VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,702)

page 173 of 186
  • CVE-2024-46989LowSep 18, 2024
    risk 0.17cvss 3.7epss 0.00

    spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Multiple caveats over the same indirect subject type on the same relation can result in no permission being returned when permission is…

  • CVE-2024-39302LowJun 28, 2024
    risk 0.17cvss 3.7epss 0.00

    BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file permissions in the `/usr/local/bigbluebutton/core/vendor/bundle/ruby/2.7.0/gems/resque-2.6.0` directory with the goal…

  • CVE-2026-73747LowSep 1, 2026
    risk 0.16cvss 2.5epss 0.00

    A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user with local access to elevate their user privileges and make limited modifications on the affected…

  • CVE-2023-21512LowJun 28, 2023
    risk 0.16cvss 2.4epss 0.00

    Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission.

  • CVE-2022-1606LowNov 30, 2022
    risk 0.16cvss 2.4epss 0.00

    Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.

  • CVE-2022-35921LowAug 1, 2022
    risk 0.16cvss 3.5epss 0.01

    fof/byobu is a private discussions extension for Flarum forum. Affected versions were found to not respect private discussion disablement by users. Users of Byobu should update the extension to version 1.1.7, where this has been patched. Users of Byobu with Flarum 1.0 or 1.1…

  • CVE-2021-25513LowDec 8, 2021
    risk 0.16cvss 2.4epss 0.00

    An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthorized access to some device data on the lockscreen.

  • CVE-2019-4266LowMay 6, 2020
    risk 0.16cvss 2.4epss 0.00

    IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 does not have device jailbreak detection which could result in an attacker gaining sensitive information about the device. IBM X-Force ID: 160199.

  • CVE-2025-53029LowJul 15, 2025
    risk 0.15cvss 2.3epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes…

  • CVE-2017-10292LowOct 19, 2017
    risk 0.15cvss 2.3epss 0.00

    Vulnerability in the RDBMS Security component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create User privilege with logon to the infrastructure where…

  • CVE-2026-46696LowSep 14, 2026
    risk 0.14cvss 3.3epss 0.00

    October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. The Laravel session store was exposed to…

  • CVE-2025-57840LowDec 24, 2025
    risk 0.14cvss 2.2epss 0.00

    ADB(Android Debug Bridge) is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability.

  • CVE-2025-61786LowOct 8, 2025
    risk 0.14cvss 3.3epss 0.00

    Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype.stat` and `Deno.FsFile.prototype.statSync` are not limited by the permission model check `--deny-read=./`. It's possible to retrieve stats from files that the…

  • CVE-2024-21101LowApr 16, 2024
    risk 0.14cvss 2.2epss 0.00

    Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.5.33 and prior, 7.6.29 and prior, 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with…

  • CVE-2023-5549LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.01

    Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.

  • CVE-2019-4048LowJun 6, 2019
    risk 0.14cvss 2.1epss 0.00

    IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311.

  • CVE-2026-44218LowMay 12, 2026
    risk 0.13cvss 3.0epss 0.00

    ciguard is a static security auditor for CI/CD pipelines. From 0.1.0 to 0.8.1, the published ghcr.io/jo-jo98/ciguard container image inherits the default root user because the Dockerfile lacks a USER directive. This vulnerability is fixed in 0.8.2.

  • CVE-2025-24307LowNov 11, 2025
    risk 0.13cvss 2.0epss 0.00

    Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable…

  • CVE-2022-4270LowDec 2, 2022
    risk 0.13cvss 2.0epss 0.01

    Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permissions accidentally.

  • CVE-2025-54821LowNov 18, 2025
    risk 0.12cvss 1.9epss 0.00

    An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all…