VYPR

CWE-280

Improper Handling of Insufficient Permissions or Privileges

BaseDraft

Description

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (176)

page 6 of 9
  • CVE-2026-46054HigMay 27, 2026
    risk 0.39cvss 7.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the "user" file) and…

  • CVE-2023-21421MedFeb 9, 2023
    risk 0.38cvss 5.9epss 0.00

    Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker to access device SIM PIN.

  • CVE-2022-39886MedNov 9, 2022
    risk 0.38cvss 5.9epss 0.00

    Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information.

  • CVE-2022-39885MedNov 9, 2022
    risk 0.38cvss 5.9epss 0.00

    Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.

  • CVE-2022-39872MedOct 7, 2022
    risk 0.38cvss 5.9epss 0.00

    Improper restriction of broadcasting Intent in ShareLive prior to version 13.2.03.5 leaks MAC address of the connected Bluetooth device.

  • CVE-2022-36874MedSep 9, 2022
    risk 0.38cvss 5.9epss 0.00

    Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows attacker to access device IMEI and Serial number.

  • CVE-2020-10072MedMay 25, 2021
    risk 0.38cvss 5.9epss 0.00

    Improper Handling of Insufficient Permissions or Privileges in zephyr. Zephyr versions >= v1.14.2, >= v2.2.0 contain Improper Handling of Insufficient Permissions or Privileges (CWE-280). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/G…

  • CVE-2026-32639MedAug 26, 2026
    risk 0.37cvss 6.8epss 0.00

    Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type permission checks, allowing a backend user with any single CMS permission to act…

  • CVE-2026-21099MedSep 9, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.

  • CVE-2024-35301MedMay 16, 2024
    risk 0.36cvss 5.5epss 0.00

    In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token

  • CVE-2026-54261MedJul 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint, a user with access to the Wagtail admin can preview any image. The existing data of the image object…

  • CVE-2026-9792MedMay 28, 2026
    risk 0.35cvss 6.5epss 0.00

    A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the `reject-ropc-grant`…

  • CVE-2026-2340MedMay 27, 2026
    risk 0.35cvss 6.5epss 0.01

    A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with…

  • CVE-2026-44200MedMay 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they don't have access to to an area of the site they do. Once coped, they'd be able to view its contents, and…

  • CVE-2026-44199MedMay 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to form pages could delete submissions to form pages they don't have access to by crafting a form submission to delete submissions on a page they…

  • CVE-2026-44197MedMay 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could access revisions of the page through the revision compare view if they knew the primary key of two revisions. This could…

  • CVE-2025-58122MedNov 18, 2025
    risk 0.35cvss 5.4epss 0.00

    Insufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16 allows low-privileged users to modify notification parameters via the REST API, which could lead to unauthorized actions or information disclosure.

  • CVE-2025-58121MedNov 18, 2025
    risk 0.35cvss 5.4epss 0.00

    Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.0p16 allows low-privileged users to perform unauthorized actions or obtain sensitive information

  • CVE-2022-4863MedDec 30, 2022
    risk 0.35cvss 6.5epss 0.01

    Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2021-37175MedSep 14, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCOM ROX RX1500 (All versions < V2.14.1), RUGGEDCOM ROX RX1501 (All versions < V2.14.1), RUGGEDCOM ROX RX1510 (All versions < V2.14.1),…