VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 104 of 164
  • CVE-2026-21223HigJan 16, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.

  • CVE-2025-53914HigSep 9, 2025
    risk 0.46cvss epss 0.00

    Excessive Privileges vulnerability in Calix GigaCenter ONT (Broadcom SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G, 813G, 818G.

  • CVE-2025-53913HigSep 9, 2025
    risk 0.46cvss epss 0.00

    Excessive Privileges vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G, 813G, 818G.

  • CVE-2025-58437HigSep 6, 2025
    risk 0.46cvss 8.1epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insecure session handling in prebuilt workspaces. Coder automatically generates a session token for a…

  • CVE-2025-26513HigAug 7, 2025
    risk 0.46cvss 7.0epss 0.00

    The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when successfully exploited could allow a local user to escalate their privileges.

  • CVE-2024-48729HigJul 25, 2025
    risk 0.46cvss 7.1epss 0.00

    An issue in ETSI Open-Source MANO (OSM) 14.0.x before 14.0.3, 15.0.x before 15.0.2, 16.0.0, and 17.0.0 allows a remote authenticated attacker to escalate privileges via the /osm/admin/v1/users component.

  • CVE-2025-53003HigJul 1, 2025
    risk 0.46cvss epss 0.00

    The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without scope verification. This has a large internal surface attack area that exposes all sorts of information from the IDP including…

  • CVE-2025-49156HigJun 17, 2025
    risk 0.46cvss 7.0epss 0.00

    A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to…

  • CVE-2025-27468HigMay 13, 2025
    risk 0.46cvss 7.0epss 0.00

    Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

  • CVE-2025-4085HigApr 29, 2025
    risk 0.46cvss 7.1epss 0.00

    An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability was fixed in Firefox 138 and Thunderbird 138.

  • CVE-2024-2297HigFeb 27, 2025
    risk 0.46cvss 7.1epss 0.00

    The Bricks theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.6.1. This is due to insufficient validation checks placed on the create_autosave AJAX function. This makes it possible for authenticated attackers, with…

  • CVE-2025-0651HigJan 22, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low system privileges  can create a set of symlinks inside the C:\ProgramData\Cloudflare\warp-diag-partials folder. After triggering the 'Reset all settings" option…

  • CVE-2020-9222HigDec 27, 2024
    risk 0.46cvss 7.0epss 0.00

    There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be deserialized, local attackers can exploit this vulnerability to elevate permissions. (Vulnerability ID: HWPSIRT-2020-05241) This…

  • CVE-2024-11721HigDec 14, 2024
    risk 0.46cvss 8.1epss 0.01

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.24.5. This is due to insufficient controls on the user role select field when utilizing the 'Role' field in a form. This makes it possible for…

  • CVE-2024-10203HigNov 7, 2024
    risk 0.46cvss 7.0epss 0.00

    Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines.

  • CVE-2024-3656HigOct 9, 2024
    risk 0.46cvss 8.1epss 0.03

    A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to perform actions reserved for administrators, potentially leading to data breaches or system compromise.

  • CVE-2023-22576HigAug 21, 2024
    risk 0.46cvss 7.0epss 0.00

    Dell Repository Manager version 3.4.2 and earlier, contain a Local Privilege Escalation Vulnerability in Installation module. A local low privileged attacker may potentially exploit this vulnerability leading to the execution of arbitrary executable on the operating system with…

  • CVE-2024-22069HigAug 8, 2024
    risk 0.46cvss 7.1epss 0.00

    There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.

  • CVE-2024-42050HigJul 28, 2024
    risk 0.46cvss 7.0epss 0.00

    The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM via an oplock on CredProvider_Inst.reg.

  • CVE-2024-34725HigJul 9, 2024
    risk 0.46cvss 7.0epss 0.00

    In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.