fabric Bridge CWE-1311 0 (0.0%) Missing Protection for Mirrored Regions in On-Chip Fabric Firewall CWE-1312 0 (0.0%) Hardware Allows Activation of Test or Debug Logic at Runtime CWE-1313 0 (0.0%) Improper Setting of Bus Controlling Capability in Fabric End-point CWE-1315 0 (0.0%) Fabric-Address Map Allows Programming of Unwarranted Overlaps of Protected and Unprotected Ranges CWE-1316 0 (0.0%) Improper Access Control in Fabric Bridge CWE-1317 0 (0.0%) Improper Protection for Outbound Error Messages and Alert Signals CWE-1320 0 (0.0%) Improper Management of Sensitive Trace Data CWE-1323 0 (0.0%) Unauthorized Error Injection Can Degrade Hardware Redundancy CWE-1334 0 (0.0%)

CVEs

CVEs for Improper Access Control CWE-284

Summary Publication CVE ID Published
Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement CVE-2026-76949 2026-09-17
dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover CVE-2026-91039 2026-09-17
OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication CVE-2026-88952 2026-09-17
`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication CVE-2026-85500 2026-09-17
Sign-in token minted for one resource accepted by another in AshAuthentication CVE-2026-80218 2026-09-17
Confirmation token accepted on any record in AshAuthentication CVE-2026-82685 2026-09-17
Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle CVE-2026-86338 2026-09-16
AshLua eval read operations can read field-policy-protected fields via aggregates CVE-2026-78216 2026-09-08
AshAi aggregate tool can read field-policy-protected fields CVE-2026-78230 2026-09-08
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes CVE-2026-82586 2026-09-07
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint CVE-2026-82758 2026-09-07
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls CVE-2026-82754 2026-09-07
httpd mod_auth directory protection bypassed by a doubled slash in the request path
Erlang
pkg:otp/inets
CVE-2026-66835 2026-09-01
inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth
Erlang
pkg:otp/inets
CVE-2026-74994 2026-09-01
Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor CVE-2026-82747 2026-09-01
Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records CVE-2026-82749 2026-09-01
Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another CVE-2026-82748 2026-09-01
Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records CVE-2026-82746 2026-09-01
ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness CVE-2026-82745 2026-09-01
Authorization-redacted field values disclosed through AshTypescript result normalization CVE-2026-82730 2026-09-01
AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data CVE-2026-82725 2026-08-31
Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain CVE-2026-82724 2026-08-31
AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracle CVE-2026-81853 2026-08-31
Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records CVE-2026-82564 2026-08-31
MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header CVE-2026-81315 2026-08-31
25 per page · 56 CVEs
Page of 3