VYPR

CWE-280

Improper Handling of Insufficient Permissions or Privileges

BaseDraft

Description

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (176)

page 9 of 9
  • CVE-2024-42194LowDec 17, 2024
    risk 0.20cvss 3.1epss 0.00

    An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access via a read-only account can possibly change certain configuration parameters by crafting a specific REST API call.

  • CVE-2024-29852LowMay 22, 2024
    risk 0.18cvss 2.7epss 0.01

    Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs.

  • CVE-2026-11764LowJun 9, 2026
    risk 0.16cvss —epss 0.00

    When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if the user creating the export does not have permission to view gift cards. This is inconsistent with the UI and API where only the first letters of the gift…

  • CVE-2024-4692LowOct 16, 2024
    risk 0.16cvss 2.4epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - Service Virtualization config has been discovered in…

  • CVE-2024-4211LowOct 16, 2024
    risk 0.16cvss 2.4epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job config has been discovered in OpenText…

  • CVE-2024-32882LowMay 2, 2024
    risk 0.11cvss 2.7epss 0.00

    Wagtail is an open source content management system built on Django. In affected versions if a model has been made available for editing through the `wagtail.contrib.settings` module or `ModelViewSet`, and the `permission` argument on `FieldPanel` has been used to further…

  • CVE-2026-11804MedJul 23, 2026
    risk 0.00cvss 5.2epss 0.00

    Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5;…

  • CVE-2026-62393MedJul 14, 2026
    risk 0.00cvss 4.3epss 0.00

    Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 through 5.0.3. …

  • CVE-2026-20463MedJul 1, 2026
    risk 0.00cvss 6.7epss 0.00

    In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: MOLY01716533; Issue ID:…

  • CVE-2026-45195HigJun 26, 2026
    risk 0.00cvss 7.8epss 0.00

    Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside the permitted range of memory for the host kernel. Addresses passed to the GPU Firmware can be used by the Firmware for more…

  • CVE-2026-41566CriJun 25, 2026
    risk 0.00cvss —epss 0.00

    Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: 2.8.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.

  • CVE-2025-62510HigOct 20, 2025
    risk 0.00cvss 8.1epss 0.00

    FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0, a regression allowed folder visibility/ownership to be inferred from folder names. Low-privilege users could see or interact with folders matching their…

  • CVE-2025-62509HigOct 20, 2025
    risk 0.00cvss 8.1epss 0.00

    FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version 1.4.0, a business logic flaw in FileRise’s file/folder handling allows low-privilege users to perform unauthorized operations (view/delete/modify) on files…

  • CVE-2025-62176MedOct 13, 2025
    risk 0.00cvss 4.3epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, the streaming server accepts serving events for public timelines to clients using any valid authentication token, even if those tokens lack the read:statuses…

  • CVE-2024-0560MedFeb 28, 2024
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection policy discovers the Token Introspection endpoint from the token_introspection_endpoint field, but the…

  • CVE-2023-22737MedJan 28, 2023
    risk 0.00cvss 6.5epss 0.01

    wire-server provides back end services for Wire, a team communication and collaboration platform. Prior to version 2022-12-09, every member of a Conversation can remove a Bot from a Conversation due to a missing permissions check. Only Conversation admins should be able to…