CWE-274Base

Improper Handling of Insufficient Privileges

Draft in the CWE catalog · 40 CVEs mapped

40
CVEs mapped
7.4
Median CVSS
What it is

The product does not handle or incorrectly handles when it has insufficient privileges to perform an operation, leading to resultant weaknesses.

Recent examples
6.5cvss
CVE-2026-62764

CVE-2026-62764 - MEDIUM Severity Vulnerability

Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote command to gracefully shutdown system components (compaction-coordinator, compactor, gc, manager, monitor, tserver, or sserver), leading to a denial of service. This issue affects Apache Accumulo 2.1.4 and 2.1.5. Users are recommended to upgrade to version 2.1.6, which fixes the issue.

MEDIUMno explanation yet
0%
epss
5.3cvss
CVE-2025-54511

Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an input value to a function without…

Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an input value to a function without sufficient privileges and successfully write data, potentially resulting in loss of integrity of availability.

MEDIUMno explanation yet
0%
epss
4.3cvss
CVE-2026-33005

Apache OpenMeetings: Insufficient checks in FileWebService

Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at FileItemDTO object. This issue affects Apache OpenMeetings: from 3.10 before 9.0.0. Users are recommended to upgrade to version 9.0.0, which fixes the issue.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-274
Abstraction
Base
Structure
Simple
Status
Draft