VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 145 of 164
  • CVE-2026-20607MedMar 25, 2026
    risk 0.26cvss 4.0epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access protected user data.

  • CVE-2025-24353MedJan 23, 2025
    risk 0.26cvss 5.0epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.2.0, when sharing an item, a typical user can specify an arbitrary role. It allows the user to use a higher-privileged role to see fields that otherwise the user should not be…

  • CVE-2023-23438MedDec 29, 2023
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions

  • CVE-2023-23429MedDec 29, 2023
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

  • CVE-2023-23427MedDec 29, 2023
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

  • CVE-2022-30739MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number with a normal level permission.

  • CVE-2022-29587MedMay 16, 2022
    risk 0.26cvss 4.0epss 0.00

    Konica Minolta bizhub MFP devices before 2022-04-14 have an internal Chromium browser that executes with root (aka superuser) access privileges.

  • CVE-2022-22266MedJan 10, 2022
    risk 0.26cvss 4.0epss 0.00

    (Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.

  • CVE-2022-22263MedJan 10, 2022
    risk 0.26cvss 4.0epss 0.00

    Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity.

  • CVE-2021-25515MedDec 8, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.

  • CVE-2021-36943MedAug 12, 2021
    risk 0.26cvss 4.0epss 0.01

    Azure CycleCloud Elevation of Privilege Vulnerability

  • CVE-2026-56212LowJun 20, 2026
    risk 0.25cvss 3.8epss 0.00

    Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable mandatory two-factor authentication for all team members without first enabling 2FA on their own account. The application fails to…

  • CVE-2026-50565MedJun 10, 2026
    risk 0.25cvss 4.9epss 0.00

    Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission builder pods were created with ServiceAccountName: fission-builder and no AutomountServiceAccountToken:…

  • CVE-2025-5494LowSep 25, 2025
    risk 0.25cvss 3.9epss 0.00

    ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.

  • CVE-2025-6943LowJul 2, 2025
    risk 0.25cvss 3.8epss 0.00

    Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables.

  • CVE-2024-51324LowFeb 11, 2025
    risk 0.25cvss 3.8epss 0.00

    An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (Bring Your Own Vulnerable Driver) attack.

  • CVE-2023-25185LowJun 16, 2023
    risk 0.25cvss 3.8epss 0.00

    An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN software releases. Certain software processes in the BTS internal software design have unnecessarily high privileges to BTS…

  • CVE-2020-7255LowApr 15, 2020
    risk 0.25cvss 3.9epss 0.00

    Privilege escalation vulnerability in the administrative user interface in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to gain elevated privileges via ENS not checking user permissions when editing configuration in the ENS…

  • CVE-2020-5253LowMar 10, 2020
    risk 0.25cvss 3.9epss 0.01

    NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited. This bug is patched in NetHack 3.6.0.

  • CVE-2019-14838MedOct 14, 2019
    risk 0.25cvss 4.9epss 0.01

    A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server