CWE-280— Improper Handling of Insufficient Permissions or Privileges
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.— MITRE CWE catalog
162 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-280page 4 of 4
- CVE-2026-45196HIGHCVSS 7.8EG 7.82026-07-10
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU register access which can lead to privilege escalation.
- CVE-2026-46054HIGHCVSS 7.1EG 7.12026-05-27
In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the…
- CVE-2026-54259MEDIUMCVSS 4.3EG 4.32026-07-01
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Documents and Images chooser's chosen endpoint incorrectly listed items for which the user has not been granted choose pe…
- CVE-2026-54261MEDIUMCVSS 6.5EG 6.52026-07-01
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint, a user with access to the Wagtail admin can preview any imag…
- CVE-2026-54262MEDIUMCVSS 4.3EG 4.32026-07-01
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can create translations for any page, including those they do n…
- CVE-2026-55468MEDIUMCVSS 4.3EG 4.32026-08-20
Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without suffi…
- CVE-2026-58416HIGHCVSS 7.1EG 7.12026-07-21
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
- CVE-2026-59567HIGHCVSS 8.8EG 8.82026-08-24
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.
- CVE-2026-62393MEDIUMCVSS 4.3EG 4.32026-07-14
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects A…
- CVE-2026-6805HIGHCVSS 7.5EG 7.52026-05-07
Vulnerability on the external sharing feature in Cryptobox allows an attacker knowing a sharing link URL to retrieve information from the server allowing an offline brute-force attack of the access code associated to this sharing link.
- CVE-2026-73239MEDIUMCVSS 6.5EG 6.52026-08-12
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the …
- CVE-2026-9792MEDIUMCVSS 6.5EG 6.52026-05-28
A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security res…
Map vulnerabilities like CWE-280 to your infrastructure
EchelonGraph correlates every CVE — across CWE-280 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →