CWE-282: Improper Ownership Management
The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.
29 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-23514 — Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management
- CVE-2024-37999 — A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes
- CVE-2025-27254 — CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass. The software's s
- CVE-2024-39755 — A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially cr
- CVE-2025-57732 — In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership
- CVE-2026-50130 — Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`
- CVE-2024-47816 — Users can impersonate import requesters if their actor IDs coincide in ImportDump
- CVE-2024-43176 — IBM OpenPages information disclosure
- CVE-2025-32946 — PeerTube Arbitrary Playlist Creation via ActivityPub Protocol
- CVE-2026-40214 — In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. Th
- CVE-2026-3867 — An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownershi
- CVE-2026-86769 — Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout
- CVE-2025-3629 — IBM InfoSphere Information Server file manipulation
- CVE-2025-32945 — PeerTube Arbitrary Playlist Creation via REST API
- CVE-2025-1112 — IBM OpenPages with Watson information disclosure
- CVE-2025-46416 — The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges t
- CVE-2024-13249 — Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-013
- CVE-2024-13246 — Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-010
Recently published
- CVE-2026-86769 — Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout
- CVE-2026-50130 — Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`
- CVE-2026-40214 — In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. Th
- CVE-2026-3867 — An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownershi
- CVE-2026-23514 — Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management
- CVE-2025-57732 — In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership
- CVE-2025-1112 — IBM OpenPages with Watson information disclosure
- CVE-2025-46416 — The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges t
- CVE-2025-3629 — IBM InfoSphere Information Server file manipulation
- CVE-2025-32946 — PeerTube Arbitrary Playlist Creation via ActivityPub Protocol
- CVE-2025-32945 — PeerTube Arbitrary Playlist Creation via REST API
- CVE-2025-27254 — CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass. The software's s
- CVE-2024-13249 — Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-013
- CVE-2024-13246 — Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-010
- CVE-2024-43176 — IBM OpenPages information disclosure
- CVE-2024-47816 — Users can impersonate import requesters if their actor IDs coincide in ImportDump
- CVE-2024-39755 — A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially cr
- CVE-2024-37999 — A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes