CWE-280— Improper Handling of Insufficient Permissions or Privileges
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.— MITRE CWE catalog
174 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-280page 1 of 4
- CVE-2024-29748CRITICALCVSS 7.8EG 9.0⚠ KEV2024-04-05
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
- CVE-2025-46066CRITICALCVSS 9.9EG 9.92026-01-12
An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges
- CVE-2024-25108CRITICALCVSS 9.9EG 9.92024-02-12
Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative a…
- CVE-2025-6573CRITICALCVSS 9.8EG 9.82025-08-09
Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from the trusted execution environment (TEE).
- CVE-2024-24116CRITICALCVSS 9.8EG 9.82024-10-02
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.
- CVE-2024-7314CRITICALCVSS 9.8EG 9.82024-08-02
anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ";swagger-ui" to HTTP requests to bypass authentication and execute arbitrary Java on the victim server. Exploitat…
- CVE-2024-5163CRITICALCVSS 9.8EG 9.82024-06-17
Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account security risks.
- CVE-2026-41566CRITICALCVSS 9.4EG 9.42026-06-25
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: 2.8.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
- CVE-2024-1608CRITICALCVSS 9.1EG 9.12024-02-20
In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o user interaction.
- CVE-2026-59567HIGHCVSS 8.8EG 8.82026-08-24
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.
- CVE-2026-40371HIGHCVSS 8.8EG 8.82026-06-09
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
- CVE-2026-24096HIGHCVSS 8.8EG 8.82026-04-01
Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 allows low-privileged users to perform unauthorized actions or obtain sensitive …
- CVE-2025-58770HIGHCVSS 8.8EG 8.82025-12-12
APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privileges” by local access. Successful exploitation of this vulnerability can lead to escalation of authorization and pot…
- CVE-2025-8109HIGHCVSS 8.8EG 8.82025-08-04
Software installed and run as a non-privileged user may conduct ptrace system calls to issue writes to GPU origin read only memory.
- CVE-2025-27025HIGHCVSS 8.8EG 8.82025-07-02
The target device exposes a service on a specific TCP port with a configured endpoint. The access to that endpoint is granted using a Basic Authentication method. The endpoint accepts also the PUT method and it is possible to write file…
- CVE-2025-31173HIGHCVSS 8.8EG 8.82025-04-07
Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-6660HIGHCVSS 8.8EG 8.82024-07-17
The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the bo…
- CVE-2024-36451HIGHCVSS 8.8EG 8.82024-07-10
Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked by an unauthorized user. As a result, data …
- CVE-2023-38298HIGHCVSS 8.8EG 8.82024-04-22
Various software builds for the following TCL devices (30Z, A3X, 20XE, 10L) leak the device IMEI to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted thir…
- CVE-2024-22078HIGHCVSS 8.8EG 8.82024-03-20
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write acce…
- CVE-2019-6570HIGHCVSS 8.8EG 8.82019-04-17
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to insufficient checking of user permissions, an attacker may access URLs that require special authorization. An attacker must have access to a …
- CVE-2022-2193HIGHCVSS 7.5EG 8.82022-07-19
Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authenticator to arbitrary accounts via parameter tampering in the Device Manager page. This issue aff…
- CVE-2026-18860HIGHCVSS 8.7EG 8.72026-08-11
Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org. To man…
- CVE-2026-79403HIGHCVSS 8.4EG 8.42026-09-29
An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint
- CVE-2026-0047HIGHCVSS 8.4EG 8.42026-03-02
In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permission check. This could lead to local escalation of privilege with no additional execution privilege…
- CVE-2024-51459HIGHCVSS 8.4EG 8.42025-03-19
IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions.
- CVE-2026-23857HIGHCVSS 8.2EG 8.22026-02-12
Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vuln…
- CVE-2025-22395HIGHCVSS 8.2EG 8.22025-01-07
Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary remote sc…
- CVE-2025-67848HIGHCVSS 8.1EG 8.12026-02-03
A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforc…
- CVE-2025-62510HIGHCVSS 8.1EG 8.12025-10-20
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0, a regression allowed folder visibility/ownership to be inferred from folder names. Low-privilege users could see or i…
- CVE-2025-62509HIGHCVSS 8.1EG 8.12025-10-20
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version 1.4.0, a business logic flaw in FileRise’s file/folder handling allows low-privilege users to perform unauthorized o…
- CVE-2024-46874HIGHCVSS 8.1EG 8.12024-12-06
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients connecting with device credentials to send messages to some topics. Attackers with device credentials could issue commands to other devices on behalf…
- CVE-2024-43702HIGHCVSS 8.1EG 8.12024-11-30
Software installed and run as a non-privileged user may conduct improper GPU system calls to allow unprivileged access to arbitrary physical memory page.
- CVE-2024-6302HIGHCVSS 8.1EG 8.12024-06-25
Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to redact any message from users on the same server, given that they are able to send redaction events.
- CVE-2026-84631HIGHCVSS 7.8EG 7.82026-09-14
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to gain root privileges.
- CVE-2026-64701HIGHCVSS 7.8EG 7.82026-09-14
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
- CVE-2026-86917HIGHCVSS 7.8EG 7.82026-09-14
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
- CVE-2026-43786HIGHCVSS 7.8EG 7.82026-09-14
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
- CVE-2026-69907HIGHCVSS 7.8EG 7.82026-09-08
Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.
- CVE-2026-45196HIGHCVSS 7.8EG 7.82026-07-10
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU register access which can lead to privilege escalation.
- CVE-2026-45195HIGHCVSS 7.8EG 7.82026-06-26
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside the permitted range of memory for the host kernel. Addresses passed to the GPU Firmware can …
- CVE-2026-27910HIGHCVSS 7.8EG 7.82026-04-14
Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally.
- CVE-2026-2123HIGHCVSS 7.8EG 7.82026-03-31
A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philipp…
- CVE-2026-20817HIGHCVSS 7.8EG 7.82026-01-13
Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
- CVE-2025-43527HIGHCVSS 7.8EG 7.82025-12-12
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26.2. An app may be able to gain root privileges.
- CVE-2025-45376HIGHCVSS 7.8EG 7.82025-09-29
Dell Repository Manager (DRM), versions 3.4.7 and 3.4.8, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leadi…
- CVE-2025-50170HIGHCVSS 7.8EG 7.82025-08-12
Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-25179HIGHCVSS 7.8EG 7.82025-06-02
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages.
- CVE-2025-3931HIGHCVSS 7.8EG 7.82025-05-14
A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However…
- CVE-2025-30453HIGHCVSS 7.8EG 7.82025-05-12
The issue was addressed with additional permissions checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to gain root privileges.
Map vulnerabilities like CWE-280 to your infrastructure
EchelonGraph correlates every CVE — across CWE-280 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →