VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,180)

page 45 of 59
  • CVE-2025-0206MedJan 4, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability classified as critical was found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit…

  • CVE-2024-13109MedJan 2, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. It has been rated as critical. This issue affects some unknown processing of the file /doc.html. The manipulation leads to improper authorization. The attack may be…

  • CVE-2024-12901MedDec 23, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/Site.php of the component API Endpoint. The manipulation of the argument password leads to improper authorization. The…

  • CVE-2024-12347MedDec 9, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This issue affects some unknown processing of the file /jeewms_war/webpage/system/druid/index.html of the component Druid Monitoring Interface. The manipulation…

  • CVE-2023-26280MedNov 25, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM Jazz Foundation 7.0.2 and 7.0.3 could allow a user to change their dashboard using a specially crafted HTTP request due to improper access control.

  • CVE-2024-11306MedNov 18, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. This issue affects some unknown processing of the file /index.php/display/database/. The manipulation leads to improper authorization. The attack may be…

  • CVE-2024-23794MedJul 15, 2024
    risk 0.34cvss 5.2epss 0.00

    An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an agent with read-only permissions to gain full access to a ticket. This issue arises in very rare instances when an admin has…

  • CVE-2023-7270MedJun 27, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision 1215. FreeOffice 2021 is also affected, but won't be fixed. The SoftMaker Office and FreeOffice MSI installer files were found to produce a visible…

  • CVE-2020-36624MedDec 22, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was found in ahorner text-helpers up to 1.0.x. It has been declared as critical. This vulnerability affects unknown code of the file lib/text_helpers/translation.rb. The manipulation of the argument link leads to use of web link to untrusted target with…

  • CVE-2026-82594MedAug 31, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to improper authorization. The attack may be performed from remote. A high complexity level is…

  • CVE-2026-82486MedAug 30, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument SecurityKey results in improper access controls. Remote exploitation of the attack is…

  • CVE-2026-20028MedAug 5, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to…

  • CVE-2025-65842MedDec 3, 2025
    risk 0.33cvss 5.1epss 0.00

    The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege escalation. The service accepts XPC connections from any local process without validating the client's identity, and its authorization logic incorrectly calls…

  • CVE-2025-12103MedOct 28, 2025
    risk 0.33cvss 5.0epss 0.00

    A flaw was found in Red Hat Openshift AI Service. The TrustyAI component is granting all service accounts and users on a cluster permissions to get, list, watch any pod in any namespace on the cluster. TrustyAI is creating a role `trustyai-service-operator-lmeval-user-role`…

  • CVE-2025-11281MedOct 5, 2025
    risk 0.33cvss 5.0epss 0.00

    A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished Course Handler. Such manipulation leads to improper access controls. The attack may be launched remotely. This attack is…

  • CVE-2025-43260MedJul 30, 2025
    risk 0.33cvss 5.1epss 0.00

    This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to hijack entitlements granted to other privileged apps.

  • CVE-2025-23260MedJun 24, 2025
    risk 0.33cvss 5.0epss 0.00

    NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access by using the ServiceAccount attached to the ClusterRole. A successful exploit of this vulnerability may lead to information disclosure.

  • CVE-2024-9476MedNov 13, 2024
    risk 0.33cvss —epss 0.00

    A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.This vulnerability will only affect users who…

  • CVE-2023-3114MedJun 22, 2023
    risk 0.33cvss 5.0epss 0.00

    Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the workspace to be targeted by unauthorized agents. This authorization flaw could potentially allow a workspace to access resources from a separate, higher-privileged…

  • CVE-2022-4613MedDec 19, 2022
    risk 0.33cvss 5.0epss 0.01

    A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as critical. This issue affects some unknown processing of the component Browser Extension Provisioning. The manipulation leads to improper authorization. The…