VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,180)

page 36 of 59
  • CVE-2026-90523HigSep 13, 2026
    risk 0.40cvss 7.3epss 0.01

    A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint.…

  • CVE-2026-77654MedSep 8, 2026
    risk 0.40cvss —epss 0.00

    Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the…

  • CVE-2026-11462HigJun 7, 2026
    risk 0.40cvss 7.3epss 0.00

    A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/StripeController.php of the component Stripe Plugin. Performing a manipulation of the argument Request results in…

  • CVE-2026-9795HigMay 28, 2026
    risk 0.40cvss 7.3epss 0.00

    A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability to assign any realm role, including highly privileged roles, to a client's scope mapping. This bypasses…

  • CVE-2026-9580HigMay 26, 2026
    risk 0.40cvss 7.3epss 0.00

    A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been…

  • CVE-2026-7505HigApr 30, 2026
    risk 0.40cvss 7.3epss 0.00

    A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used.…

  • CVE-2026-1411MedJan 26, 2026
    risk 0.40cvss 6.1epss 0.00

    A flaw has been found in Beetel 777VR1 up to 01.00.09/01.00.09_55. The affected element is an unknown function of the component UART Interface. This manipulation causes improper access controls. It is feasible to perform the attack on the physical device. The complexity of an…

  • CVE-2021-47799MedJan 15, 2026
    risk 0.40cvss 6.2epss 0.00

    Visual Tools DVR VX16 version 4.2.28 contains a local privilege escalation vulnerability in its Sudo configuration that allows attackers to gain root access. Attackers can exploit the unsafe Sudo settings by using mount commands to bind a shell, enabling unauthorized…

  • CVE-2022-50927MedJan 13, 2026
    risk 0.40cvss 6.2epss 0.00

    Cyclades Serial Console Server 3.3.0 contains a local privilege escalation vulnerability due to overly permissive sudo privileges for the admin user and admin group. Attackers can exploit the default user configuration to gain root access by manipulating system binaries and…

  • CVE-2025-64761HigNov 25, 2025
    risk 0.40cvss 7.2epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in the system. Specifically…

  • CVE-2025-53425HigOct 22, 2025
    risk 0.40cvss 7.2epss 0.00

    Incorrect Privilege Assignment vulnerability in Dokan, Inc. Dokan dokan-lite allows Privilege Escalation.This issue affects Dokan: from n/a through <= 4.1.3.

  • CVE-2025-5417MedAug 19, 2025
    risk 0.40cvss 6.1epss 0.00

    An insufficient access control vulnerability was found in the Red Hat Developer Hub rhdh/rhdh-hub-rhel9 container image. The Red Hat Developer Hub cluster admin/user, who has standard user access to the cluster, and the Red Hat Developer Hub namespace, can access the…

  • CVE-2025-54996HigAug 9, 2025
    risk 0.40cvss 7.2epss 0.00

    OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, accounts with access to highly-privileged identity entity systems in root namespaces were able to increase their…

  • CVE-2024-9180HigOct 10, 2024
    risk 0.40cvss 7.2epss 0.01

    A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16.

  • CVE-2024-42441MedAug 14, 2024
    risk 0.40cvss 6.2epss 0.00

    Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.

  • CVE-2026-63349HigSep 18, 2026
    risk 0.39cvss —epss 0.00

    AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_process() forwards the group argument to the…

  • CVE-2024-23976MedFeb 14, 2024
    risk 0.39cvss 6.0epss 0.00

    When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX templates on a BIG-IP system.  Note: Software versions which have reached End of Technical Support (EoTS) are not…

  • CVE-2026-1712MedMar 25, 2026
    risk 0.38cvss —epss 0.00

    Incorrect privilege assignment vulnerability in HYPR Server allows Privilege Escalation.This issue affects HYPR Server: from 10.5.1 before 10.7.

  • CVE-2025-29036MedApr 1, 2025
    risk 0.38cvss 5.9epss 0.00

    An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the user.js component.

  • CVE-2022-4041MedJan 31, 2023
    risk 0.38cvss 5.9epss 0.01

    Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.8.0 before 04.9.1.