CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 63 of 99
- CVE-2023-22331HIGHCVSS 7.5EG 7.52023-01-20
Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to alter user credentials information.
- CVE-2023-2240HIGHCVSS 8.8EG 8.82023-04-22
Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.
- CVE-2023-22576HIGHCVSS 7.0EG 7.02024-08-21
Dell Repository Manager version 3.4.2 and earlier, contain a Local Privilege Escalation Vulnerability in Installation module. A local low privileged attacker may potentially exploit this vulnerability leading to the execution of arbitrary …
- CVE-2023-22645HIGHCVSS 8.0EG 8.02023-04-19
An Improper Privilege Management vulnerability in SUSE kubewarden allows attackers to read arbitrary secrets if they get access to the ServiceAccount kubewarden-controller This issue affects: SUSE kubewarden kubewarden-controller versions …
- CVE-2023-22651CRITICALCVSS 9.9EG 9.92023-05-04
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhook. This component enforces validation rul…
- CVE-2023-22809HIGHCVSS 7.8EG 8.42023-01-18
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of fil…
- CVE-2023-22946MEDIUMCVSS 6.4EG 6.42023-04-17
In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application can execute code with the privileges of the submitting user, however, by providing maliciou…
- CVE-2023-23412HIGHCVSS 7.8EG 7.82023-03-14
Windows Accounts Picture Elevation of Privilege Vulnerability
- CVE-2023-23427MEDIUMCVSS 4.0EG 4.02023-12-29
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
- CVE-2023-23428LOWCVSS 3.3EG 3.32023-12-29
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
- CVE-2023-23429MEDIUMCVSS 4.0EG 4.02023-12-29
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
- CVE-2023-23430LOWCVSS 3.3EG 3.32023-12-29
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
- CVE-2023-23438MEDIUMCVSS 4.0EG 4.02023-12-29
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions
- CVE-2023-23497HIGHCVSS 7.8EG 7.82023-02-27
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey 12.6.3. An app may be able to gain root privileges.
- CVE-2023-23610MEDIUMCVSS 6.5EG 6.52023-01-26
GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standard interface can export data of almost any GLPI item type, ev…
- CVE-2023-23629MEDIUMCVSS 6.3EG 6.32023-01-28
Metabase is an open source data analytics platform. Affected versions are subject to Improper Privilege Management. As intended, recipients of dashboards subscriptions can view the data as seen by the creator of that subscription. This all…
- CVE-2023-23990HIGHCVSS 7.6EG 7.62024-05-17
Improper Privilege Management vulnerability in Qube One Ltd. Redirection for Contact Form 7 wpcf7-redirect allows Privilege Escalation.This issue affects Redirection for Contact Form 7: from n/a through 2.7.0.
- CVE-2023-24483HIGHCVSS 7.8EG 7.82023-02-16
A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.
- CVE-2023-24491HIGHCVSS 7.8EG 7.82023-07-11
A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate …
- CVE-2023-24509CRITICALCVSS 9.3EG 9.32023-04-13
On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root use…
- CVE-2023-24760HIGHCVSS 8.8EG 8.82023-03-16
An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.
- CVE-2023-2485MEDIUMCVSS 4.4EG 4.42023-06-07
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can …
- CVE-2023-2495MEDIUMCVSS 4.3EG 4.32023-07-10
The Greeklish-permalink WordPress plugin through 3.3 does not implement correct authorization or nonce checks in the cyrtrans_ajax_old AJAX action, allowing unauthenticated and low-privilege users to trigger the plugin's functionality to c…
- CVE-2023-25011HIGHCVSS 7.8EG 7.82023-02-15
PC settings tool Ver10.1.26.0 and earlier, PC settings tool Ver11.0.22.0 and earlier allows a attacker to write to the registry as administrator privileges with standard user privileges.
- CVE-2023-25133CRITICALCVSS 9.1EG 9.12023-04-24
Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 3…
- CVE-2023-25144HIGHCVSS 7.8EG 7.82023-03-10
An improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated privileges and create arbitrary directories with arbitrary ownership.
- CVE-2023-25149HIGHCVSS 8.8EG 8.82023-02-14
TimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through 2.9.2. During installation, TimescaleDB creates a telemetry job that is runs as the installation user. The queries run…
- CVE-2023-25185LOWCVSS 3.8EG 3.82023-06-16
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN software releases. Certain software processes in the BTS internal software design have un…
- CVE-2023-25188MEDIUMCVSS 5.1EG 5.12023-06-16
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from the Nokia Single RAN BTS baseband unit, the BTS baseband unit diagnostic tool AaShell (whi…
- CVE-2023-25521HIGHCVSS 7.5EG 7.52023-07-04
NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause execution with unnecessary privileges by leveraging a weakness whereby proper input parameter validation is not performed. A successful exploit of thi…
- CVE-2023-25535HIGHCVSS 7.2EG 7.22024-02-14
Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has a high vulnerability that can result in local privilege escalation (LPE). This vulnerability only affects first-time in…
- CVE-2023-25590HIGHCVSS 7.8EG 7.82023-03-22
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role. A successful exploit allows malicious users to execute arbitrary code with roo…
- CVE-2023-25647MEDIUMCVSS 4.7EG 4.72023-08-17
There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.
- CVE-2023-25701CRITICALCVSS 9.8EG 9.82024-05-17
Improper Privilege Management vulnerability in WhatArmy WatchTowerHQ allows Privilege Escalation.This issue affects WatchTowerHQ: from n/a through 3.6.16.
- CVE-2023-25834MEDIUMCVSS 5.4EG 5.42023-05-09
Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to access content that they are no longer privileged to access.
- CVE-2023-26009CRITICALCVSS 9.8EG 9.82024-05-17
Improper Privilege Management vulnerability in Favethemes Houzez Login Register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through 2.6.3.
- CVE-2023-26062HIGHCVSS 7.0EG 7.02023-06-14
A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute administrative functions. Exploitation is not possible from outside of mobile network sol…
- CVE-2023-26236HIGHCVSS 7.8EG 7.82023-10-05
An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGuard EPDR processes, it is possible to perform a Local Privilege Escalation on Windows by sending a crafted message to a…
- CVE-2023-26243HIGHCVSS 7.8EG 7.82023-04-27
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to decrypt firmware files has an information leak that allows an attacker to read the AES key and ini…
- CVE-2023-26244HIGHCVSS 7.8EG 7.82023-04-27
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDMClient binary file, which is used during the firmware installation process, can be modified by an attacker to bypass th…
- CVE-2023-26245HIGHCVSS 7.8EG 7.82023-04-27
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is used during the firmware installation process, can be modified by an attacker to bypass the…
- CVE-2023-26246HIGHCVSS 7.8EG 7.82023-04-27
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is used during the firmware installation process, can be modified by an attacker to bypass the…
- CVE-2023-26475CRITICALCVSS 9.9EG 9.92023-03-02
XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by a…
- CVE-2023-26540CRITICALCVSS 9.8EG 9.82024-05-17
Improper Privilege Management vulnerability in Favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 2.7.1.
- CVE-2023-26600MEDIUMCVSS 6.5EG 6.52023-03-06
ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports.
- CVE-2023-26604HIGHCVSS 7.8EG 7.82023-03-03
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1…
- CVE-2023-2679MEDIUMCVSS 4.1EG 4.12023-05-17
Data leakage in Adobe connector in Snow Software SPE 9.27.0 on Windows allows privileged user to observe other users data.
- CVE-2023-27094HIGHCVSS 8.8EG 8.82023-03-23
An issue found in OpenGoofy Hippo4j v.1.4.3 allows attackers to escalate privileges via the ThreadPoolController of the tenant Management module.
- CVE-2023-27316HIGHCVSS 8.8EG 8.82023-10-12
SnapCenter versions 4.8 through 4.9 are susceptible to a vulnerability which may allow an authenticated SnapCenter Server user to become an admin user on a remote system where a SnapCenter plug-in has been installed.
- CVE-2023-27558HIGHCVSS 8.4EG 8.42023-07-10
IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed service using an unquoted service path. A local attacker could exploit this vulnerability to gain elevated privileges by…
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →