VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 158 of 164
  • CVE-2026-50295MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-49176HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

  • CVE-2026-53565HigJul 14, 2026
    risk 0.00cvss epss 0.00

    Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. This issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. 5.1.7.

  • CVE-2026-52533CriJul 13, 2026
    risk 0.00cvss 9.8epss 0.00

    An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file

  • CVE-2026-61463HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.00

    Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can escalate to administrator by submitting a crafted PATCH request with owner: true, then…

  • CVE-2026-59245HigJul 13, 2026
    risk 0.00cvss 8.1epss 0.00

    In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission…

  • CVE-2026-59260HigJul 12, 2026
    risk 0.00cvss 8.8epss 0.01

    OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global options such as message command to a root…

  • CVE-2026-14262HigJul 11, 2026
    risk 0.00cvss 8.8epss 0.00

    The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerability exists because…

  • CVE-2026-13756HigJul 11, 2026
    risk 0.00cvss 8.8epss 0.00

    The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key validation in the `update()` handler for the `/wp-json/wpgb/v2/metadata` REST endpoint. This makes it…

  • CVE-2026-55843MedJul 10, 2026
    risk 0.00cvss 6.5epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and PreserveUnauthorizedPrivilegedPermissionsAction in a way that can overwrite a target user’s…

  • CVE-2026-51119CriJul 10, 2026
    risk 0.00cvss 9.1epss 0.00

    An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components

  • CVE-2026-40009MedJul 10, 2026
    risk 0.00cvss 6.5epss 0.00

    Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor. This issue affects Apache IoTDB: from 2.0.8 before 2.0.10. Users are recommended to…

  • CVE-2026-44787HigJul 9, 2026
    risk 0.00cvss 8.2epss 0.00

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group membership on sites with…

  • CVE-2026-0275MedJul 9, 2026
    risk 0.00cvss 6.7epss 0.00

    A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform actions on the device with root privileges. This issue only affects Prisma® Browser on macOS.

  • CVE-2026-54652HigJul 8, 2026
    risk 0.00cvss 8.1epss 0.00

    Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the viewer role to download Frigate and nginx logs, exposing auto-generated admin passwords and camera credentials logged in request…

  • CVE-2026-14250MedJul 8, 2026
    risk 0.00cvss 6.3epss 0.00

    The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. This is due to the handle_frontend_register() function in the unauthenticated /thlogin/v1/register REST endpoint accepting a user-controlled…

  • CVE-2026-9842HigJul 8, 2026
    risk 0.00cvss 7.5epss 0.00

    The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This is due to the plugin assigning the `manage_options` capability to the `backstage_customizer_user` demo role, which is more…

  • CVE-2026-14482HigJul 8, 2026
    risk 0.00cvss 8.8epss 0.00

    The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The vulnerability exists due to a missing capability and nonce check on a directly web-accessible API endpoint, combined with a trivially forgeable…

  • CVE-2026-58583HigJul 7, 2026
    risk 0.00cvss 7.1epss 0.00

    FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege escalation for a standard user account via arbitrary physical memory mapping at \Device\PhysicalMemory. Fixed in version 1.0.7.6. The fixed driver is currently…

  • CVE-2026-53645HigJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow a low-privileged staff account to grant arbitrary module permissions to itself through the admin API, resulting in persistent privilege escalation. A staff user that only has…