CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
5,359 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 1 of 108
- CVE-2020-1472CRITICALCVSS 10.0EG 10.0⚠ KEV2020-08-17
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vu…
- CVE-2026-84869CRITICALCVSS 9.9EG 9.9⚠ KEV2026-09-08
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
- CVE-2026-46817CRITICALCVSS 9.8EG 9.8⚠ KEV2026-05-28
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network…
- CVE-2021-22941CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-23
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.
- CVE-2021-34523CRITICALCVSS 9.8EG 9.8⚠ KEV2021-07-14
Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2021-20021CRITICALCVSS 9.8EG 9.8⚠ KEV2021-04-09
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
- CVE-2021-21972CRITICALCVSS 9.8EG 9.8⚠ KEV2021-02-24
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlyi…
- CVE-2020-10181CRITICALCVSS 9.8EG 9.8⚠ KEV2020-03-11
goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) on a device, as demonstrated by a setString=new_user<*1*>administrator<*1*>123456 request.
- CVE-2019-7192CRITICALCVSS 9.8EG 9.8⚠ KEV2019-12-05
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
- CVE-2017-5689CRITICALCVSS 9.8EG 9.8⚠ KEV2017-05-02
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageab…
- CVE-2026-102490CRITICALCVSS 7.8EG 9.8⚠ KEV2026-09-30
Zammad packages built with packager.io (DEB and RPM) could have allowed a local attacker who already had file system write privileges as the unprivileged zammad service account to escalate to full root privileges on the host. Service proce…
- CVE-2023-28434CRITICALCVSS 8.8EG 9.0⚠ KEV2023-03-22
Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To …
- CVE-2022-41040CRITICALCVSS 8.8EG 9.0⚠ KEV2022-10-03
Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2022-23176CRITICALCVSS 8.8EG 9.0⚠ KEV2022-02-24
WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. This vulnerability impacts Fireware OS before 12.7.2_U1, 1…
- CVE-2021-42287CRITICALCVSS 8.8EG 9.0⚠ KEV2021-11-10
Active Directory Domain Services Elevation of Privilege Vulnerability
- CVE-2021-34527CRITICALCVSS 8.8EG 9.0⚠ KEV2021-07-02
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. …
- CVE-2021-28664CRITICALCVSS 8.8EG 9.0⚠ KEV2021-05-10
The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valh…
- CVE-2021-3493CRITICALCVSS 8.8EG 9.0⚠ KEV2021-04-17
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along…
- CVE-2013-0643CRITICALCVSS 8.8EG 9.0⚠ KEV2013-02-27
The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier f…
- CVE-2024-49035CRITICALCVSS 8.7EG 9.0⚠ KEV2024-11-26
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.
- CVE-2021-33739CRITICALCVSS 8.4EG 9.0⚠ KEV2021-06-08
Microsoft DWM Core Library Elevation of Privilege Vulnerability
- CVE-2021-23874CRITICALCVSS 8.2EG 9.0⚠ KEV2021-02-10
Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.
- CVE-2024-8068CRITICALCVSS 8.0EG 9.0⚠ KEV2024-11-12
Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain
- CVE-2026-21533CRITICALCVSS 7.8EG 9.0⚠ KEV2026-02-10
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
- CVE-2024-38014CRITICALCVSS 7.8EG 9.0⚠ KEV2024-09-10
Windows Installer Elevation of Privilege Vulnerability
- CVE-2024-26169CRITICALCVSS 7.8EG 9.0⚠ KEV2024-03-12
Windows Error Reporting Service Elevation of Privilege Vulnerability
- CVE-2023-35674CRITICALCVSS 7.8EG 9.0⚠ KEV2023-09-11
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…
- CVE-2022-22047CRITICALCVSS 7.8EG 9.0⚠ KEV2022-07-12
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
- CVE-2022-22960CRITICALCVSS 7.8EG 9.0⚠ KEV2022-04-13
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.
- CVE-2022-22718CRITICALCVSS 7.8EG 9.0⚠ KEV2022-02-09
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-21999CRITICALCVSS 7.8EG 9.0⚠ KEV2022-02-09
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-21882CRITICALCVSS 7.8EG 9.0⚠ KEV2022-01-11
Win32k Elevation of Privilege Vulnerability
- CVE-2021-43226CRITICALCVSS 7.8EG 9.0⚠ KEV2021-12-15
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2021-41379CRITICALCVSS 7.8EG 9.0⚠ KEV2021-11-10
Windows Installer Elevation of Privilege Vulnerability
- CVE-2021-41357CRITICALCVSS 7.8EG 9.0⚠ KEV2021-10-13
Win32k Elevation of Privilege Vulnerability
- CVE-2021-40450CRITICALCVSS 7.8EG 9.0⚠ KEV2021-10-13
Win32k Elevation of Privilege Vulnerability
- CVE-2021-40449CRITICALCVSS 7.8EG 9.0⚠ KEV2021-10-13
Win32k Elevation of Privilege Vulnerability
- CVE-2021-38649CRITICALCVSS 7.8EG 9.0⚠ KEV2021-09-15
Open Management Infrastructure Elevation of Privilege Vulnerability
- CVE-2021-38648CRITICALCVSS 7.8EG 9.0⚠ KEV2021-09-15
Open Management Infrastructure Elevation of Privilege Vulnerability
- CVE-2021-38645CRITICALCVSS 7.8EG 9.0⚠ KEV2021-09-15
Open Management Infrastructure Elevation of Privilege Vulnerability
- CVE-2021-36955CRITICALCVSS 7.8EG 9.0⚠ KEV2021-09-15
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2021-36948CRITICALCVSS 7.8EG 9.0⚠ KEV2021-08-12
Windows Update Medic Service Elevation of Privilege Vulnerability
- CVE-2021-34486CRITICALCVSS 7.8EG 9.0⚠ KEV2021-08-12
Windows Event Tracing Elevation of Privilege Vulnerability
- CVE-2021-34484CRITICALCVSS 7.8EG 9.0⚠ KEV2021-08-12
Windows User Profile Service Elevation of Privilege Vulnerability
- CVE-2021-36934CRITICALCVSS 7.8EG 9.0⚠ KEV2021-07-22
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerabi…
- CVE-2021-33771CRITICALCVSS 7.8EG 9.0⚠ KEV2021-07-14
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2021-31979CRITICALCVSS 7.8EG 9.0⚠ KEV2021-07-14
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2021-31956CRITICALCVSS 7.8EG 9.0⚠ KEV2021-06-08
Windows NTFS Elevation of Privilege Vulnerability
- CVE-2021-1675CRITICALCVSS 7.8EG 9.0⚠ KEV2021-06-08
Windows Print Spooler Remote Code Execution Vulnerability
- CVE-2021-28310CRITICALCVSS 7.8EG 9.0⚠ KEV2021-04-13
Win32k Elevation of Privilege Vulnerability
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →