CWE-280
Improper Handling of Insufficient Permissions or Privileges
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.
155 vulnerabilities with CWE-280
CVE-2026-2123
HIGH
Privilege escalation vulnerability in Operations Agent
CVSS 7.8
CVE-2026-3190
MEDIUM
Keycloak: keycloak: information disclosure via improper role enforcement in uma 2.0 protection api
CVSS 4.3
CVE-2026-21736
MEDIUM
Non-privileged Software - Privilege Escalation
CVSS 4.4
CVE-2026-0047
HIGH
ActivityManagerService - Privilege Escalation
CVSS 8.4
CVE-2026-1772
MEDIUM
Hitachi Energy RTU500 Series Firmware 12.7.1-12.7.7 - Unauthenticated Information Disclosure via Browser Developer Tools
CVSS 5.3
CVE-2026-23857
HIGH
Dell Update Package (DUP) Framework <24.12.00 - Privilege Escalation
CVSS 8.2
CVE-2026-20817
HIGH
Windows Error Reporting - Privilege Escalation
CVSS 7.8
CVE-2025-67848
HIGH
Moodle < 4.1.22 - Authentication Bypass via LTI Provider
CVSS 8.1
CVE-2025-46066
CRITICAL
Automai Director <25.2.0 - Privilege Escalation
CVSS 9.9
CVE-2025-64997
MEDIUM
Checkmk - Unauthenticated Information Disclosure via REST API Agent Information Endpoint
CVSS 6.5
CVE-2025-43527
HIGH
macOS Tahoe <26.2 - Privilege Escalation
CVSS 7.8
CVE-2025-58770
HIGH
AMI APTIO V 5.0-5.041 - Privilege Escalation via BIOS Local Access
CVSS 8.8
CVE-2025-58122
MEDIUM
Checkmk 2.4.0 - Insufficient Permission Validation in REST API
CVSS 5.4
CVE-2025-58121
MEDIUM
Checkmk <2.4.0p16 - Info Disclosure
CVSS 5.4
CVE-2025-58410
HIGH
ImaginationTech DDK - Privilege Escalation via GPU System Call Memory Protection Bypass
CVSS 7.5
CVE-2025-62510
HIGH
FileRise < 1.5.0 - Improper Access Control via Folder Name Inference
CVSS 8.1
CVE-2025-62509
HIGH
FileRise < 1.4.0 - Unauthorized File Operations via Insecure Folder Ownership Inference
CVSS 8.1
CVE-2025-62176
MEDIUM
Mastodon <4.4.6-4.2.27 - Info Disclosure
CVSS 4.3
CVE-2025-45376
HIGH
Dell Repository Manager <3.4.8 - Privilege Escalation
CVSS 7.5
CVE-2025-58457
MEDIUM
Apache ZooKeeper <3.9.4 - Privilege Escalation
CVSS 4.3
CVE-2025-59040
MEDIUM
Tuleap < 16.11.99.1757427600 - Insufficient Permission Validation in Backlog Item Representation
CVSS 4.3
CVE-2025-50170
HIGH
Windows Cloud Files Mini Filter Driver - Privilege Escalation
CVSS 7.8
CVE-2025-6573
CRITICAL
Imagination Technologies Graphics DDK <=25.1 RTM - Kernel Information Disclosure
CVSS 9.8
CVE-2025-8109
HIGH
Imagination Technologies Graphics DDK 1.13 RTM-24.2 RTM2 and >=24.3 RTM - Unauthorized Memory Write via ptrace
CVSS 8.8
CVE-2025-49731
LOW
Microsoft Teams - Privilege Escalation
CVSS 3.1
Details
Vulnerabilities
155