VYPR

CWE-282

Improper Ownership Management

ClassDraft

Description

The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-17 · CAPEC-35

CVEs mapped to this weakness (29)

page 1 of 2
  • CVE-2026-23514HigMar 25, 2026
    risk 0.57cvss 8.8epss 0.01

    Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch.

  • CVE-2020-10632HigFeb 24, 2022
    risk 0.57cvss 8.8epss 0.00

    Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of important configuration files, which could cause the system to fail or behave in an unpredictable manner.

  • CVE-2025-27254HigMar 10, 2025
    risk 0.52cvss 8.0epss 0.00

    CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass.  The software's startup authentication can be disabled by altering a Windows registry setting that any user can modify.

  • CVE-2024-39755HigOct 3, 2024
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lead to execute priviledged operation. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

  • CVE-2024-37999HigJul 8, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes as a trusted account with high privileges and network access. This could allow an authenticated local attacker to escalate privileges.

  • CVE-2022-29187HigJul 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765,…

  • CVE-2017-12189HigJan 10, 2018
    risk 0.51cvss 7.8epss 0.00

    It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This issue is a result of an incomplete fix for CVE-2016-8656.

  • CVE-2025-57732HigAug 20, 2025
    risk 0.49cvss 7.5epss 0.00

    In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership

  • CVE-2024-3383HigApr 10, 2024
    risk 0.48cvss 7.4epss 0.01

    A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to…

  • CVE-2022-0026MedMay 11, 2022
    risk 0.44cvss 6.7epss 0.00

    A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\) to execute a program with elevated privileges. This…

  • CVE-2026-40214MedMay 7, 2026
    risk 0.41cvss 6.3epss 0.00

    In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project filtering, and policy checks are self-referential…

  • CVE-2024-8949MedSep 17, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Online Eyewear Shop 1.0. This affects an unknown part of the file /classes/Master.php of the component Cart Content Handler. The manipulation of the argument cart_id/id leads to improper ownership…

  • CVE-2024-45104MedSep 13, 2024
    risk 0.41cvss 6.3epss 0.00

    A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.

  • CVE-2023-7226MedJan 11, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in meetyoucrop big-whale 1.1 and classified as critical. Affected by this issue is some unknown functionality of the file /auth/user/all.api of the component Admin Module. The manipulation of the argument id leads to improper ownership management. The…

  • CVE-2026-3867MedApr 27, 2026
    risk 0.39cvss epss 0.00

    An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownership management, a low-privileged authenticated user may access a configuration file containing the hashed password of the administrative account. Successful…

  • CVE-2024-13249MedJan 9, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 7.X-1.0 before 7.X-1.2.

  • CVE-2024-43176MedJan 9, 2025
    risk 0.35cvss 5.4epss 0.00

    IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should only be available to privileged users.

  • CVE-2024-47816MedOct 9, 2024
    risk 0.35cvss 6.4epss 0.00

    ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the database to tell who made what requests. Therefore, if a user on another wiki happens to have the same actor ID as someone on the central wiki, the user on the…

  • CVE-2025-32946MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and then sets the associated channel to the channel ID…

  • CVE-2024-13246MedJan 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 0.0.0 before 2.0.2.