VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,703)

page 159 of 186
  • CVE-2026-70974MedAug 18, 2026
    risk 0.34cvss 5.3epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-19928MedAug 16, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a manipulation can lead to improper privilege management. The…

  • CVE-2026-40001MedMay 6, 2026
    risk 0.34cvss 5.2epss 0.00

    There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which may allow local arbitrary code execution, privilege escalation and path traversal bypass.

  • CVE-2026-34397MedApr 1, 2026
    risk 0.34cvss 6.3epss 0.00

    Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From versions 2.0.0-alpha to before 2.3.9 and 3.0.0-alpha to before 3.1.1, there is a conditional local privilege escalation vulnerability in an edge-case naming collision. Only authenticated…

  • CVE-2025-64436MedNov 7, 2025
    risk 0.34cvss 5.3epss 0.00

    KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node. This…

  • CVE-2021-43768MedOct 24, 2025
    risk 0.34cvss 5.3epss 0.00

    In Malwarebytes For Teams v.1.0.990 and before and fixed in v.1.0.1003 and later a privilege escalation can occur via the COM interface running in mbamservice.exe.

  • CVE-2025-32098MedSep 2, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insecure file delete operations during the update process.

  • CVE-2025-55627MedAug 22, 2025
    risk 0.34cvss 5.3epss 0.00

    Insufficient privilege verification in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows authenticated attackers to create accounts with elevated privileges.

  • CVE-2025-26705MedMar 11, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

  • CVE-2025-26707MedMar 11, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

  • CVE-2024-30150MedFeb 25, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure and potential for Server-Side Request Forgery (SSRF) and Denial of Service(DOS) attacks from unauthenticated users.

  • CVE-2024-45297MedOct 7, 2024
    risk 0.34cvss 5.3epss 0.00

    Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the label/name of that tag. This issue has been patched in the latest stable, beta and tests-passed version of Discourse. All users area are advised to upgrade.…

  • CVE-2024-21118MedApr 16, 2024
    risk 0.34cvss 5.3epss 0.00

    Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions that are affected are 8.5.6 and 8.5.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where…

  • CVE-2024-22239MedFeb 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain regular shell access.

  • CVE-2023-46756MedNov 8, 2023
    risk 0.34cvss 5.3epss 0.00

    Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows.

  • CVE-2023-43663MedSep 28, 2023
    risk 0.34cvss 6.3epss 0.00

    PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit `ce1f6708` addresses this…

  • CVE-2023-41312MedSep 27, 2023
    risk 0.34cvss 5.3epss 0.00

    Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatically.

  • CVE-2023-29056MedApr 28, 2023
    risk 0.34cvss 5.3epss 0.00

    A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined.

  • CVE-2021-4314MedJan 18, 2023
    risk 0.34cvss 5.3epss 0.00

    It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue affects: 1.16 versions to 1.19. What…

  • CVE-2022-1901MedAug 19, 2022
    risk 0.34cvss 5.3epss 0.01

    In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.