VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,180)

page 26 of 59
  • CVE-2026-5330MedApr 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_user of the component User Delete Handler. Performing a manipulation of the argument ID results in…

  • CVE-2026-20110MedMar 25, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because incorrect privileges are associated with the start maintenance command. An…

  • CVE-2026-2669MedFeb 18, 2026
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impacts an unknown function of the file /dm/dispatch/user/delete of the component User Handler. This manipulation of the argument ID causes improper access…

  • CVE-2025-67278MedJan 9, 2026
    risk 0.42cvss 6.5epss 0.00

    An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via a crafted HTTP request

  • CVE-2025-14206MedDec 8, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was determined in SourceCodester Online Student Clearance System 1.0. The affected element is an unknown function of the file /Admin/delete-fee.php of the component Fee Table Handler. Executing manipulation of the argument ID can lead to improper authorization.…

  • CVE-2025-63384MedNov 10, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exception Return) instruction fails to correctly transition the processor's privilege level. Instead of downgrading from Machine-mode (M-mode) to Supervisor-mode…

  • CVE-2025-56503MedNov 10, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Sublime HQ Pty Ltd Sublime Text 4 4200 allows authenticated attackers with low-level privileges to escalate privileges to Administrator via replacing the uninstall file with a crafted binary in the installation folder. NOTE: this is disputed by the Supplier because…

  • CVE-2025-31513MedJul 22, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can elevate to administrator privileges via the IsAdminApprover parameter in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version…

  • CVE-2025-46204MedJun 4, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.

  • CVE-2025-46203MedJun 4, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.

  • CVE-2025-4493MedMay 28, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue. This issue affects the following versions :  * Devolutions Server 2025.1.3.0 through…

  • CVE-2025-48695MedMay 23, 2025
    risk 0.42cvss 6.4epss 0.00

    An issue was discovered in CyberDAVA before 1.1.20. A privilege escalation vulnerability allows a low-privileged user to escalate their privilege by abusing the following API due to the lack of access control: /api/v2/users/user//role/ROLE/ (admin access…

  • CVE-2025-4374MedMay 6, 2025
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.

  • CVE-2025-4269MedMay 5, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/cstecgi.cgi of the component Log Handler. The manipulation of the argument topicurl with the input…

  • CVE-2025-3536MedApr 13, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Tutorials-Website Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/delete-user.php. The manipulation of the argument ID leads to improper authorization. The attack may…

  • CVE-2025-2686MedMar 24, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. Affected by this vulnerability is the function doFilter of the file /admin/ of the component Backend. The…

  • CVE-2025-21092MedMar 5, 2025
    risk 0.42cvss 6.5epss 0.00

    GMOD Apollo does not have sufficient logical or access checks when updating a user's information. This could result in an attacker being able to escalate privileges for themselves or others.

  • CVE-2024-9779HigDec 17, 2024
    risk 0.42cvss 7.5epss 0.00

    A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-manager or klusterlet deployments. The cluster-manager deployment uses a service account with the same name "cluster-manager" which is bound to a ClusterRole…

  • CVE-2024-11860MedNov 27, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This affects an unknown part of the file /rental/ajax.php?action=delete_tenant of the component POST Request Handler. The manipulation of the argument id leads to…

  • CVE-2024-47653MedOct 4, 2024
    risk 0.42cvss 6.5epss 0.00

    This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker could exploit this vulnerability by placing or cancelling requests through API request…