CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 61 of 99
- CVE-2022-44708HIGHCVSS 8.3EG 8.32022-12-13
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2022-44710HIGHCVSS 7.8EG 7.82022-12-13
DirectX Graphics Kernel Elevation of Privilege Vulnerability
- CVE-2022-44732HIGHCVSS 7.8EG 7.82022-11-07
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39900.
- CVE-2022-44733HIGHCVSS 7.8EG 7.82022-11-07
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39900.
- CVE-2022-44929CRITICALCVSS 9.8EG 9.82022-12-02
An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.
- CVE-2022-45069HIGHCVSS 6.3EG 8.82022-11-17
Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.
- CVE-2022-45101CRITICALCVSS 7.3EG 9.82023-02-01
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and …
- CVE-2022-45183HIGHCVSS 8.8EG 8.82022-11-14
Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to retrieve other app tokens by ID via an HTTP web request. Patched Versions are 3.5.3, 3.4.7, and 2.…
- CVE-2022-45451HIGHCVSS 7.8EG 8.82023-08-31
Local privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40173, Acronis Agent (Windows) before build 30600, Acronis Cybe…
- CVE-2022-45452HIGHCVSS 7.8EG 7.82023-05-18
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30430, Acronis Cyber Protect 15 (Windows) before build 30984.
- CVE-2022-45608HIGHCVSS 8.8EG 8.82023-03-01
An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and become an Administrator (TENANT_ADMIN) or (SYS_ADMIN) on the web application. It is important to no…
- CVE-2022-45853MEDIUMCVSS 6.7EG 6.72023-05-30
The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHI.3) could allow an authenticated, local attacker with administrator privileges to execute some sy…
- CVE-2022-45963CRITICALCVSS 9.8EG 9.82022-12-27
h3c firewall <= 3.10 ESS6703 has a privilege bypass vulnerability.
- CVE-2022-45988HIGHCVSS 7.8EG 7.82023-03-03
starsoftcomm CooCare 5.304 allows local attackers to escalate privileges and execute arbitrary commands via a crafted file upload.
- CVE-2022-46172MEDIUMCVSS 6.4EG 6.42022-12-28
authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticated user can create an arbitrary number of accounts through the default flows. This would ci…
- CVE-2022-46327CRITICALCVSS 9.8EG 9.82022-12-20
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions.
- CVE-2022-46334HIGHCVSS 7.8EG 7.82022-12-21
Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions. This affects all versions 8.19.0 and below.
- CVE-2022-46356HIGHCVSS 8.8EG 8.82023-01-30
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and information disclosure.
- CVE-2022-46357HIGHCVSS 8.8EG 8.82023-01-30
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and information disclosure.
- CVE-2022-46358HIGHCVSS 8.8EG 8.82023-01-30
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and information disclosure.
- CVE-2022-46359HIGHCVSS 8.8EG 8.82023-01-30
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and information disclosure.
- CVE-2022-46410HIGHCVSS 8.8EG 8.82022-12-04
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root by using specific commands.
- CVE-2022-4687HIGHCVSS 8.1EG 8.12022-12-23
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.
- CVE-2022-47505HIGHCVSS 7.8EG 7.82023-04-21
The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a local adversary with a valid system user account to escalate local privileges.
- CVE-2022-48019HIGHCVSS 7.8EG 7.82023-02-06
The components wfshbr64.sys and wfshbr32.sys in Another Eden before v3.0.20 and before v2.14.200 allows attackers to perform privilege escalation via a crafted payload.
- CVE-2022-4808HIGHCVSS 8.8EG 8.82022-12-28
Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-48226HIGHCVSS 7.8EG 7.82023-04-04
An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During installation, an EXE gets executed out of C:\Windows\Temp. A standard user can create the path file ahead of time and obtain elevated code execution. Permissions need…
- CVE-2022-48227HIGHCVSS 7.8EG 7.82023-04-04
An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It allows elevation of privileges because it opens Notepad after the installation of AssureID, Identify x64, and Identify x86, aka CORE-7361.
- CVE-2022-48279HIGHCVSS 7.5EG 7.52023-01-20
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSe…
- CVE-2022-48283CRITICALCVSS 9.8EG 9.82023-02-27
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.
- CVE-2022-48284CRITICALCVSS 9.8EG 9.82023-02-27
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.
- CVE-2022-48286HIGHCVSS 7.5EG 7.52023-02-09
The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-48341HIGHCVSS 8.8EG 8.82023-02-23
ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by modifying the scope via the scopes parameter.
- CVE-2022-48353CRITICALCVSS 9.8EG 9.82023-03-27
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause kernel privilege escalation, which results in system service exceptions.
- CVE-2022-48365HIGHCVSS 7.2EG 7.22023-03-12
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges.
- CVE-2022-48515HIGHCVSS 7.5EG 7.52023-07-06
Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-0101HIGHCVSS 8.8EG 8.82023-01-20
A privilege escalation vulnerability was identified in Nessus versions 8.10.1 through 8.15.8 and 10.0.0 through 10.4.1. An authenticated attacker could potentially execute a specially crafted file to obtain root or NT AUTHORITY / SYSTEM pr…
- CVE-2023-0192HIGHCVSS 4.7EG 7.82023-04-01
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer handler, where improper privilege management can lead to escalation of privileges and information disclosure.
- CVE-2023-0221MEDIUMCVSS 4.4EG 4.42023-01-13
Product security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypass the execution controls provided by ACC using the utilman program.
- CVE-2023-0242HIGHCVSS 8.8EG 8.82023-01-18
Rapid7 Velociraptor allows users to be created with different privileges on the server. Administrators are generally allowed to run any command on the server including writing arbitrary files. However, lower privilege users are generally f…
- CVE-2023-0524HIGHCVSS 8.8EG 8.82023-02-01
As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a malicious actor with sufficient permissions to modify environment variables and abuse an impacted plugin in…
- CVE-2023-0635HIGHCVSS 7.8EG 7.82023-06-05
Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG10010…
- CVE-2023-0664HIGHCVSS 7.8EG 7.82023-03-29
A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows installer via repair custom actions to elevate their privileges on the system.
- CVE-2023-0872HIGHCVSS 8.2EG 8.22023-08-14
The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elevation of privilege. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30…
- CVE-2023-0959MEDIUMCVSS 6.5EG 6.52023-04-05
Bhima version 1.27.0 allows a remote attacker to update the privileges of any account registered in the application via a malicious link sent to an administrator. This is possible because the application is vulnerable to CSRF.
- CVE-2023-0971CRITICALCVSS 9.6EG 9.62023-06-21
A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.
- CVE-2023-1326HIGHCVSS 7.7EG 7.72023-04-13
A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the t…
- CVE-2023-1548MEDIUMCVSS 5.5EG 5.52023-04-18
A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to perform a denial of service through the console server service that is part of EcoStruxure Control Expert. Affected Products: EcoStruxure Cont…
- CVE-2023-1597HIGHCVSS 8.8EG 8.82023-07-10
The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which…
- CVE-2023-1693HIGHCVSS 7.5EG 7.52023-05-20
The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →