CWE-286
Incorrect User Management
Description
The product does not properly manage a user within its environment.
Hierarchy (View 1000)
CVEs mapped to this weakness (33)
page 2 of 2| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0857 | Med | 0.38 | 5.9 | 0.01 | May 11, 2023 | Unintentional change of settings during initial registration of system administrators which uses control protocols. The affected Office / Small Office Multifunction Printers and Laser Printers(*) may allow an attacker on the network segment to trigger unauthorized access to the… | ||
| CVE-2021-26262 | Med | 0.36 | 5.5 | 0.01 | Nov 19, 2021 | Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. | ||
| CVE-2024-29296 | Med | 0.35 | 5.3 | 0.01 | Apr 10, 2024 | A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not. | ||
| CVE-2023-3914 | Med | 0.35 | 5.4 | 0.00 | Sep 29, 2023 | A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects. | ||
| CVE-2023-3115 | Med | 0.35 | 5.4 | 0.00 | Sep 29, 2023 | An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only… | ||
| CVE-2024-45425 | Med | 0.32 | 4.9 | 0.00 | Feb 25, 2025 | Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access. | ||
| CVE-2023-51750 | Med | 0.30 | 4.6 | 0.00 | Jan 11, 2024 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the vendor's position is "Not vulnerable if the default Windows device profile configuration is used which utilizes modern management with website allow-listing… | ||
| CVE-2024-6356 | Med | 0.29 | 4.4 | 0.00 | Feb 5, 2025 | An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which allowed cross project access for Security policy bot. | ||
| CVE-2024-52359 | Med | 0.28 | 4.3 | 0.00 | Nov 19, 2024 | IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform unauthorized actions that should be reserved to administrator used due to improper access controls. | ||
| CVE-2024-13041 | Med | 0.27 | 4.2 | 0.00 | Jan 9, 2025 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external… | ||
| CVE-2023-3907 | Med | 0.25 | 4.9 | 0.01 | Dec 17, 2023 | A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner | ||
| CVE-2025-64521 | Med | 0.24 | 4.8 | 0.00 | Nov 19, 2025 | authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creates a service account for the provider. In previous authentik versions, authentication for this… | ||
| CVE-2026-56428 | Hig | 0.00 | 8.1 | 0.00 | Jul 30, 2026 | The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in… |
- risk 0.38cvss 5.9epss 0.01
Unintentional change of settings during initial registration of system administrators which uses control protocols. The affected Office / Small Office Multifunction Printers and Laser Printers(*) may allow an attacker on the network segment to trigger unauthorized access to the…
- risk 0.36cvss 5.5epss 0.01
Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- risk 0.35cvss 5.3epss 0.01
A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.
- risk 0.35cvss 5.4epss 0.00
A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.
- risk 0.35cvss 5.4epss 0.00
An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only…
- risk 0.32cvss 4.9epss 0.00
Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.
- risk 0.30cvss 4.6epss 0.00
ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the vendor's position is "Not vulnerable if the default Windows device profile configuration is used which utilizes modern management with website allow-listing…
- risk 0.29cvss 4.4epss 0.00
An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which allowed cross project access for Security policy bot.
- risk 0.28cvss 4.3epss 0.00
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform unauthorized actions that should be reserved to administrator used due to improper access controls.
- risk 0.27cvss 4.2epss 0.00
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external…
- risk 0.25cvss 4.9epss 0.01
A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner
- risk 0.24cvss 4.8epss 0.00
authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creates a service account for the provider. In previous authentik versions, authentication for this…
- risk 0.00cvss 8.1epss 0.00
The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in…