VYPR

CWE-280

Improper Handling of Insufficient Permissions or Privileges

BaseDraft

Description

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (176)

page 7 of 9
  • CVE-2020-26195MedFeb 9, 2021
    risk 0.35cvss 5.3epss 0.02

    Dell EMC PowerScale OneFS versions 8.1.2 – 9.1.0 contain an issue where the OneFS SMB directory auto-create may erroneously create a directory for a user. A remote unauthenticated attacker may take advantage of this issue to slow down the system.

  • CVE-2012-4550MedJan 5, 2013
    risk 0.35cvss 5.3epss 0.02

    A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC)…

  • CVE-2026-10549MedJun 2, 2026
    risk 0.34cvss —epss 0.00

    LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP credentials to bypass group membership checks resulting in unauthorized access to the database.

  • CVE-2026-1772MedFeb 24, 2026
    risk 0.34cvss 5.3epss 0.00

    RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser development utilities to access them without required privileges.

  • CVE-2025-24029MedFeb 3, 2025
    risk 0.34cvss 5.3epss 0.00

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users (possibly anonymous ones if the widget is used in the dashboard of a public project) might get access to artifacts they should not see. This issue has been addressed in Tuleap…

  • CVE-2024-36112MedMay 28, 2024
    risk 0.34cvss 6.3epss 0.00

    Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group records (`extras.view_dynamicgroup` permission) can use the Dynamic Group detail UI view (`/extras/dynamic-groups//`) and/or the members REST API view…

  • CVE-2024-22077MedMar 20, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The SQLite database file has weak permissions.

  • CVE-2024-47766MedOct 14, 2024
    risk 0.32cvss 4.9epss 0.01

    Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, administrators of a project can access the content of trackers with…

  • CVE-2024-46988MedOct 14, 2024
    risk 0.31cvss 4.8epss 0.00

    Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, users might receive email notification with information they should not…

  • CVE-2026-21736MedMar 9, 2026
    risk 0.29cvss 4.4epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory. This is caused by improper handling of the memory protections for the user-mode wrapped memory resource.

  • CVE-2024-35228MedMay 30, 2024
    risk 0.29cvss 5.5epss 0.00

    Wagtail is an open source content management system built on Django. Due to an improperly applied permission check in the `wagtail.contrib.settings` module, a user with access to the Wagtail admin and knowledge of the URL of the edit view for a settings model can access and…

  • CVE-2026-54262MedJul 1, 2026
    risk 0.28cvss 4.3epss 0.00

    Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can create translations for any page, including those they do not have permissions for. This issue has…

  • CVE-2025-46708MedJun 27, 2025
    risk 0.28cvss 4.3epss 0.00

    Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU.

  • CVE-2024-55604MedMar 25, 2025
    risk 0.28cvss 4.3epss 0.00

    Appsmith is a platform to build admin panels, internal tools, and dashboards. Users invited as "App Viewer" should not have access to development information of a workspace. Datasources are such a component in a workspace. Yet, in versions of Appsmith prior to 1.51, app viewers…

  • CVE-2025-22129MedFeb 3, 2025
    risk 0.28cvss 4.3epss 0.00

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted information. This issue has been addressed in Tuleap Community Edition 16.3.99.1736242932, Tuleap Enterprise…

  • CVE-2024-47767MedOct 14, 2024
    risk 0.28cvss 4.3epss 0.00

    Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.113, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, users might see tracker names they should not have access to. Tuleap…

  • CVE-2023-6189MedNov 22, 2023
    risk 0.28cvss 4.3epss 0.01

    Missing access permissions checks in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export jobs using the M-Files API methods.

  • CVE-2023-43087MedNov 2, 2023
    risk 0.28cvss 4.3epss 0.00

    Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure.

  • CVE-2023-2020MedApr 18, 2023
    risk 0.28cvss 4.3epss 0.00

    Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host.

  • CVE-2022-42126MedNov 15, 2022
    risk 0.28cvss 4.3epss 0.01

    The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.