← Back
CWE-282

29 CVEs • Abstraction: Class

Improper Ownership Management

The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.

JSON object

Loading...

CVEs (29)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jul 16, 2026
Jul 14, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by rep...Show more
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3.Show less
-
-
Jun 17, 2026
May 7, 2026
N/A· v4
6.3 MEDIUM· v3
N/A· v2
In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have n...Show more
In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project filtering, and policy checks are self-referential (the authorize_wsgi decorator compares the caller's project_id with itself rather than the target resource). Any authenticated non-admin user can complete various actions such as deleting ARQs bound to other projects' instances, aka cross-tenant denial of service.Show less
-
-
Jun 17, 2026
Apr 27, 2026
6.0 MEDIUM· v4
N/A· v3
N/A· v2
An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownership management, a low-privileged authenticated user may access a configuration file containing the has...Show more
An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownership management, a low-privileged authenticated user may access a configuration file containing the hashed password of the administrative account. Successful exploitation of this vulnerability could allow an attacker to obtain sensitive information. Exploitation is only possible under a specific condition — when the configuration file has been exported. This vulnerability does not impact the integrity or availability of the affected product, and no confidentiality, integrity, or availability impact to the subsequent system has been identified.Show less
1Accellion
1Kiteworks
Jun 17, 2026
Mar 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version...Show more
Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch.Show less
1Jenkins
1Hashicorp Vault
Jun 17, 2026
Dec 10, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Vault...Show more
Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Vault credentials they are not entitled to.Show less
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 20, 2025
N/A· v4
6.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership
1Ibm
1Openpages With Watson
Jun 17, 2026
Jul 9, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IBM OpenPages with Watson 8.3 and 9.0 could allow an authenticated user to obtain sensitive information that should only be available to privileged users.
-
-
Jun 17, 2026
Jun 27, 2025
N/A· v4
2.9 LOW· v3
N/A· v2
The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28...Show more
The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.Show less
1Ibm
1Infosphere Information Server
Jun 17, 2026
Jun 21, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to delete another user's comments due to improper ownership management.
1Framasoft
1Peertube
Jun 17, 2026
Apr 15, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and t...Show more
This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and then sets the associated channel to the channel ID supplied by the request, without checking if it belongs to the user.Show less
1Framasoft
1Peertube
Jun 17, 2026
Apr 15, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The vulnerability allows an existing user to add playlists to a different user’s channel using the PeerTube REST API. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and t...Show more
The vulnerability allows an existing user to add playlists to a different user’s channel using the PeerTube REST API. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and then sets the associated channel to the channel ID supplied by the request, without checking if it belongs to the user.Show less
-
-
Jun 17, 2026
Mar 10, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass.  The software's startup authentication can be disabled by altering a Windows registry setting that any user can modif...Show more
CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass.  The software's startup authentication can be disabled by altering a Windows registry setting that any user can modify.Show less
1Node Access Rebuild Progressive Project
1Node Access Rebuild Progressive
Jun 17, 2026
Jan 9, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 7.X-1.0 before 7.X-1.2.
1Node Access Rebuild Progressive Project
1Node Access Rebuild Progressive
Jun 17, 2026
Jan 9, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 0.0.0 before 2.0.2.
1Ibm
1Openpages With Watson
Jun 17, 2026
Jan 9, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should only be available to privileged users.
-
-
Jun 17, 2026
Oct 9, 2024
N/A· v4
6.4 MEDIUM· v3
N/A· v2
ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the database to tell who made what requests. Therefore, if a user on another wiki happens to have the sa...Show more
ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the database to tell who made what requests. Therefore, if a user on another wiki happens to have the same actor ID as someone on the central wiki, the user on the other wiki can act as if they're the original wiki requester. This can be abused to create new comments, edit the request, and view the request if it's marked private. This issue has been addressed in commit `5c91dfc` and all users are advised to update. Users unable to update may disable the special page outside of their global wiki. See `miraheze/mw-config@e566499` for details on that.Show less
1Veertu
1Anka Build Cloud
Jun 17, 2026
Oct 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lead to execute priviledged operation. An attacker can make an unauthenticated HT...Show more
A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lead to execute priviledged operation. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.Show less
1Oretnom23
1Online Eyewear Shop
Jun 17, 2026
Sep 17, 2024
5.3 MEDIUM· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability classified as critical has been found in SourceCodester Online Eyewear Shop 1.0. This affects an unknown part of the file /classes/Master.php of the component Cart Content Handler. The manipulation of the...Show more
A vulnerability classified as critical has been found in SourceCodester Online Eyewear Shop 1.0. This affects an unknown part of the file /classes/Master.php of the component Cart Content Handler. The manipulation of the argument cart_id/id leads to improper ownership management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.Show less
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Sep 13, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Sep 13, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.