← Back
CWE-280

154 CVEs • Abstraction: Base

Improper Handling of Insufficient Permissions or Privileges

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

JSON object

Loading...

CVEs (154)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Apr 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Apr 7, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Vulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability will affect availability.
1Google
1Android
Jun 17, 2026
Apr 5, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
1Apple
1Macos
Jun 17, 2026
Mar 28, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A process may gain admin privileges without proper authentication.
1Zscaler
1Client Connector
Jun 17, 2026
Mar 26, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121 and later.
1Elspec Ltd
1G5dfr Firmware
Jun 17, 2026
Mar 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This re...Show more
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write access for all authenticated users and the possibility to escalate from user privileges to administrative privileges.Show less
1Elspec Ltd
1G5dfr Firmware
Jun 17, 2026
Mar 20, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The SQLite database file has weak permissions.
1Common Services
1So Flexibilite
Jun 17, 2026
Mar 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information via debug file.
1Redhat
13scale
Jun 17, 2026
Feb 28, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection policy discovers the Token Introspection endp...Show more
A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection policy discovers the Token Introspection endpoint from the token_introspection_endpoint field, but the field was removed on RH-SSO 7.5. As a result, the policy doesn't inspect tokens, it determines that all tokens are valid.Show less
1Oppo
1Usercenter Credit Software Development Kit
Jun 17, 2026
Feb 20, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o user interaction.
1Google
1Android
Jun 17, 2026
Feb 16, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges...Show more
In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Show less
1Dell
1Supportassist For Home Pcs
Jun 17, 2026
Feb 14, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass vulnerability that allows locally authenticated non-admin users to gain temporary privilege within the SupportAssist User Interfac...Show more
Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass vulnerability that allows locally authenticated non-admin users to gain temporary privilege within the SupportAssist User Interface on their respective PC. The Run as Admin temporary privilege feature enables IT/System Administrators to perform driver scans and Dell-recommended driver installations without requiring them to log out of the local non-admin user session. However, the granted privilege is limited solely to the SupportAssist User Interface and automatically expires after 15 minutes. Show less
1Pixelfed
1Pixelfed
Jun 17, 2026
Feb 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to t...Show more
Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative and moderator functionality of the Pixelfed server. This vulnerability affects every version of Pixelfed between v0.10.4 and v0.11.9, inclusive. A proof of concept of this vulnerability exists. This vulnerability affects every local user of a Pixelfed server, and can potentially affect the servers' ability to federate. Some user interaction is required to setup the conditions to be able to exercise the vulnerability, but the attacker could conduct this attack time-delayed manner, where user interaction is not actively required. This vulnerability has been addressed in version 0.11.11. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Dell
1Power Manager
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Power Manager, versions prior to 3.14, contain an Improper Authorization vulnerability in DPM service. A low privileged malicious user could potentially exploit this vulnerability in order to elevate privileges on...Show more
Dell Power Manager, versions prior to 3.14, contain an Improper Authorization vulnerability in DPM service. A low privileged malicious user could potentially exploit this vulnerability in order to elevate privileges on the system. Show less
1M Files
1M Files Server
Jun 17, 2026
Nov 22, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Missing access permissions checks in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export jobs using the M-Files API methods.
1Zoom
1Rooms
Jun 17, 2026
Nov 15, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper privilege management in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.
1Dell
1Powerscale Onefs
Jun 17, 2026
Nov 2, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure.
1Dell
1Powerscale Onefs
Jun 17, 2026
Aug 16, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Dell PowerScale OneFS 8.2x -9.5x contains a privilege escalation vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, to bypass mode protections and gain elevated privileges...Show more
Dell PowerScale OneFS 8.2x -9.5x contains a privilege escalation vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, to bypass mode protections and gain elevated privileges.   Show less
1M Files
1M Files
Jun 17, 2026
May 25, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications
1Checkmk
1Checkmk
Jun 17, 2026
Apr 18, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host.