VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 137 of 164
  • CVE-2023-43663MedSep 28, 2023
    risk 0.34cvss 6.3epss 0.00

    PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit `ce1f6708` addresses this…

  • CVE-2023-41312MedSep 27, 2023
    risk 0.34cvss 5.3epss 0.00

    Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatically.

  • CVE-2023-29056MedApr 28, 2023
    risk 0.34cvss 5.3epss 0.00

    A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined.

  • CVE-2021-4314MedJan 18, 2023
    risk 0.34cvss 5.3epss 0.00

    It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue affects: 1.16 versions to 1.19. What…

  • CVE-2022-1901MedAug 19, 2022
    risk 0.34cvss 5.3epss 0.00

    In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.

  • CVE-2017-20107MedJun 28, 2022
    risk 0.34cvss 5.3epss 0.00

    A vulnerability, which was classified as problematic, was found in ShadeYouVPN.com Client 2.0.1.11. Affected is an unknown function. The manipulation leads to improper privilege management. Local access is required to approach this attack. The exploit has been disclosed to the…

  • CVE-2022-30743MedJun 7, 2022
    risk 0.34cvss 5.3epss 0.00

    Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.

  • CVE-2022-30736MedJun 7, 2022
    risk 0.34cvss 5.3epss 0.00

    Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.

  • CVE-2022-0611MedFeb 16, 2022
    risk 0.34cvss 6.3epss 0.01

    Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.

  • CVE-2017-13165MedDec 6, 2017
    risk 0.34cvss 5.3epss 0.00

    An elevation of privilege vulnerability in the kernel file system. Product: Android. Versions: Android kernel. Android ID A-31269937.

  • CVE-2017-9662MedAug 14, 2017
    risk 0.34cvss 5.3epss 0.00

    An Improper Privilege Management issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. Monitouch V-SFT is installed in a directory with weak access controls by default, which could allow an authenticated attacker with local access to escalate…

  • CVE-2026-11276MedJun 5, 2026
    risk 0.33cvss 5.1epss 0.00

    Inappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to bypass discretionary access control via malicious network traffic. (Chromium security severity: Low)

  • CVE-2026-7778MedMay 5, 2026
    risk 0.33cvss 5.0epss 0.00

    An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N…

  • CVE-2026-6386MedApr 22, 2026
    risk 0.33cvss 6.2epss 0.00

    In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled this failed to take into account the presence of 1GB largepage mappings created using the shm_create_largepage(3)…

  • CVE-2026-40002MedApr 17, 2026
    risk 0.33cvss 5.0epss 0.00

    Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting this vulnerability, an attacker can write…

  • CVE-2025-57443MedOct 2, 2025
    risk 0.33cvss 5.1epss 0.00

    FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library-validation) that allow unprivileged local attackers to inject code into the FrostWire process via the DYLD_INSERT_LIBRARIES environment variable. This allows…

  • CVE-2024-23454MedSep 25, 2024
    risk 0.33cvss 6.2epss 0.00

    Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the other local users may be able to view the content. This is because, on unix-like systems, the system temporary directory is…

  • CVE-2023-38496MedJul 25, 2023
    risk 0.33cvss 6.1epss 0.00

    Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when requesting container network setup, therefore subsequent functions are called with root privileges, the attack surface is rather limited for users but an attacker…

  • CVE-2023-25188MedJun 16, 2023
    risk 0.33cvss 5.1epss 0.00

    An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from the Nokia Single RAN BTS baseband unit, the BTS baseband unit diagnostic tool AaShell (which is by default disabled) allows…

  • CVE-2022-29614MedJun 14, 2022
    risk 0.33cvss 5.0epss 0.00

    SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, SAPHOSTAGENT 7.22, -…