Vulnerability index

Browse CVEs

23 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Ranger CRITICAL 9.8
CVE-2026-40920

Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe…

No fix yet
Fix from $5,750 2026-08-10
Syncope CRITICAL 9.8
CVE-2026-62183

Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user wor…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Apache Airflow Providers Fab HIGH 8.1
CVE-2026-59245

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resour…

Fix: 3.7.2+
Fix from $1,950 2026-07-13
HTTP Server MEDIUM 5.5
CVE-2026-44119

Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges…

Fix: 2.4.68+
Fix from $1,600 2026-06-08
HTTP Server HIGH 8.8
CVE-2026-24072

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges …

Fix: 2.4.67+
Fix from $1,950 2026-05-04
Streampipes HIGH 8.1
CVE-2025-47411EPSS 15%

A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows th…

Fix: 0.98.0+
Fix from $1,950 2026-01-01
Kvrocks MEDIUM 5.4
CVE-2025-59790

Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommende…

Fix: 2.14.0+
Fix from $1,600 2025-11-28
Cloudstack HIGH 8.8
CVE-2025-47713

A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d…

Fix: 4.19.3.0 / 4.20.1.0+
Fix from $1,950 2025-06-10
Cloudstack HIGH 8.8
CVE-2025-47849

A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d…

Fix: 4.19.3.0 / 4.20.1.0+
Fix from $1,950 2025-06-10
Streampipes MEDIUM 6.5
CVE-2024-24778

Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This i…

Fix: 0.97.0+
Fix from $1,600 2025-03-03
Kafka MEDIUM 6.5
CVE-2024-31141

Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accep…

Fix: after 3.6.2
Fix from $1,600 2024-11-19
Linkis HIGH 8.8
CVE-2024-27181

In Apache Linkis <= 1.5.0, Privilege Escalation in Basic management services where the attacking user is a trusted account allows access to Link…

Fix: 1.6.0+
Fix from $1,950 2024-08-02
Fineract HIGH 8.8
CVE-2024-23537

Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to versi…

Fix: 1.9.0+
Fix from $1,950 2024-03-29
Streampipes HIGH 8.8
CVE-2023-31469

A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user wi…

Fix: after 0.91.0
Fix from $1,950 2023-06-23
Cassandra HIGH 7.8
CVE-2023-30601

Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This iss…

Fix: 4.0.10 / 4.1.2+
Fix from $1,950 2023-05-30
Inlong CRITICAL 9.8
CVE-2023-31062

Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.…

Fix: after 1.6.0
Fix from $2,300 2023-05-22
Spark CRITICAL 9.9
CVE-2023-22946

In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application c…

Fix: 3.4.0+
Fix from $2,300 2023-04-17
Shenyu HIGH 8.8
CVE-2022-42735

Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privilege low-level administrators…

Mitigation only
Fix from $1,950 2023-02-15
Airflow CRITICAL 9.8
CVE-2021-38540EPSS 81%

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint …

Fix: 2.1.3+
Fix from $2,300 2021-09-09
Airflow MEDIUM 5.3
CVE-2021-26697

The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to h…

Mitigation only
Fix from $1,600 2021-02-17
Hadoop HIGH 7.4
CVE-2018-11767

In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-d…

Fix: after 2.9.1
Fix from $1,950 2019-03-21
Karaf HIGH 8.8
CVE-2018-11786

In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with ri…

Fix: 4.2.0+
Fix from $1,950 2018-09-18
Couchdb CRITICAL 9.8
CVE-2017-12635EPSS 100%

Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1…

Fix: 1.7.0+
Fix from $2,300 2017-11-14