CWE-280

Improper Handling of Insufficient Permissions or Privileges

Parent: CWE-755 - Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

155 vulnerabilities with CWE-280
CVE-2026-11804 MEDIUM
Tridium Niagara Framework - Program Module Vulnerability
CVSS 5.2
CVE-2026-62393 MEDIUM
Apache Kylin: Improper authorization in job information retrieval
CVSS 4.3
CVE-2026-45196 HIGH
GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers from host kernel
CVSS 7.8
CVE-2026-54262 MEDIUM
Wagtail: Pages translations can be created without page permissions when using simple_translation
CVSS 4.3
CVE-2026-54261 MEDIUM
Wagtail: Improper permission handling in image preview
CVSS 6.5
CVE-2026-54259 MEDIUM
Wagtail: Improper restriction handling on Documents and Images chosen endpoints
CVSS 4.3
CVE-2026-20463 MEDIUM
MediaTek Chipset - Improper Handling of Insufficient Permissions or Privileges
CVSS 6.7
CVE-2026-45195 HIGH
GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted
CVSS 7.8
CVE-2026-41566 CRITICAL
Apache Kvrocks: Improper permission for the APPLYBATCH command
CVE-2026-40371 HIGH
Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-11764 LOW
pretix - Data Exposed Without Proper Permission
CVE-2026-10549 MEDIUM
Privilege escalation in Yandex Database
CVE-2026-9792 MEDIUM
Keycloak: keycloak: security restriction bypass allows unauthorized ropc token acquisition
CVSS 6.5
CVE-2026-46054 HIGH
selinux: fix overlayfs mmap() and mprotect() access checks
CVSS 7.1
CVE-2026-2340 MEDIUM
Samba: vfs_worm does not block directory modification
CVSS 6.5
CVE-2026-44201 MEDIUM
Wagtail: Improper restriction handling on Documents and Images API
CVSS 5.3
CVE-2026-44200 MEDIUM
Wagtail: Improper permission handling when copying pages
CVSS 6.5
CVE-2026-44199 MEDIUM
Wagtail: Improper permission handling when deleting form submissions
CVSS 6.5
CVE-2026-44198 MEDIUM
Wagtail: Improper permission handling when viewing page history
CVSS 4.3
CVE-2026-44197 MEDIUM
Wagtail: Improper permission handling when comparing revisions
CVSS 6.5
CVE-2026-6805 HIGH
Vulnerability on Cryptobox external sharing feature
CVSS 7.5
CVE-2026-20448 MEDIUM
MediaTek chipset MT6765 - Privilege Escalation
CVSS 6.7
CVE-2026-21733 HIGH
Imagination Graphics DDK RGXDerivePTEProt8 - Shared Memory Overwrite
CVSS 7.3
CVE-2026-27910 HIGH
Windows Installer Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-24096 HIGH
Insufficient permission validation on multiple REST API Quick Setup endpoints
CVSS 8.8
Details
Vulnerabilities 155