A
CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation when the server is accessed by a privileged account via a console and through exploitation of a setup script.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.