VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,068)

page 22 of 54
  • CVE-2025-48741MedMay 23, 2025
    risk 0.44cvss epss 0.00

    A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5.4.10 allows remote, authenticated, and unprivileged users to retrieve alerts, cases, logs, observables, or tasks, regardless of the user's permissions,…

  • CVE-2025-4692MedMay 23, 2025
    risk 0.44cvss 6.8epss 0.00

    Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation by submitting the malicious JWT to a vulnerable method exposed on the cloud platform. If the exploit is successful, the user can escalate privileges to access…

  • CVE-2024-33503MedJan 14, 2025
    risk 0.44cvss 6.7epss 0.00

    A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager Cloud 7.0 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions,…

  • CVE-2024-45759MedNov 8, 2024
    risk 0.44cvss 6.8epss 0.00

    Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of privilege vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to unauthorized execution of certain commands to…

  • CVE-2024-39579MedAug 31, 2024
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability. A local high privileged attacker could potentially exploit this vulnerability to gain root-level access.

  • CVE-2024-37134MedJul 2, 2024
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability to gain root-level access.

  • CVE-2024-37132MedJul 2, 2024
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service and Elevation of privileges.

  • CVE-2024-27460MedMay 14, 2024
    risk 0.44cvss 6.7epss 0.02

    A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.

  • CVE-2023-6477MedFeb 22, 2024
    risk 0.44cvss 6.7epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_member permission, they may be…

  • CVE-2023-5080MedJan 19, 2024
    risk 0.44cvss 6.8epss 0.00

    A privilege escalation vulnerability was reported in some Lenovo tablet products that could allow local applications access to device identifiers and system commands.

  • CVE-2021-40124MedNov 4, 2021
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to escalate privileges on an affected device. This vulnerability is due to incorrect privilege assignment to scripts…

  • CVE-2020-27122MedNov 6, 2020
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to elevate privileges on an affected device. To exploit this vulnerability, an attacker would need to have a valid administrator…

  • CVE-2020-26182MedOct 16, 2020
    risk 0.44cvss 6.8epss 0.01

    Dell EMC NetWorker versions prior to 19.3.0.2 contain an incorrect privilege assignment vulnerability. A non-LDAP remote user with low privileges may exploit this vulnerability to perform 'saveset' related operations in an unintended manner. The vulnerability is not exploitable…

  • CVE-2026-27102MedApr 8, 2026
    risk 0.43cvss 6.6epss 0.00

    Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of…

  • CVE-2024-38278MedJul 9, 2024
    risk 0.43cvss 6.6epss 0.00

    A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.9.0), RUGGEDCOM RMC8388NC V5.X (All versions < V5.9.0), RUGGEDCOM RS416NCv2 V5.X (All versions < V5.9.0), RUGGEDCOM RS416PNCv2 V5.X (All versions < V5.9.0), RUGGEDCOM RS416Pv2 V5.X (All versions <…

  • CVE-2024-3013MedMar 28, 2024
    risk 0.43cvss 6.3epss 0.23

    A flaw has been found in Teledyne FLIR AX8 up to 1.46.16. The impacted element is an unknown function of the file /tools/test_login.php?action=register of the component User Registration. Executing manipulation can lead to improper authorization. The attack may be performed from…

  • CVE-2023-35165MedJun 23, 2023
    risk 0.43cvss 6.6epss 0.01

    AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. In the packages `aws-cdk-lib` 2.0.0 until 2.80.0 and `@aws-cdk/aws-eks` 1.57.0 until 1.202.0, `eks.Cluster`…

  • CVE-2026-4629MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject the `realm-admin` role into…

  • CVE-2026-12388MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is mapped to Keycloak users. An administrator with limited permissions to manage identity providers can exploit this flaw by creating…

  • CVE-2026-56251MedJun 21, 2026
    risk 0.42cvss 6.5epss 0.00

    Capgo before 12.128.2 contains a broken row level security policy in the org_users table that allows authenticated users to elevate privileges from admin to super_admin. Attackers can exploit the insufficient RLS enforcement to gain unauthorized super_admin access and compromise…