VYPR

CWE-283

Unverified Ownership

BaseDraft

Description

The product does not properly verify that a critical resource is owned by the proper entity.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (24)

page 1 of 2
  • CVE-2024-27903CriJul 8, 2024
    risk 0.64cvss 9.8epss 0.09

    OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

  • CVE-2021-24501HigAug 9, 2021
    risk 0.53cvss 8.1epss 0.01

    The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifying or deleting objects. This allowed a logged in user to modify or delete objects belonging to other…

  • CVE-2021-24500HigAug 9, 2021
    risk 0.53cvss 8.1epss 0.01

    Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site,…

  • CVE-2026-20912CriJan 22, 2026
    risk 0.52cvss 9.1epss 0.00

    Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users.

  • CVE-2025-43882HigAug 27, 2025
    risk 0.51cvss 7.8epss 0.00

    Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A local low-privileged attacker could potentially exploit this vulnerability leading to Unauthorized Access.

  • CVE-2026-26016HigFeb 19, 2026
    risk 0.46cvss 8.1epss 0.00

    Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers allows any user with access to a node secret token to fetch information about any server on a…

  • CVE-2026-4269HigMar 16, 2026
    risk 0.42cvss 7.5epss 0.00

    A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue only affects users of the Bedrock AgentCore…

  • CVE-2026-29788HigMar 6, 2026
    risk 0.42cvss 7.5epss 0.00

    TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparency work. Prior to version 30, conversion of empty strings to null allows disguising DPA reports as genuine self-deletion reports.…

  • CVE-2020-8554MedJan 21, 2021
    risk 0.42cvss 6.3epss 0.09

    Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation…

  • CVE-2025-47940HigMay 20, 2025
    risk 0.40cvss 7.2epss 0.00

    TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, administrator-level backend users without system maintainer privileges can escalate their privileges and…

  • CVE-2026-44707MedMay 26, 2026
    risk 0.37cvss 6.8epss 0.00

    Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confirmation was not enforced before an account became usable, an attacker could pre-register an email…

  • CVE-2024-1853MedMar 14, 2024
    risk 0.36cvss 5.5epss 0.00

    Zemana AntiLogger v2.74.204.664 is vulnerable to an Arbitrary Process Termination vulnerability by triggering the 0x80002048 IOCTL code of the zam64.sys and zamguard64.sys drivers.

  • CVE-2026-44562MedMay 15, 2026
    risk 0.35cvss 6.5epss 0.00

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/models/import endpoint allows users with the workspace.models_import permission to overwrite any existing model in the database, regardless of…

  • CVE-2025-1007MedFeb 19, 2025
    risk 0.34cvss 5.3epss 0.00

    In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name, description, website, support link and social media links. The…

  • CVE-2025-9822MedSep 3, 2025
    risk 0.29cvss 5.5epss 0.00

    SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them.

  • CVE-2025-36091MedNov 3, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ownership assignment.

  • CVE-2026-27486MedFeb 21, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenClaw is a personal AI assistant. In versions 2026.2.13 and below of the OpenClaw CLI, the process cleanup uses system-wide process enumeration and pattern matching to terminate processes without verifying if they are owned by the current OpenClaw process. On shared hosts,…

  • CVE-2026-0598MedFeb 6, 2026
    risk 0.27cvss 4.2epss 0.00

    A security flaw was identified in the Ansible Lightspeed API conversation endpoints that handle AI chat interactions. The APIs do not properly verify whether a conversation identifier belongs to the authenticated user making the request. As a result, an attacker with valid…

  • CVE-2026-40337MedApr 18, 2026
    risk 0.26cvss 5.1epss 0.00

    The Sentry kernel is a high security level micro-kernel implementation made for high security embedded systems. A given task with one of the DEV or IO capability is able to interact with another task's IRQ line through the __sys_int_* syscall familly. Prior to version 0.4.7,…

  • CVE-2023-30544LowApr 24, 2023
    risk 0.25cvss 3.9epss 0.00

    Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update their email addresses via the `My profile` admin page. This page allowed them to change the email address registered with their account without the ownership…