The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.
Volume of CVEs assigned to CWE-282 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0386HIGH A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a u | Mar 22, 2023 | 7.8 | 78 | YES | YES |
CVE-2026-50130HIGH Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged | Jul 14, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-40214MEDIUM In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL | May 7, 2026 | 6.3 | 27 | NO | NO |
CVE-2026-3867MEDIUM An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownership management, a low-privileged authenticated user may access | Apr 27, 2026 | 6.0 | 27 | NO | NO |
CVE-2026-23514MEDIUM Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized co | Mar 25, 2026 | 6.5 | 25 | NO | NO |
CVE-2024-3383CRITICAL A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user | Apr 10, 2024 | 9.1 | 25 | NO | NO |
CVE-2024-8949HIGH A vulnerability classified as critical has been found in SourceCodester Online Eyewear Shop 1.0. This affects an unknown part of the file /classes/Master.php of the component Cart | Sep 17, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-37999HIGH A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes as a trusted account with high privileges and network acces | Jul 8, 2024 | 7.8 | 24 | NO | NO |
CVE-2025-27254HIGH CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass.
The software's startup authentication can be disabled by altering a Windows | Mar 10, 2025 | 8.0 | 23 | NO | NO |
CVE-2024-39755HIGH A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lead to execute priviledged operation. An | Oct 3, 2024 | 7.8 | 23 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.