VYPR

CWE-280

Improper Handling of Insufficient Permissions or Privileges

BaseDraft

Description

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (166)

page 6 of 9
  • CVE-2024-35301MedMay 16, 2024
    risk 0.36cvss 5.5epss 0.00

    In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token

  • CVE-2026-9792MedMay 28, 2026
    risk 0.35cvss 6.5epss 0.00

    A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the `reject-ropc-grant`…

  • CVE-2026-2340MedMay 27, 2026
    risk 0.35cvss 6.5epss 0.01

    A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with…

  • CVE-2026-44200MedMay 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they don't have access to to an area of the site they do. Once coped, they'd be able to view its contents, and…

  • CVE-2026-44199MedMay 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to form pages could delete submissions to form pages they don't have access to by crafting a form submission to delete submissions on a page they…

  • CVE-2026-44197MedMay 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could access revisions of the page through the revision compare view if they knew the primary key of two revisions. This could…

  • CVE-2025-58122MedNov 18, 2025
    risk 0.35cvss 5.4epss 0.00

    Insufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16 allows low-privileged users to modify notification parameters via the REST API, which could lead to unauthorized actions or information disclosure.

  • CVE-2025-58121MedNov 18, 2025
    risk 0.35cvss 5.4epss 0.00

    Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.0p16 allows low-privileged users to perform unauthorized actions or obtain sensitive information

  • CVE-2022-4863MedDec 30, 2022
    risk 0.35cvss 6.5epss 0.01

    Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2021-37175MedSep 14, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCOM ROX RX1500 (All versions < V2.14.1), RUGGEDCOM ROX RX1501 (All versions < V2.14.1), RUGGEDCOM ROX RX1510 (All versions < V2.14.1),…

  • CVE-2020-26195MedFeb 9, 2021
    risk 0.35cvss 5.3epss 0.02

    Dell EMC PowerScale OneFS versions 8.1.2 – 9.1.0 contain an issue where the OneFS SMB directory auto-create may erroneously create a directory for a user. A remote unauthenticated attacker may take advantage of this issue to slow down the system.

  • CVE-2012-4550MedJan 5, 2013
    risk 0.35cvss 5.3epss 0.02

    A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC)…

  • CVE-2026-10549MedJun 2, 2026
    risk 0.34cvss epss 0.00

    LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP credentials to bypass group membership checks resulting in unauthorized access to the database.

  • CVE-2026-1772MedFeb 24, 2026
    risk 0.34cvss 5.3epss 0.00

    RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser development utilities to access them without required privileges.

  • CVE-2025-24029MedFeb 3, 2025
    risk 0.34cvss 5.3epss 0.00

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users (possibly anonymous ones if the widget is used in the dashboard of a public project) might get access to artifacts they should not see. This issue has been addressed in Tuleap…

  • CVE-2024-36112MedMay 28, 2024
    risk 0.34cvss 6.3epss 0.00

    Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group records (`extras.view_dynamicgroup` permission) can use the Dynamic Group detail UI view (`/extras/dynamic-groups//`) and/or the members REST API view…

  • CVE-2024-22077MedMar 20, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The SQLite database file has weak permissions.

  • CVE-2024-47766MedOct 14, 2024
    risk 0.32cvss 4.9epss 0.01

    Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, administrators of a project can access the content of trackers with…

  • CVE-2024-46988MedOct 14, 2024
    risk 0.31cvss 4.8epss 0.00

    Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, users might receive email notification with information they should not…

  • CVE-2026-21736MedMar 9, 2026
    risk 0.29cvss 4.4epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory. This is caused by improper handling of the memory protections for the user-mode wrapped memory resource.