VYPR

CWE-280

Improper Handling of Insufficient Permissions or Privileges

BaseDraft

Description

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (166)

page 8 of 9
  • CVE-2025-59040MedSep 18, 2025
    risk 0.21cvss 4.3epss 0.00

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representations do not verify the permissions of the child trackers. Users might see tracker names they should not have access to. This vulnerability is fixed in Tuleap…

  • CVE-2024-39691MedJul 5, 2024
    risk 0.21cvss 4.3epss 0.00

    matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The fix for GHSA-wm4w-7h2q-3pf7 / CVE-2024-32000 included in matrix-appservice-irc 2.0.0 relied on the Matrix homeserver-provided timestamp to determine whether a user has access to the event…

  • CVE-2024-4468MedJun 8, 2024
    risk 0.21cvss 4.3epss 0.00

    The Salon booking system plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions hooked into admin_init in all versions up to, and including, 9.9. This makes it possible for authenticated attackers…

  • CVE-2024-27837LowMay 14, 2024
    risk 0.21cvss 3.3epss 0.00

    A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. A local attacker may gain access to Keychain items.

  • CVE-2024-32000MedApr 12, 2024
    risk 0.21cvss 4.3epss 0.00

    matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. matrix-appservice-irc before version 2.0.0 can be exploited to leak the truncated body of a message if a malicious user sends a Matrix reply to an event ID they don't have access to. As a…

  • CVE-2025-49731LowJul 8, 2025
    risk 0.20cvss 3.1epss 0.00

    Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

  • CVE-2024-42194LowDec 17, 2024
    risk 0.20cvss 3.1epss 0.00

    An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access via a read-only account can possibly change certain configuration parameters by crafting a specific REST API call.

  • CVE-2024-29852LowMay 22, 2024
    risk 0.18cvss 2.7epss 0.01

    Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs.

  • CVE-2026-11764LowJun 9, 2026
    risk 0.16cvss epss 0.00

    When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if the user creating the export does not have permission to view gift cards. This is inconsistent with the UI and API where only the first letters of the gift…

  • CVE-2024-4692LowOct 16, 2024
    risk 0.16cvss 2.4epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - Service Virtualization config has been discovered in…

  • CVE-2024-4211LowOct 16, 2024
    risk 0.16cvss 2.4epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job config has been discovered in OpenText…

  • CVE-2024-32882LowMay 2, 2024
    risk 0.11cvss 2.7epss 0.00

    Wagtail is an open source content management system built on Django. In affected versions if a model has been made available for editing through the `wagtail.contrib.settings` module or `ModelViewSet`, and the `permission` argument on `FieldPanel` has been used to further…

  • CVE-2026-32639Aug 12, 2026
    risk 0.00cvss epss

    ### Impact Affected versions of Winter CMS did not enforce per-template-type permission checks in the CMS section's AJAX handlers. The CMS controller (`Cms\Controllers\Index`) used OR-logic across its five permissions (`cms.manage_pages`, `cms.manage_partials`,…

  • CVE-2026-11804MedJul 23, 2026
    risk 0.00cvss 5.2epss 0.00

    Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5;…

  • CVE-2026-62393MedJul 14, 2026
    risk 0.00cvss 4.3epss 0.00

    Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 through 5.0.3. …

  • CVE-2026-54262MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can create translations for any page, including those they do not have permissions for. This issue has…

  • CVE-2026-54261MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint, a user with access to the Wagtail admin can preview any image. The existing data of the image object…

  • CVE-2026-54259MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Documents and Images chooser's chosen endpoint incorrectly listed items for which the user has not been granted choose permission. A user with access to the…

  • CVE-2026-20463MedJul 1, 2026
    risk 0.00cvss 6.7epss 0.00

    In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: MOLY01716533; Issue ID:…

  • CVE-2026-45195HigJun 26, 2026
    risk 0.00cvss 7.8epss 0.00

    Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside the permitted range of memory for the host kernel. Addresses passed to the GPU Firmware can be used by the Firmware for more…