VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,702)

page 120 of 186
  • CVE-2026-83239HigSep 15, 2026
    risk 0.46cvss 7.0epss 0.00

    Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker…

  • CVE-2026-83150HigSep 15, 2026
    risk 0.46cvss 7.0epss 0.00

    Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Application Testing Suite executes to compromise Oracle…

  • CVE-2026-88863HigSep 10, 2026
    risk 0.46cvss 8.1epss 0.00

    capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts. The POST /private/invite_new_user_to_org endpoint only…

  • CVE-2026-19453HigSep 2, 2026
    risk 0.46cvss 7.1epss 0.00

    The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a subscriber-level user to gain administrator access after the site owner…

  • CVE-2026-73724HigSep 1, 2026
    risk 0.46cvss 7.1epss 0.00

    Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.

  • CVE-2026-73723HigSep 1, 2026
    risk 0.46cvss 7.1epss 0.00

    A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current…

  • CVE-2026-19423HigAug 28, 2026
    risk 0.46cvss 8.1epss 0.00

    The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing…

  • CVE-2026-16923HigAug 20, 2026
    risk 0.46cvss 7.0epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.

  • CVE-2026-70936HigAug 18, 2026
    risk 0.46cvss 7.1epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle…

  • CVE-2026-17744HigJul 30, 2026
    risk 0.46cvss 7.1epss 0.00

    Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-34496HigJul 23, 2026
    risk 0.46cvss —epss 0.00

    Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1.

  • CVE-2026-60492HigJul 21, 2026
    risk 0.46cvss 7.1epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: OW HR PR Foundation). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-47412HigJul 21, 2026
    risk 0.46cvss 8.1epss 0.01

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE /workspaces/{workspace_id}` endpoint is gated only by `require_workspace_member(workspace_id)`…

  • CVE-2026-47409HigJul 21, 2026
    risk 0.46cvss 8.1epss 0.01

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling owner lockout. The `DELETE /workspaces/{workspace_id}/members/{user_id}` endpoint is gated only by…

  • CVE-2026-47870HigJul 18, 2026
    risk 0.46cvss 7.1epss 0.00

    VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute remote code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in…

  • CVE-2026-56245HigJun 24, 2026
    risk 0.46cvss 8.2epss 0.00

    Supabase Capgo before 12.128.2 contains an authorization bypass vulnerability in the SECURITY DEFINER record_build_time RPC function that allows unauthenticated attackers to insert arbitrary build-time records. Attackers can exploit this by calling POST…

  • CVE-2026-54415HigJun 17, 2026
    risk 0.46cvss 8.1epss 0.00

    Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their…

  • CVE-2026-46914HigJun 17, 2026
    risk 0.46cvss 7.1epss 0.00

    Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise…

  • CVE-2026-53855HigJun 16, 2026
    risk 0.46cvss 8.1epss 0.00

    OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell positional parameters. Attackers can combine allowlisted tools with shell positional arguments to place inline-eval content in shell…

  • CVE-2024-38487HigJun 16, 2026
    risk 0.46cvss 7.0epss 0.00

    api-gateway container running with root privilege would allow an attacker to escape the container and access host system to perform unintended actions.