VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 115 of 164
  • CVE-2021-42304MedNov 10, 2021
    risk 0.43cvss 6.6epss 0.01

    Azure RTOS Elevation of Privilege Vulnerability

  • CVE-2021-42303MedNov 10, 2021
    risk 0.43cvss 6.6epss 0.01

    Azure RTOS Elevation of Privilege Vulnerability

  • CVE-2021-42302MedNov 10, 2021
    risk 0.43cvss 6.6epss 0.01

    Azure RTOS Elevation of Privilege Vulnerability

  • CVE-2021-1371MedMar 24, 2021
    risk 0.43cvss 6.6epss 0.00

    A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker with read-only privileges to obtain administrative privileges by using the console port when the device is in the default SD-WAN configuration. This…

  • CVE-2021-1646MedJan 12, 2021
    risk 0.43cvss 6.6epss 0.01

    Windows WLAN Service Elevation of Privilege Vulnerability

  • CVE-2020-7274MedApr 15, 2020
    risk 0.43cvss 6.6epss 0.00

    Privilege escalation vulnerability in McTray.exe in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to spawn unrelated processes with elevated privileges via the system administrator granting McTray.exe elevated privileges (by…

  • CVE-2020-7259MedApr 15, 2020
    risk 0.43cvss 6.6epss 0.00

    Exploitation of Privilege/Trust vulnerability in file in McAfee Endpoint Security (ENS) Prior to 10.7.0 February 2020 Update allows local users to bypass local security protection via a carefully crafted input file

  • CVE-2020-6584MedMar 16, 2020
    risk 0.43cvss 6.5epss 0.04

    Nagios Log Server 2.1.3 has Incorrect Access Control.

  • CVE-2019-16777HigDec 13, 2019
    risk 0.43cvss 7.7epss 0.02

    Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any…

  • CVE-2019-12794MedJun 11, 2019
    risk 0.43cvss 6.6epss 0.01

    An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admins have the inherent ability to reset passwords for all of their organization's users). This, however, could be abused in a situation where the host…

  • CVE-2017-5623MedMar 19, 2017
    risk 0.43cvss 6.6epss 0.00

    An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of the device by issuing the 'fastboot oem boot_mode {rf/wlan/ftm/normal} command' in contradiction to the threat model of Android where the bootloader MUST NOT…

  • CVE-2026-18702MedAug 11, 2026
    risk 0.42cvss 6.4epss 0.00

    An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the intended database. This could allow suppression of diagnostic logging server-wide,…

  • CVE-2026-60183MedJul 21, 2026
    risk 0.42cvss 6.4epss 0.00

    Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit…

  • CVE-2026-12450MedJun 17, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-45254MedMay 21, 2026
    risk 0.42cvss 6.5epss 0.00

    In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key was treated as "allow any" instead of being rejected. In certain scenarios, an application that had previously restricted a subset of network operations could…

  • CVE-2026-46333HigMay 15, 2026
    risk 0.42cvss 7.1epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or not - and makes no sense when…

  • CVE-2026-33727MedApr 6, 2026
    risk 0.42cvss 6.4epss 0.00

    Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privilege-escalation vulnerability allows code execution as root from the low-privilege pihole account. Important context: the pihole account uses nologin, so this…

  • CVE-2026-33509HigMar 24, 2026
    risk 0.42cvss 7.5epss 0.01

    pyLoad is a free and open-source download manager written in Python. From version 0.4.0 to before version 0.5.0b3.dev97, the set_config_value() API endpoint allows users with the non-admin SETTINGS permission to modify any configuration option without restriction. The…

  • CVE-2026-2375MedMar 21, 2026
    risk 0.42cvss 6.5epss 0.00

    The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.5.10. This is due to the `verify_role()` function in `AuthTrails.php` explicitly whitelisting the `wcfm_vendor`…

  • CVE-2026-24894HigFeb 12, 2026
    risk 0.42cvss 7.5epss 0.00

    FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the…