VYPR

CWE-286

Incorrect User Management

ClassIncomplete

Description

The product does not properly manage a user within its environment.

Users can be assigned to the wrong group (class) of permissions resulting in unintended access rights to sensitive objects.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (33)

page 2 of 2
  • CVE-2023-0857MedMay 11, 2023
    risk 0.38cvss 5.9epss 0.01

    Unintentional change of settings during initial registration of system administrators which uses control protocols. The affected Office / Small Office Multifunction Printers and Laser Printers(*) may allow an attacker on the network segment to trigger unauthorized access to the…

  • CVE-2021-26262MedNov 19, 2021
    risk 0.36cvss 5.5epss 0.01

    Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

  • CVE-2024-29296MedApr 10, 2024
    risk 0.35cvss 5.3epss 0.01

    A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.

  • CVE-2023-3914MedSep 29, 2023
    risk 0.35cvss 5.4epss 0.00

    A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

  • CVE-2023-3115MedSep 29, 2023
    risk 0.35cvss 5.4epss 0.00

    An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only…

  • CVE-2024-45425MedFeb 25, 2025
    risk 0.32cvss 4.9epss 0.00

    Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.

  • CVE-2023-51750MedJan 11, 2024
    risk 0.30cvss 4.6epss 0.00

    ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the vendor's position is "Not vulnerable if the default Windows device profile configuration is used which utilizes modern management with website allow-listing…

  • CVE-2024-6356MedFeb 5, 2025
    risk 0.29cvss 4.4epss 0.00

    An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which allowed cross project access for Security policy bot.

  • CVE-2024-52359MedNov 19, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform unauthorized actions that should be reserved to administrator used due to improper access controls.

  • CVE-2024-13041MedJan 9, 2025
    risk 0.27cvss 4.2epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external…

  • CVE-2023-3907MedDec 17, 2023
    risk 0.25cvss 4.9epss 0.01

    A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner

  • CVE-2025-64521MedNov 19, 2025
    risk 0.24cvss 4.8epss 0.00

    authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creates a service account for the provider. In previous authentik versions, authentication for this…

  • CVE-2026-56428HigJul 30, 2026
    risk 0.00cvss 8.1epss 0.00

    The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in…