VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,068)

page 23 of 54
  • CVE-2026-10272MedJun 1, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The impacted element is an unknown function of the file admin/deleteform.php. Such manipulation of the argument sid leads to improper authorization. It is possible to…

  • CVE-2026-35062MedMay 13, 2026
    risk 0.42cvss 6.5epss 0.00

    An authenticated iControl SOAP user may be able to obtain information of other accounts.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2026-40869HigApr 21, 2026
    risk 0.42cvss 7.5epss 0.00

    Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the…

  • CVE-2026-5330MedApr 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_user of the component User Delete Handler. Performing a manipulation of the argument ID results in…

  • CVE-2026-20110MedMar 25, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because incorrect privileges are associated with the start maintenance command. An…

  • CVE-2026-2669MedFeb 18, 2026
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impacts an unknown function of the file /dm/dispatch/user/delete of the component User Handler. This manipulation of the argument ID causes improper access…

  • CVE-2025-67278MedJan 9, 2026
    risk 0.42cvss 6.5epss 0.00

    An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via a crafted HTTP request

  • CVE-2025-14206MedDec 8, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was determined in SourceCodester Online Student Clearance System 1.0. The affected element is an unknown function of the file /Admin/delete-fee.php of the component Fee Table Handler. Executing manipulation of the argument ID can lead to improper authorization.…

  • CVE-2025-63384MedNov 10, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exception Return) instruction fails to correctly transition the processor's privilege level. Instead of downgrading from Machine-mode (M-mode) to Supervisor-mode…

  • CVE-2025-56503MedNov 10, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Sublime HQ Pty Ltd Sublime Text 4 4200 allows authenticated attackers with low-level privileges to escalate privileges to Administrator via replacing the uninstall file with a crafted binary in the installation folder. NOTE: this is disputed by the Supplier because…

  • CVE-2025-31513MedJul 22, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can elevate to administrator privileges via the IsAdminApprover parameter in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version…

  • CVE-2025-46204MedJun 4, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.

  • CVE-2025-46203MedJun 4, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.

  • CVE-2025-4493MedMay 28, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue. This issue affects the following versions :  * Devolutions Server 2025.1.3.0 through…

  • CVE-2025-48695MedMay 23, 2025
    risk 0.42cvss 6.4epss 0.00

    An issue was discovered in CyberDAVA before 1.1.20. A privilege escalation vulnerability allows a low-privileged user to escalate their privilege by abusing the following API due to the lack of access control: /api/v2/users/user//role/ROLE/ (admin access…

  • CVE-2025-4374MedMay 6, 2025
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.

  • CVE-2025-4269MedMay 5, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/cstecgi.cgi of the component Log Handler. The manipulation of the argument topicurl with the input…

  • CVE-2025-3536MedApr 13, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Tutorials-Website Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/delete-user.php. The manipulation of the argument ID leads to improper authorization. The attack may…

  • CVE-2025-2686MedMar 24, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. Affected by this vulnerability is the function doFilter of the file /admin/ of the component Backend. The…

  • CVE-2025-21092MedMar 5, 2025
    risk 0.42cvss 6.5epss 0.00

    GMOD Apollo does not have sufficient logical or access checks when updating a user's information. This could result in an attacker being able to escalate privileges for themselves or others.