Threats Tagged 'cwe-281'
View all threats tagged with 'cwe-281'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-281'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-40767: CWE-281 Improper Preservation of Permissions in Tomdever wpForo ForumCVE-2026-40767 0 Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions. Join the discussion | CVE Database V5 | 06/15/2026, 20:18:15 UTC Added: 06/15/2026, 20:32:09 UTC |
CVE-2026-44832: CWE-281: Improper Preservation of Permissions in grokability snipe-itCVE-2026-44832 0 CVE-2026-44832 is a privilege escalation vulnerability in grokability's Snipe-IT IT asset/license management system versions prior to 8.4.1. An authenticated user with only the users.edit permission can escalate their privileges to admin by sending a specially crafted PATCH request to the user API endpoint. The API controller improperly preserves permissions by only stripping the superuser key but allowing the admin permission to be set, enabling unauthorized privilege escalation. This vulnerability is fixed in version 8.4.1. Join the discussion | CVE Database V5 | 05/26/2026, 19:29:31 UTC Added: 05/26/2026, 19:42:49 UTC |
CVE-2026-24194: CWE-281 Improper Preservation of Permissions in NVIDIA GeForceCVE-2026-24194 0 A vulnerability exists in the NVIDIA Display Driver for Linux in the kernel mode layer handler that improperly preserves permissions. Exploiting this flaw could allow a local user with limited privileges to cause denial of service, escalate privileges, disclose information, tamper with data, or execute arbitrary code. This affects all driver versions prior to 595.71.05. The vulnerability has a high severity score of 7.8 but no official patch or remediation guidance has been confirmed yet. Join the discussion | CVE Database V5 | 05/26/2026, 17:24:13 UTC Added: 05/26/2026, 18:02:29 UTC |
Showing 1 to 3 of 3 results