VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,702)

page 164 of 186
  • CVE-2023-20216MedAug 3, 2023
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An…

  • CVE-2023-0221MedJan 13, 2023
    risk 0.29cvss 4.4epss 0.00

    Product security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypass the execution controls provided by ACC using the utilman program.

  • CVE-2022-32782MedSep 23, 2022
    risk 0.29cvss 4.4epss 0.00

    This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information.

  • CVE-2022-32781MedSep 23, 2022
    risk 0.29cvss 4.4epss 0.00

    This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5, Security Update 2022-005 Catalina, macOS Big Sur 11.6.8. An app with root privileges may be able to access private information.

  • CVE-2022-30610MedJun 10, 2022
    risk 0.29cvss 4.5epss 0.01

    IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it. An administrator could enter a link to a malicious URL that another administrator…

  • CVE-2022-27840MedApr 11, 2022
    risk 0.29cvss 4.4epss 0.00

    Improper access control vulnerability in SamsungRecovery prior to version 8.1.43.0 allows local attckers to delete arbitrary files as SamsungRecovery permission.

  • CVE-2021-36931MedAug 26, 2021
    risk 0.29cvss 4.4epss 0.01

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2019-12522MedApr 15, 2020
    risk 0.29cvss 4.5epss 0.00

    An issue was discovered in Squid through 4.7. When Squid is run as root, it spawns its child processes as a lesser user, by default the user nobody. This is done via the leave_suid call. leave_suid leaves the Saved UID as 0. This makes it trivial for an attacker who has…

  • CVE-2019-1588MedMar 6, 2019
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vulnerability is due to a lack of proper input and validation…

  • CVE-2018-12261MedJun 12, 2018
    risk 0.29cvss 4.4epss 0.00

    An issue was discovered on Momentum Axel 720P 5.1.8 devices. All processes run as root.

  • CVE-2017-10689MedFeb 9, 2018
    risk 0.29cvss 5.5epss 0.00

    In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.

  • CVE-2018-1368MedFeb 9, 2018
    risk 0.29cvss 4.4epss 0.00

    IBM Security Guardium Database Activity Monitor 9.0, 9.1, and 9.5 could allow a local user with low privileges to view report pages and perform some actions that only an admin should be performing, so there is risk that someone not authorized can change things that they are not…

  • CVE-2026-86554MedSep 20, 2026
    risk 0.28cvss 4.3epss 0.00

    SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine…

  • CVE-2026-55226MedSep 15, 2026
    risk 0.28cvss 5.4epss 0.00

    Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, deploying only the Topic Operator or only the User Operator through the Kafka custom resource leaves the Entity Operator…

  • CVE-2026-90487MedSep 12, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupController.java. The manipulation results in improper privilege management. The…

  • CVE-2026-79276MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper privilege management in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-70443MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL.

  • CVE-2026-20308MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation.…

  • CVE-2026-48926MedMay 27, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2026-48923MedMay 27, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connect to an attacker-specified URL.