VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 140 of 164
  • CVE-2017-13721MedOct 10, 2017
    risk 0.31cvss 4.7epss 0.00

    In X.Org Server (aka xserver and xorg-server) before 1.19.4, an attacker authenticated to an X server with the X shared memory extension enabled can cause aborts of the X server or replace shared memory segments of other X clients in the same session.

  • CVE-2026-21981MedJan 20, 2026
    risk 0.30cvss 4.6epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…

  • CVE-2025-31286MedApr 2, 2025
    risk 0.30cvss 4.6epss 0.00

    An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code. Please note: this issue has already been addressed on the backend service and is no longer considered an active vulnerability.

  • CVE-2025-31285MedApr 2, 2025
    risk 0.30cvss 4.6epss 0.00

    A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already…

  • CVE-2025-31284MedApr 2, 2025
    risk 0.30cvss 4.6epss 0.00

    A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been…

  • CVE-2025-31283MedApr 2, 2025
    risk 0.30cvss 4.6epss 0.00

    A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already…

  • CVE-2025-31282MedApr 2, 2025
    risk 0.30cvss 4.6epss 0.00

    A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already…

  • CVE-2024-47770MedFeb 3, 2025
    risk 0.30cvss 4.6epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based environments. This vulnerability occurs when the system has weak privilege access,…

  • CVE-2023-28436MedMar 23, 2023
    risk 0.30cvss 5.7epss 0.00

    Tailscale is software for using Wireguard and multi-factor authentication (MFA). A vulnerability identified in the implementation of Tailscale SSH starting in version 1.34.0 and prior to prior to 1.38.2 in FreeBSD allows commands to be run with a higher privilege group ID than…

  • CVE-2026-44119MedJun 8, 2026
    risk 0.29cvss 5.5epss 0.00

    Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. This issue affects Apache HTTP Server: from through 2.4.67. Users are recommended to upgrade to version…

  • CVE-2026-42185MedMay 8, 2026
    risk 0.29cvss 5.5epss 0.00

    People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0, a user holding the Administrator role on a mail domain could send a crafted invitation request to promote any existing user (including users with no current…

  • CVE-2025-70795MedApr 17, 2026
    risk 0.29cvss 5.5epss 0.00

    STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficient caller validation in the driver's…

  • CVE-2026-34218MedMar 31, 2026
    risk 0.29cvss 5.5epss 0.00

    ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.14, two related startup defects created a window during which only the single compile-time baseline rule was enforced by opfilter. All managed…

  • CVE-2026-29111MedMar 23, 2026
    risk 0.29cvss 5.5epss 0.00

    systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version…

  • CVE-2025-24805MedFeb 5, 2025
    risk 0.29cvss 5.5epss 0.00

    Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to make use of an access token for materials for scopes which it…

  • CVE-2024-2432MedMar 13, 2024
    risk 0.29cvss 4.5epss 0.00

    A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

  • CVE-2023-42952MedFeb 21, 2024
    risk 0.29cvss 4.4epss 0.00

    The issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.1. An app with root privileges may be able to access private information.

  • CVE-2023-51430MedDec 29, 2023
    risk 0.29cvss 4.4epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.

  • CVE-2021-26734MedOct 23, 2023
    risk 0.29cvss 4.4epss 0.00

    Zscaler Client Connector Installer on Windows before version 3.4.0.124 improperly handled directory junctions during uninstallation. A local adversary may be able to delete folders in an elevated context.

  • CVE-2023-20216MedAug 3, 2023
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An…