CWE-280Base

Improper Handling of Insufficient Permissions or Privileges

Draft in the CWE catalog · 138 CVEs mapped

138
CVEs mapped
6.5
Median CVSS
What it is

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

Recent examples
4.3cvss
CVE-2026-55468

CVE-2026-55468 - MEDIUM Severity Vulnerability

Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2.

MEDIUMno explanation yet
0%
epss
8.8cvss
CVE-2026-59567

CVE-2026-59567 - HIGH Severity Vulnerability

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.

HIGHno explanation yet
0%
epss
7.1cvss
CVE-2026-58416

CVE-2026-58416 - HIGH Severity Vulnerability

Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-280
Abstraction
Base
Structure
Simple
Status
Draft