Skip to main content

Threats Tagged 'cwe-282'

View all threats tagged with 'cwe-282'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-282

Threats Tagged 'cwe-282'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-40214 is a vulnerability in OpenStack Cyborg versions prior to 16.0.1 where the Accelerator Request (ARQ) API fails to enforce project ownership. The project_id field in the database is always NULL, and there is no project filtering in database queries. Policy checks incorrectly compare the caller's project_id with itself rather than the target resource. This allows any authenticated non-admin user to perform actions such as deleting ARQs associated with other projects, leading to cross-tenant denial of service.

Join the discussion

CVE-2026-3867 is an improper ownership management vulnerability in Moxa EDR-8010 Series Secure Router version 1.0. It allows a low-privileged authenticated user to access a configuration file containing the hashed password of the administrative account, but only if the configuration file has been exported. The vulnerability does not affect the integrity or availability of the product, nor does it impact the confidentiality, integrity, or availability of connected systems. Exploitation requires specific conditions and user privileges.

Join the discussion

Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch.

Join the discussion
0

In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership

Join the discussion

IBM OpenPages with Watson 8.3 and 9.0 could allow an authenticated user to obtain sensitive information that should only be available to privileged users.

Join the discussion

The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

Join the discussion

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to delete another user's comments due to improper ownership management.

Join the discussion

CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass.  The software's startup authentication can be disabled by altering a Windows registry setting that any user can modify.

Join the discussion
0

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Tag: cwe-282
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses