VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 123 of 164
  • CVE-2025-40594MedSep 9, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < V6.4 HF7), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed without the required privileges due to…

  • CVE-2025-8107MedJul 24, 2025
    risk 0.41cvss 6.3epss 0.00

    In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.

  • CVE-2025-53942HigJul 23, 2025
    risk 0.41cvss 7.4epss 0.00

    authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set of protocols. In versions 2025.4.4 and earlier, as well as versions 2025.6.0-rc1 through 2025.6.3, deactivated users who registered through OAuth/SAML or linked…

  • CVE-2024-1908MedMar 21, 2024
    risk 0.41cvss 6.3epss 0.01

    An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use the Enterprise Actions GitHub Connect download token to fetch private repository data. An attacker would require an account on the server instance with…

  • CVE-2024-0674MedJan 30, 2024
    risk 0.41cvss 6.3epss 0.00

    Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local user to acquire root permissions by modifying the updatescript.js, inserting special code inside the script and creating the done.txt file. This would cause…

  • CVE-2023-20274MedNov 21, 2023
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the installer script of Cisco AppDynamics PHP Agent could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient permissions that are set by the PHP Agent Installer on the PHP Agent…

  • CVE-2023-23629MedJan 28, 2023
    risk 0.41cvss 6.3epss 0.00

    Metabase is an open source data analytics platform. Affected versions are subject to Improper Privilege Management. As intended, recipients of dashboards subscriptions can view the data as seen by the creator of that subscription. This allows someone with greater access to data…

  • CVE-2022-4281MedDec 5, 2022
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /face-recognition-php/facepay-master/camera.php. The manipulation of the argument userId leads to authorization bypass. The attack can…

  • CVE-2021-43076MedSep 6, 2022
    risk 0.41cvss 6.3epss 0.00

    An improper privilege management vulnerability [CWE-269] in FortiADC versions 6.2.1 and below, 6.1.5 and below, 6.0.4 and below, 5.4.5 and below and 5.3.7 and below may allow a remote authenticated attacker with restricted user profile to modify the system files using the shell…

  • CVE-2019-25071MedJun 25, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Apple iPhone up to 12.4.1. It has been declared as critical. Affected by this vulnerability is Siri. Playing an audio or video file might be able to initiate Siri on the same device which makes it possible to execute commands remotely. Exploit…

  • CVE-2017-20081MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in Hindu Matrimonial Script. This affects an unknown part of the file /admin/reports.php. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2017-20080MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Hindu Matrimonial Script. Affected by this issue is some unknown functionality of the file /admin/googleads.php. The manipulation leads to improper privilege management. The attack may be launched remotely. The…

  • CVE-2017-20079MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in Hindu Matrimonial Script. Affected by this vulnerability is an unknown functionality of the file /admin/photo.php. The manipulation leads to improper privilege management. The attack can be launched remotely. The exploit has…

  • CVE-2017-20078MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in Hindu Matrimonial Script. Affected is an unknown function of the file /admin/featured.php. The manipulation leads to improper privilege management. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2017-20077MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Hindu Matrimonial Script. It has been rated as critical. This issue affects some unknown processing of the file /admin/success_story.php. The manipulation leads to improper privilege management. The attack may be initiated remotely. The exploit has…

  • CVE-2017-20076MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Hindu Matrimonial Script. It has been declared as critical. This vulnerability affects unknown code of the file /admin/searchview.php. The manipulation leads to improper privilege management. The attack can be initiated remotely. The exploit has been…

  • CVE-2017-20075MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Hindu Matrimonial Script. It has been classified as critical. This affects an unknown part of the file /admin/payment.php. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2017-20074MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Hindu Matrimonial Script and classified as critical. Affected by this issue is some unknown functionality of the file /admin/newsletter1.php. The manipulation leads to improper privilege management. The attack may be launched remotely. The exploit…

  • CVE-2017-20073MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in Hindu Matrimonial Script and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/cms.php. The manipulation leads to improper privilege management. The attack can be launched remotely. The exploit…

  • CVE-2017-20072MedJun 21, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in Hindu Matrimonial Script. Affected is an unknown function of the file /admin/generalsettings.php. The manipulation leads to improper privilege management. It is possible to launch the attack remotely. The exploit…