CWE-280
Improper Handling of Insufficient Permissions or Privileges
Description
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (166)
page 1 of 9| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-24116 | Cri | 0.66 | 9.8 | 0.28 | Oct 2, 2024 | An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm. | ||
| CVE-2025-46066 | Cri | 0.64 | 9.9 | 0.00 | Jan 12, 2026 | An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges | ||
| CVE-2025-6573 | Cri | 0.64 | 9.8 | 0.00 | Aug 9, 2025 | Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from the trusted execution environment (TEE). | ||
| CVE-2024-5163 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2024 | Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account security risks. | ||
| CVE-2024-29748 | Hig | 0.63 | 7.8 | 0.01 | KEV | Apr 5, 2024 | there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |
| CVE-2024-1608 | Cri | 0.59 | 9.1 | 0.00 | Feb 20, 2024 | In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o user interaction. | ||
| CVE-2026-40371 | Hig | 0.57 | 8.8 | 0.01 | Jun 9, 2026 | Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-58770 | Hig | 0.57 | 8.8 | 0.00 | Dec 12, 2025 | APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privileges” by local access. Successful exploitation of this vulnerability can lead to escalation of authorization and potentially impact Integrity and… | ||
| CVE-2025-8109 | — | Hig | 0.57 | 8.8 | 0.00 | Aug 4, 2025 | Software installed and run as a non-privileged user may conduct ptrace system calls to issue writes to GPU origin read only memory. | |
| CVE-2025-27025 | — | Hig | 0.57 | 8.8 | 0.01 | Jul 2, 2025 | The target device exposes a service on a specific TCP port with a configured endpoint. The access to that endpoint is granted using a Basic Authentication method. The endpoint accepts also the PUT method and it is possible to write files on the target device file system.… | |
| CVE-2025-31173 | Hig | 0.57 | 8.8 | 0.00 | Apr 7, 2025 | Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-36451 | Hig | 0.57 | 8.8 | 0.01 | Jul 10, 2024 | Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked by an unauthorized user. As a result, data within a system may be referred, a… | ||
| CVE-2023-38298 | Hig | 0.57 | 8.8 | 0.00 | Apr 22, 2024 | Various software builds for the following TCL devices (30Z, A3X, 20XE, 10L) leak the device IMEI to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining… | ||
| CVE-2024-22078 | Hig | 0.57 | 8.8 | 0.01 | Mar 20, 2024 | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write access for all authenticated users and the… | ||
| CVE-2024-25108 | Cri | 0.57 | 9.9 | 0.01 | Feb 12, 2024 | Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative and moderator functionality of the… | ||
| CVE-2019-6570 | Hig | 0.57 | 8.8 | 0.01 | Apr 17, 2019 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to insufficient checking of user permissions, an attacker may access URLs that require special authorization. An attacker must have access to a low privileged account in order to… | ||
| CVE-2023-6267 | Hig | 0.56 | 8.6 | 0.01 | Jan 25, 2024 | A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with… | ||
| CVE-2026-0047 | Hig | 0.55 | 8.4 | 0.00 | Mar 2, 2026 | In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed… | ||
| CVE-2024-51459 | Hig | 0.55 | 8.4 | 0.00 | Mar 19, 2025 | IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions. | ||
| CVE-2026-23857 | Hig | 0.53 | 8.2 | 0.00 | Feb 12, 2026 | Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of… |
- risk 0.66cvss 9.8epss 0.28
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.
- risk 0.64cvss 9.9epss 0.00
An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges
- risk 0.64cvss 9.8epss 0.00
Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from the trusted execution environment (TEE).
- risk 0.64cvss 9.8epss 0.01
Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account security risks.
- risk 0.63cvss 7.8epss 0.01
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
- risk 0.59cvss 9.1epss 0.00
In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o user interaction.
- risk 0.57cvss 8.8epss 0.01
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.00
APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privileges” by local access. Successful exploitation of this vulnerability can lead to escalation of authorization and potentially impact Integrity and…
- risk 0.57cvss 8.8epss 0.00
Software installed and run as a non-privileged user may conduct ptrace system calls to issue writes to GPU origin read only memory.
- risk 0.57cvss 8.8epss 0.01
The target device exposes a service on a specific TCP port with a configured endpoint. The access to that endpoint is granted using a Basic Authentication method. The endpoint accepts also the PUT method and it is possible to write files on the target device file system.…
- risk 0.57cvss 8.8epss 0.00
Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.57cvss 8.8epss 0.01
Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked by an unauthorized user. As a result, data within a system may be referred, a…
- risk 0.57cvss 8.8epss 0.00
Various software builds for the following TCL devices (30Z, A3X, 20XE, 10L) leak the device IMEI to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write access for all authenticated users and the…
- risk 0.57cvss 9.9epss 0.01
Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative and moderator functionality of the…
- risk 0.57cvss 8.8epss 0.01
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to insufficient checking of user permissions, an attacker may access URLs that require special authorization. An attacker must have access to a low privileged account in order to…
- risk 0.56cvss 8.6epss 0.01
A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with…
- risk 0.55cvss 8.4epss 0.00
In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…
- risk 0.55cvss 8.4epss 0.00
IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions.
- risk 0.53cvss 8.2epss 0.00
Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of…