VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 90 of 164
  • CVE-2026-61141HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Affordable Care Act). Supported versions that are affected are 12.2.7-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-60988HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-60894HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2026-60619HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: Time Accounting and HRM Base). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-56239HigJun 21, 2026
    risk 0.49cvss 7.6epss 0.00

    Capgo before 12.128.2 contains a potential privilege escalation vulnerability in the public.apply_usage_overage SECURITY DEFINER function, which performs sensitive billing operations without enforcing internal authorization checks (no validation of auth.uid(), org membership, or…

  • CVE-2026-46971HigJun 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-46966HigJun 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network…

  • CVE-2026-46959HigJun 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-46958HigJun 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2026-46935HigJun 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network…

  • CVE-2026-46934HigJun 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network…

  • CVE-2026-46873HigJun 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM…

  • CVE-2026-8176HigJun 16, 2026
    risk 0.49cvss 7.5epss 0.00

    The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.5.1. The plugin chains three independent flaws that together allow an authenticated Agent…

  • CVE-2026-11296HigJun 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-23663HigMay 22, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-28976HigMay 11, 2026
    risk 0.49cvss 7.5epss 0.00

    An information leakage was addressed with additional validation. This issue is fixed in macOS Tahoe 26.5. An app may be able to gain root privileges.

  • CVE-2026-3621HigApr 23, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured.

  • CVE-2026-32048HigMar 21, 2026
    risk 0.49cvss 7.5epss 0.00

    OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to create child processes under unsandboxed agents. An attacker with a sandboxed session can exploit this to spawn child runtimes…

  • CVE-2025-15576HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.00

    If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the other, jailed processes may nonetheless be able to access a shared directory via a nullfs mount, if the administrator has…

  • CVE-2026-26010HigFeb 11, 2026
    risk 0.49cvss 7.6epss 0.00

    OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres). Any read-only user can gain access to a highly privileged account, typically…