CWE-280: Improper Handling of Insufficient Permissions or Privileges
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.
137 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-46874 — Ruijie Reyee OS Improper Handling of Insufficient Permissions or Privileges
- CVE-2025-31173 — Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerab
- CVE-2025-27025 — Improper File Access in Infinera G42
- CVE-2026-2123 — Privilege escalation vulnerability in Operations Agent
- CVE-2024-51459 — IBM InfoSphere Server Information command execution
- CVE-2026-23857 — Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient P
- CVE-2025-22395 — Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. A loca
- CVE-2025-67848 — Moodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access.
- CVE-2025-62510 — FileRise insecure folder visibility via name-based mapping and incomplete ACL checks
- CVE-2025-62509 — FileRise improper ownership/permission validation allowed cross-tenant file operations
- CVE-2026-41566 — Apache Kvrocks: Improper permission for the APPLYBATCH command
- CVE-2025-46584 — Vulnerability of improper authentication logic implementation in the file system module Impact: Successful exploitation
- CVE-2025-3931 — Yggdrasil: local privilege escalation in yggdrasil
- CVE-2025-31172 — Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerab
- CVE-2025-46740 — Improper Handling of Insufficient Permissions
- CVE-2025-45376 — Dell Repository Manager (DRM), versions 3.4.7 and 3.4.8, contains an Improper Handling of Insufficient Permissions or Pr
- CVE-2026-59567 — Local privilege escalation
- CVE-2024-12430 — An attacker who successfully exploited these vulnerabilities could cause enable command execution. A vulnerability exist
- CVE-2026-18860 — Velociraptor incorrect Org deletion permissions check
- CVE-2025-58770 — TCG2 TPM RT Not Locked Issue
Recently published
- CVE-2026-55468 — Wagtail: Improper restriction handling on Pages admin API
- CVE-2026-59567 — Local privilege escalation
- CVE-2026-58416 — Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
- CVE-2026-73239 — Apache Allura: Missing permission checks IDOR
- CVE-2026-18860 — Velociraptor incorrect Org deletion permissions check
- CVE-2026-11804 — Program Module Vulnerability
- CVE-2026-62393 — Apache Kylin: Improper authorization in job information retrieval
- CVE-2026-45196 — GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers from host kernel
- CVE-2026-54262 — Wagtail: Pages translations can be created without page permissions when using simple_translation
- CVE-2026-54261 — Wagtail: Improper permission handling in image preview
- CVE-2026-54259 — Wagtail: Improper restriction handling on Documents and Images chosen endpoints
- CVE-2026-20463 — In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation o
- CVE-2026-45195 — GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted
- CVE-2026-41566 — Apache Kvrocks: Improper permission for the APPLYBATCH command
- CVE-2026-11764 — Data exposed without proper permission
- CVE-2026-10549 — Privilege escalation in Yandex Database
- CVE-2026-9792 — Keycloak: keycloak: security restriction bypass allows unauthorized ropc token acquisition
- CVE-2026-2340 — Samba: vfs_worm does not block directory modification
- CVE-2026-44201 — Wagtail: Improper restriction handling on Documents and Images API
- CVE-2026-44200 — Wagtail: Improper permission handling when copying pages