The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.
Volume of CVEs assigned to CWE-280 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
155 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-29748HIGH there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti | Apr 5, 2024 | 7.8 | 65 | YES | NO |
CVE-2024-24116CRITICAL An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm. | Oct 2, 2024 | 9.8 | 53 | NO | YES |
CVE-2026-41566CRITICAL Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: 2.8.0.
Users are recommended to upgrade to version | Jun 25, 2026 | 9.4 | 40 | NO | NO |
CVE-2026-20817HIGH Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 | 7.8 | 35 | NO | NO |
CVE-2025-46066CRITICAL An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges | Jan 12, 2026 | 9.9 | 35 | NO | NO |
CVE-2026-40371HIGH Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network. | Jun 9, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-45196HIGH Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU register access which can lead to privilege escalation. | Jul 10, 2026 | 7.8 | 33 | NO | NO |
CVE-2025-6573CRITICAL Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from the trusted execution environment (TEE). | Aug 9, 2025 | 9.8 | 33 | NO | NO |
CVE-2026-20463MEDIUM In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege if a malicious actor has already obtained the Sy | Jul 1, 2026 | 6.7 | 32 | NO | NO |
CVE-2026-54261MEDIUM Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint, a | Jul 1, 2026 | 6.5 | 31 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.