Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-281'

View all threats tagged with 'cwe-281'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-281

Threats Tagged 'cwe-281'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-40767: CWE-281 Improper Preservation of Permissions in Tomdever wpForo ForumCVE-2026-40767
0

Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions.

Join the discussion
CVE-2026-44832: CWE-281: Improper Preservation of Permissions in grokability snipe-itCVE-2026-44832
0

CVE-2026-44832 is a privilege escalation vulnerability in grokability's Snipe-IT IT asset/license management system versions prior to 8.4.1. An authenticated user with only the users.edit permission can escalate their privileges to admin by sending a specially crafted PATCH request to the user API endpoint. The API controller improperly preserves permissions by only stripping the superuser key but allowing the admin permission to be set, enabling unauthorized privilege escalation. This vulnerability is fixed in version 8.4.1.

Join the discussion
CVE-2026-24194: CWE-281 Improper Preservation of Permissions in NVIDIA GeForceCVE-2026-24194
0

A vulnerability exists in the NVIDIA Display Driver for Linux in the kernel mode layer handler that improperly preserves permissions. Exploiting this flaw could allow a local user with limited privileges to cause denial of service, escalate privileges, disclose information, tamper with data, or execute arbitrary code. This affects all driver versions prior to 595.71.05. The vulnerability has a high severity score of 7.8 but no official patch or remediation guidance has been confirmed yet.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: cwe-281
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses