VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,180)

page 59 of 59
  • CVE-2026-1895MedFeb 4, 2026
    risk 0.00cvss 6.3epss 0.00

    A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the component Attachment Storage Handler. Executing a manipulation can lead to improper access controls. The attack can be executed remotely. Upgrading to version…

  • CVE-2026-1894MedFeb 4, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js of the component REST API. Performing a manipulation of the argument item.cardId/item.checklistId/card.boardId results in improper authorization. Remote…

  • CVE-2026-1892MedFeb 4, 2026
    risk 0.00cvss 5.0epss 0.00

    A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.js of the component REST API. Such manipulation of the argument item.cardId/item.checklistId/card.boardId leads to improper authorization. The attack…

  • CVE-2025-14503HigDec 15, 2025
    risk 0.00cvss 7.2epss 0.01

    An overly-permissive IAM trust policy in the Harmonix on AWS framework may allow IAM principals in the same AWS account to escalate privileges via role assumption. The sample code for the EKS environment provisioning role is configured to trust the account root principal, which…

  • CVE-2025-65094HigNov 19, 2025
    risk 0.00cvss 8.8epss 0.00

    WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrators group by manipulating the groups[] parameter in the /admin/users/save.php request. The UI restricts users to assigning only…

  • CVE-2025-59945HigSep 27, 2025
    risk 0.00cvss 8.1epss 0.00

    SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can assign the is_project_admin permission to their own user. This allows users to read, modify and delete pentesting…

  • CVE-2025-8547MedAug 5, 2025
    risk 0.00cvss 5.3epss 0.00

    A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as critical. This vulnerability affects unknown code of the component Email Verification Handler. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been…

  • CVE-2025-5409HigJun 1, 2025
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was found in Mist Community Edition up to 4.7.1. It has been classified as critical. This affects the function create_token of the file src/mist/api/auth/views.py of the component API Token Handler. The manipulation leads to improper access controls. It is…

  • CVE-2025-3202HigApr 4, 2025
    risk 0.00cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in ageerle ruoyi-ai up to 2.0.0. Affected is an unknown function of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysNoticeController.java. The manipulation leads to improper…

  • CVE-2025-3199HigApr 4, 2025
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was found in ageerle ruoyi-ai up to 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysModelController.java of the component API…

  • CVE-2025-2713HigMar 28, 2025
    risk 0.00cvss 7.8epss 0.00

    Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions…

  • CVE-2024-37293HigJun 11, 2024
    risk 0.00cvss 7.5epss 0.00

    The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization. ADF allows for staged, parallel, multi-account, cross-region deployments of applications or resources via the structure defined…

  • CVE-2022-2626HigAug 5, 2022
    risk 0.00cvss 7.2epss 0.01

    Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.

  • CVE-2022-1225MedApr 4, 2022
    risk 0.00cvss 6.5epss 0.01

    Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.

  • CVE-2019-11245MedAug 29, 2019
    risk 0.00cvss 4.9epss 0.01

    In kubelet v1.13.6 and v1.14.2, containers for pods that do not specify an explicit runAsUser attempt to run as uid 0 (root) on container restart, or if the image was previously pulled to the node. If the pod specified mustRunAsNonRoot: true, the kubelet will refuse to start the…

  • CVE-2019-10143HigMay 24, 2019
    risk 0.00cvss 7.0epss 0.00

    It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a radiusd-writable file to a…

  • CVE-2015-1814Oct 16, 2015
    risk 0.00cvss —epss 0.02

    The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.

  • CVE-2015-1806Oct 16, 2015
    risk 0.00cvss —epss 0.03

    The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.

  • CVE-2014-3490Aug 19, 2014
    risk 0.00cvss —epss 0.05

    RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read…

  • CVE-2014-1402May 19, 2014
    risk 0.00cvss —epss 0.00

    The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp.