VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,703)

page 161 of 186
  • CVE-2024-6908MedJul 19, 2024
    risk 0.32cvss —epss 0.00

    Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin via a crafted PUT HTTP request, potentially leading to unauthorized access to sensitive system functions and data.

  • CVE-2024-30473MedJul 18, 2024
    risk 0.32cvss 4.9epss 0.00

    Dell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privileged attacker could potentially exploit this vulnerability, gaining access to unauthorized end points.

  • CVE-2024-22513MedMar 16, 2024
    risk 0.32cvss 5.5epss 0.01

    djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources even after their account has been disabled due to missing user validation checks via the for_user method.

  • CVE-2023-40686MedOct 29, 2023
    risk 0.32cvss 4.9epss 0.00

    Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with command line access to the operating system can exploit this vulnerability to elevate privileges to gain component access to the…

  • CVE-2023-40377MedOct 16, 2023
    risk 0.32cvss 4.9epss 0.00

    Backup, Recovery, and Media Services (BRMS) for IBM i 7.2, 7.3, and 7.4 contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain component access to the host operating system. …

  • CVE-2023-40378MedOct 15, 2023
    risk 0.32cvss 4.9epss 0.00

    IBM Directory Server for IBM i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain component access to the host operating system. IBM X-Force ID: 263584.

  • CVE-2023-41322MedSep 27, 2023
    risk 0.32cvss 4.9epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. A user with write access to another user can make requests to change the latter's…

  • CVE-2023-20194MedSep 7, 2023
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected…

  • CVE-2022-39182MedJan 12, 2023
    risk 0.32cvss 4.9epss 0.00

    H C Mingham-Smith Ltd - Tardis 2000 Privilege escalation.Version 1.6 is vulnerable to privilege escalation which may allow a malicious actor to gain system privileges.

  • CVE-2022-35774MedAug 9, 2022
    risk 0.32cvss 4.9epss 0.02

    Azure Site Recovery Elevation of Privilege Vulnerability

  • CVE-2020-23128MedMay 6, 2021
    risk 0.32cvss 4.9epss 0.01

    Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.

  • CVE-2018-15321MedOct 31, 2018
    risk 0.32cvss 4.9epss 0.01

    When BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Management 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, iWorkflow 2.1.0-2.3.0, or Enterprise Manager 3.1.1 is licensed for Appliance Mode, Admin…

  • CVE-2026-71105MedAug 18, 2026
    risk 0.31cvss 4.7epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle…

  • CVE-2026-19360MedAug 9, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The…

  • CVE-2026-12313MedJun 16, 2026
    risk 0.31cvss 4.7epss 0.00

    Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-1726MedApr 23, 2026
    risk 0.31cvss 4.8epss 0.00

    IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthorized users to perform administrative operations after being demoted. Attackers could access sensitive data, modify system configurations, or change…

  • CVE-2026-32035MedMar 19, 2026
    risk 0.31cvss 5.9epss 0.00

    OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in agentCommand, causing the flag to default to true. Non-owner voice participants can exploit this omission to access owner-only tools including gateway and cron…

  • CVE-2025-50064MedJul 15, 2025
    risk 0.31cvss 4.8epss 0.00

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to…

  • CVE-2025-1425MedMar 4, 2025
    risk 0.31cvss —epss 0.00

    A Sudo privilege misconfiguration vulnerability in PocketBook InkPad Color 3 on Linux, ARM allows attackers to read file contents on the device.This issue affects InkPad Color 3: U743k3.6.8.3671.

  • CVE-2024-13058MedDec 30, 2024
    risk 0.31cvss —epss 0.00

    An issue exists in SoftIron HyperCloud where authenticated, but non-admin users can create data pools, which could potentially impact the performance and availability of the backend software-defined storage subsystem. This issue only impacts SoftIron HyperCloud and related…