VYPR

CWE-272

Least Privilege Violation

BaseIncomplete

Description

The elevated privilege level required to perform operations such as chroot() should be dropped immediately after the operation is performed.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-17 · CAPEC-35 · CAPEC-76

CVEs mapped to this weakness (42)

page 3 of 3
  • CVE-2026-23634NonJan 16, 2026
    risk 0.00cvss 0.0epss 0.00

    Pepr is a type safe K8s middleware. Prior to 1.0.5 , Pepr defaults to a cluster-admin RBAC configuration and does not explicitly force or enforce least-privilege guidance for module authors. The default behavior exists to make the “getting started” experience smooth: new…

  • CVE-2024-0798MedFeb 26, 2024
    risk 0.00cvss 6.5epss 0.01

    A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete documents uploaded by 'admin'. Despite the intended restriction that prevents 'default' role users from deleting admin-uploaded documents, an attacker can…