CWE-280

CWE-280 · 4 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-280, highest CVSS first.

  1. MEDIUM 5.4CVE-2026-90462

    A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorrectly retur…

    AI risk analysis on Exploit-DB.ai →

  2. LOW 3.5CVE-2026-54471

    Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosu…

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-56729public PoC

    Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, when multiple KB categories have different editor roles assigned, a user with knowledge_base.editor in one category can see answer titles and updated_at timestamps from categor…

    AI risk analysis on Exploit-DB.ai →

  4. UNSCOREDCVE-2026-96872

    Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension on Linux, MacOS, and Windows allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki -…

    AI risk analysis on Exploit-DB.ai →