VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,702)

page 167 of 186
  • CVE-2020-7908MedJan 30, 2020
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.

  • CVE-2018-16268MedJan 22, 2020
    risk 0.28cvss 4.3epss 0.01

    The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actions, due to improper D-Bus security policy configurations. Such actions include playing an arbitrary sound file or DTMF tones. This affects Tizen before 5.0 M1,…

  • CVE-2019-20043MedDec 27, 2019
    risk 0.28cvss 4.3epss 0.02

    In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such…

  • CVE-2019-3990MedDec 3, 2019
    risk 0.28cvss 4.3epss 0.01

    A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the…

  • CVE-2019-13705MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.3904.70 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.

  • CVE-2019-18365MedOct 31, 2019
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.

  • CVE-2015-9390MedSep 20, 2019
    risk 0.28cvss 4.3epss 0.01

    The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled.

  • CVE-2019-4047MedApr 29, 2019
    risk 0.28cvss 4.3epss 0.01

    IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest user, and obtain the information of the server execution. IBM X-Force ID: 156243.

  • CVE-2019-4222MedApr 25, 2019
    risk 0.28cvss 4.3epss 0.01

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user to view process definition of a business process without permission. IBM X-Force ID: 159231.

  • CVE-2018-0503MedOct 4, 2018
    risk 0.28cvss 4.3epss 0.02

    Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'.

  • CVE-2018-1000503MedJun 26, 2018
    risk 0.28cvss 4.3epss 0.01

    MyBB Group MyBB contains a Incorrect Access Control vulnerability in Private forums that can result in Users can view posts from private forums without having the password. This attack appear to be exploitable via Subscribe to a forum through IDOR. This vulnerability appears to…

  • CVE-2018-0566MedJun 26, 2018
    risk 0.28cvss 4.3epss 0.01

    Cybozu Office 10.0.0 to 10.8.0 allows authenticated attackers to bypass authentication to obtain the schedules without access privilege via unspecified vectors.

  • CVE-2017-10857MedOct 12, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Office 10.0.0 to 10.6.1 allows authenticated attackers to bypass access restriction to perform arbitrary actions via "Cabinet" function.

  • CVE-2017-1326MedJun 22, 2017
    risk 0.28cvss 4.3epss 0.01

    IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-Force ID: 126060.

  • CVE-2017-2094MedApr 28, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Workflow and the "MultiReport" function to alter or delete information via unspecified vectors.

  • CVE-2017-0360MedApr 4, 2017
    risk 0.28cvss 5.3epss 0.02

    file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same root name but with a suffix" attack. NOTE: This vulnerability exists because of an incomplete fix for CVE-2016-1242.

  • CVE-2016-7570MedOct 3, 2016
    risk 0.28cvss 4.3epss 0.02

    Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.

  • CVE-2026-84358MedSep 2, 2026
    risk 0.27cvss 4.2epss 0.00

    Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-33074MedMar 31, 2026
    risk 0.27cvss 5.3epss 0.00

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, a user may be able to purchase a lower tier subscription but grant themselves the benefits that comes…

  • CVE-2026-23990MedJan 21, 2026
    risk 0.27cvss 5.3epss 0.00

    The Flux Operator is a Kubernetes CRD controller that manages the lifecycle of CNCF Flux CD and the ControlPlane enterprise distribution. Starting in version 0.36.0 and prior to version 0.40.0, a privilege escalation vulnerability exists in the Flux Operator Web UI…