VYPR

CWE-267

Privilege Defined With Unsafe Actions

BaseIncomplete

Description

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-58 · CAPEC-634 · CAPEC-637 · CAPEC-643 · CAPEC-648

CVEs mapped to this weakness (65)

page 3 of 4
  • CVE-2019-10170MedMay 8, 2020
    risk 0.43cvss 6.6epss 0.01

    A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the policy. This flaw allows an attacker with authenticated user and realm management permissions to configure a malicious script to trigger and execute arbitrary…

  • CVE-2019-10169MedMay 8, 2020
    risk 0.43cvss 6.6epss 0.01

    A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy. This flaw allows an authenticated attacker with UMA permissions to configure a malicious script to trigger and execute arbitrary code with the permissions…

  • CVE-2025-53900MedNov 29, 2025
    risk 0.42cvss 6.5epss 0.01

    Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of roles and permissions in Kiteworks MFT on managing Connections could lead to unexpected escalation of privileges for authorized users. This issue has been patched…

  • CVE-2025-61754MedOct 21, 2025
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 7.6.0.0.0 and 8.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2025-7691MedSep 26, 2025
    risk 0.42cvss 6.5epss 0.00

    A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 that could have allowed a developer with specific group management permissions to escalate their privileges and obtain…

  • CVE-2025-7030MedJul 8, 2025
    risk 0.42cvss 6.5epss 0.00

    Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.11.0.

  • CVE-2023-41966MedOct 26, 2023
    risk 0.42cvss 6.5epss 0.01

    The application suffers from a privilege escalation vulnerability. A user with read permissions can elevate privileges by sending a HTTP POST to set a parameter.

  • CVE-2020-7824MedAug 25, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get administrator permission. The vulnerability is due to insecure permission when handling session cookies. An attacker could exploit this vulnerability by…

  • CVE-2023-27895MedMar 14, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP Authenticator for Android - version 1.3.0, allows the screen to be captured, if an authorized attacker installs a malicious app on the mobile device. The attacker could extract the currently views of the OTP and the secret OTP alphanumeric token during the token setup. On…

  • CVE-2025-62591MedOct 21, 2025
    risk 0.39cvss 6.0epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…

  • CVE-2019-14865MedNov 29, 2019
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be truncated and leaving the system unbootable on subsequent reboots.

  • CVE-2022-38124MedDec 13, 2022
    risk 0.37cvss 5.7epss 0.01

    Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.

  • CVE-2025-53070MedOct 21, 2025
    risk 0.36cvss 5.5epss 0.00

    Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise…

  • CVE-2025-13979MedJan 28, 2026
    risk 0.35cvss 5.4epss 0.00

    Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site: from 0.0.0 before 3.0.2.

  • CVE-2025-62289MedOct 21, 2025
    risk 0.32cvss 4.9epss 0.00

    Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS…

  • CVE-2025-62288MedOct 21, 2025
    risk 0.32cvss 4.9epss 0.00

    Vulnerability in the Oracle Health Sciences Data Management Workbench product of Oracle Health Sciences Applications (component: Logger). Supported versions that are affected are 3.4.0.1.3 and 3.4.1.0.10. Easily exploitable vulnerability allows high privileged attacker with…

  • CVE-2023-28049MedFeb 6, 2024
    risk 0.31cvss 4.7epss 0.00

    Dell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authenticated malicious user may exploit this vulnerability in order to perform a privileged arbitrary file delete.

  • CVE-2024-8631MedSep 12, 2024
    risk 0.29cvss 5.5epss 0.01

    A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include…

  • CVE-2025-47811MedJul 10, 2025
    risk 0.27cvss 4.1epss 0.04

    In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or SYSTEM by default. The web application itself offers several legitimate ways to execute arbitrary system commands (i.e., through the web console or the task…

  • CVE-2026-6816LowMay 28, 2026
    risk 0.25cvss 3.8epss 0.00

    An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2.