CWE-280— Improper Handling of Insufficient Permissions or Privileges
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.— MITRE CWE catalog
170 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-280page 4 of 4
- CVE-2026-44200MEDIUMCVSS 6.5EG 6.52026-05-11
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they don't have access to to an area of the site they do. Once coped, they'd be …
- CVE-2026-44201MEDIUMCVSS 5.3EG 5.32026-05-11
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and Images API incorrectly listed items in private collections. A user with access to the API could see the filename and nam…
- CVE-2026-45195HIGHCVSS 7.8EG 7.82026-06-26
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside the permitted range of memory for the host kernel. Addresses passed to the GPU Firmware can …
- CVE-2026-45196HIGHCVSS 7.8EG 7.82026-07-10
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU register access which can lead to privilege escalation.
- CVE-2026-46054HIGHCVSS 7.1EG 7.12026-05-27
In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the…
- CVE-2026-54259MEDIUMCVSS 4.3EG 4.32026-07-01
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Documents and Images chooser's chosen endpoint incorrectly listed items for which the user has not been granted choose pe…
- CVE-2026-54261MEDIUMCVSS 6.5EG 6.52026-07-01
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint, a user with access to the Wagtail admin can preview any imag…
- CVE-2026-54262MEDIUMCVSS 4.3EG 4.32026-07-01
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can create translations for any page, including those they do n…
- CVE-2026-54471LOWCVSS 3.5EG 3.52026-09-17
Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to…
- CVE-2026-55468MEDIUMCVSS 4.3EG 4.32026-08-20
Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without suffi…
- CVE-2026-58416HIGHCVSS 7.1EG 7.12026-07-21
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
- CVE-2026-59567HIGHCVSS 8.8EG 8.82026-08-24
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.
- CVE-2026-62393MEDIUMCVSS 4.3EG 4.32026-07-14
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects A…
- CVE-2026-64701HIGHCVSS 7.8EG 7.82026-09-14
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
- CVE-2026-6805HIGHCVSS 7.5EG 7.52026-05-07
Vulnerability on the external sharing feature in Cryptobox allows an attacker knowing a sharing link URL to retrieve information from the server allowing an offline brute-force attack of the access code associated to this sharing link.
- CVE-2026-69907HIGHCVSS 7.8EG 7.82026-09-08
Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.
- CVE-2026-73239MEDIUMCVSS 6.5EG 6.52026-08-12
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the …
- CVE-2026-84631HIGHCVSS 7.8EG 7.82026-09-14
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to gain root privileges.
- CVE-2026-86917HIGHCVSS 7.8EG 7.82026-09-14
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
- CVE-2026-9792MEDIUMCVSS 6.5EG 6.52026-05-28
A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security res…
Map vulnerabilities like CWE-280 to your infrastructure
EchelonGraph correlates every CVE — across CWE-280 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →