In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.