VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,180)

page 19 of 59
  • CVE-2025-8261HigJul 28, 2025
    risk 0.48cvss 7.3epss 0.01

    A weakness has been identified in Vaelsys VaelsysV4 4.1.0. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the component User Creation Handler. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The…

  • CVE-2025-5689HigJun 16, 2025
    risk 0.48cvss 8.5epss 0.00

    A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session.

  • CVE-2025-2360HigMar 17, 2025
    risk 0.48cvss 7.3epss 0.04

    A vulnerability classified as critical was found in D-Link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is the function SetUpnpSettings of the file /HNAP1/ of the component UPnP Service. The manipulation of the argument SOAPAction leads to improper authorization.…

  • CVE-2025-2320HigMar 14, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this vulnerability is the function submit of the file /api/blade-user/submit of the component User Handler. The manipulation leads to improper authorization. The…

  • CVE-2025-26523HigFeb 14, 2025
    risk 0.48cvss —epss 0.00

    This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and deletion operations. Successful exploitation of this vulnerability could allow an authenticated remote attacker to modify information…

  • CVE-2024-13030HigDec 30, 2024
    risk 0.48cvss 7.3epss 0.02

    A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. It has been rated as critical. This issue affects the function SetAutoRebootSettings/SetClientInfo/SetDMZSettings/SetFirewallSettings/SetParentsControlInfo/SetQoSSettings/SetVirtualServerSettings of the file /HNAP1/…

  • CVE-2024-12782HigDec 19, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 and classified as critical. This vulnerability affects unknown code of the file /home/index.html#hashHome of the component Web Interface. The manipulation leads…

  • CVE-2024-27275HigJun 15, 2024
    risk 0.48cvss 7.4epss 0.00

    IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user without administrator privilege can configure a physical file trigger to execute with the privileges of a user socially engineered to…

  • CVE-2023-3518HigAug 9, 2023
    risk 0.48cvss 7.4epss 0.00

    HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities. Fixed in 1.16.1.

  • CVE-2022-4273HigDec 3, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the file /hrm/controller/employee.php of the component Content-Type Handler. The manipulation of the argument…

  • CVE-2026-90856HigSep 15, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role leads to improper privilege management.…

  • CVE-2026-86830HigSep 14, 2026
    risk 0.47cvss 7.2epss 0.00

    Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby…

  • CVE-2026-90787HigSep 14, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow. Such manipulation of the argument level…

  • CVE-2026-90566HigSep 13, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the…

  • CVE-2026-82815HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This manipulation of the argument X-Forwarded-For/X-Real-IP/True-Client-IP causes improper access controls. The attack can be initiated…

  • CVE-2026-78271HigAug 27, 2026
    risk 0.47cvss 7.2epss 0.00

    Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.

  • CVE-2026-21756HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.00

    HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments.

  • CVE-2026-19376HigAug 10, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The…

  • CVE-2026-65559HigAug 6, 2026
    risk 0.47cvss 7.2epss 0.00

    Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.

  • CVE-2026-12529HigJun 17, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Affected is an unknown function of the file /index.php of the component Student Self-Registration Endpoint. The manipulation leads to improper access…