Threats Tagged 'cwe-282'
View all threats tagged with 'cwe-282'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-282'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-40214 is a vulnerability in OpenStack Cyborg versions prior to 16.0.1 where the Accelerator Request (ARQ) API fails to enforce project ownership. The project_id field in the database is always NULL, and there is no project filtering in database queries. Policy checks incorrectly compare the caller's project_id with itself rather than the target resource. This allows any authenticated non-admin user to perform actions such as deleting ARQs associated with other projects, leading to cross-tenant denial of service. Join the discussion | CVE Database V5 | 05/07/2026, 00:00:00 UTC Added: 05/07/2026, 22:06:23 UTC |
CVE-2026-3867 is an improper ownership management vulnerability in Moxa EDR-8010 Series Secure Router version 1.0. It allows a low-privileged authenticated user to access a configuration file containing the hashed password of the administrative account, but only if the configuration file has been exported. The vulnerability does not affect the integrity or availability of the product, nor does it impact the confidentiality, integrity, or availability of connected systems. Exploitation requires specific conditions and user privileges. Join the discussion | CVE Database V5 | 04/27/2026, 02:54:00 UTC Added: 04/27/2026, 04:15:06 UTC |
Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch. Join the discussion | CVE Database V5 | 03/25/2026, 14:19:01 UTC Added: 03/25/2026, 14:31:14 UTC |
0 In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership Join the discussion | CVE Database V5 | 08/20/2025, 09:14:00 UTC Added: 08/20/2025, 09:17:47 UTC |
IBM OpenPages with Watson 8.3 and 9.0 could allow an authenticated user to obtain sensitive information that should only be available to privileged users. Join the discussion | CVE Database V5 | 07/09/2025, 14:33:12 UTC Added: 07/09/2025, 14:55:00 UTC |
The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b. Join the discussion | CVE Database V5 | 06/27/2025, 00:00:00 UTC Added: 06/27/2025, 13:44:18 UTC |
0 IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to delete another user's comments due to improper ownership management. Join the discussion | CVE Database V5 | 06/21/2025, 12:45:57 UTC Added: 06/21/2025, 13:06:07 UTC |
0 CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass. The software's startup authentication can be disabled by altering a Windows registry setting that any user can modify. Join the discussion | CVE Database V5 | 03/10/2025, 09:05:08 UTC Added: 10/07/2025, 14:30:49 UTC |
0 A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system. Join the discussion | CVE Database V5 | 03/22/2023, 00:00:00 UTC Added: 10/21/2025, 19:06:12 UTC |
Showing 1 to 9 of 9 results