CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 64 of 99
- CVE-2023-27589MEDIUMCVSS 6.5EG 6.52023-03-14
Minio is a Multi-Cloud Object Storage framework. Starting with RELEASE.2020-12-23T02-24-12Z and prior to RELEASE.2023-03-13T19-46-17Z, a user with `consoleAdmin` permissions can potentially create a user that matches the root credential `a…
- CVE-2023-27645CRITICALCVSS 9.8EG 9.82023-04-11
An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQ preset parameters.
- CVE-2023-27651HIGHCVSS 7.8EG 7.82023-04-14
An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges via the update_info field of the _default_.xml file.
- CVE-2023-27654CRITICALCVSS 9.8EG 9.82023-04-14
An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a escalation of privileges via the TTMultiProvider component.
- CVE-2023-27793HIGHCVSS 7.8EG 7.82023-10-19
An issue discovered in IXP Data Easy Install v.6.6.14884.0 allows local attackers to gain escalated privileges via weak encoding of sensitive information.
- CVE-2023-27795HIGHCVSS 7.8EG 7.82023-10-19
An issue found in IXP Data Easy Install v.6.6.14884.0 allows a local attacker to gain privileges via a static XOR key.
- CVE-2023-27830CRITICALCVSS 9.0EG 9.02023-04-12
TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when executing a file transfer. This is due to the fact that TightVNC runs in the backend as a h…
- CVE-2023-28049MEDIUMCVSS 4.7EG 4.72024-02-06
Dell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authenticated malicious user may exploit this vulnerability in order to perform a privileged arbitrary file delete.
- CVE-2023-28122HIGHCVSS 7.8EG 7.82023-04-19
A local privilege escalation (LPE) vulnerability in UI Desktop for Windows (Version 0.59.1.71 and earlier) allows a malicious actor with local access to a Windows device running said application to submit arbitrary commands as SYSTEM.This …
- CVE-2023-28261MEDIUMCVSS 5.7EG 6.12023-04-27
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2023-2833HIGHCVSS 8.8EG 8.82023-06-06
The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, wi…
- CVE-2023-28339HIGHCVSS 8.8EG 8.82023-03-14
OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTE: TIOCSTI is unavailable in OpenBSD 6.0 and later, and can be made unavailable in the Linux kernel …
- CVE-2023-28434CRITICALCVSS 8.8EG 9.0⚠ KEV2023-03-22
Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To …
- CVE-2023-28436MEDIUMCVSS 5.7EG 5.72023-03-23
Tailscale is software for using Wireguard and multi-factor authentication (MFA). A vulnerability identified in the implementation of Tailscale SSH starting in version 1.34.0 and prior to prior to 1.38.2 in FreeBSD allows commands to be run…
- CVE-2023-2847HIGHCVSS 7.8EG 7.82023-06-15
During internal security analysis, a local privilege escalation vulnerability has been identified. On a machine with the affected ESET product installed, it was possible for a user with lower privileges due to improper privilege managemen…
- CVE-2023-28632HIGHCVSS 8.1EG 8.12023-04-05
GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, an authenticated user can modify emails of any user, and can therefore takeover another user account through the "fo…
- CVE-2023-28640MEDIUMCVSS 6.4EG 6.42023-03-27
Apiman is a flexible and open source API Management platform. Due to a missing permissions check, an attacker with an authenticated Apiman Manager account may be able to gain access to API keys they do not have permission for if they corre…
- CVE-2023-28737HIGHCVSS 8.8EG 8.82023-11-14
Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-28758HIGHCVSS 7.1EG 7.12023-03-23
An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files.
- CVE-2023-28855MEDIUMCVSS 6.5EG 6.52023-04-05
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to versions 1.13.1 and 1.20.4, lack of access control check allows any authenticated user to write data to any fields container, including those to w…
- CVE-2023-29018HIGHCVSS 8.0EG 8.02023-04-14
The OpenFeature Operator allows users to expose feature flags to applications. Assuming the pre-existence of a vulnerability that allows for arbitrary code execution, an attacker could leverage the lax permissions configured on `open-featu…
- CVE-2023-29056MEDIUMCVSS 5.3EG 5.32023-04-28
A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission…
- CVE-2023-29066LOWCVSS 3.2EG 3.22023-11-28
The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-administrative OS account can modify information stored in the local application data folders.
- CVE-2023-29166HIGHCVSS 8.8EG 8.82023-09-06
A logic issue was addressed with improved state management. This issue is fixed in Pro Video Formats 2.2.5. A user may be able to elevate privileges.
- CVE-2023-29240MEDIUMCVSS 5.4EG 5.42023-05-03
An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2023-29256MEDIUMCVSS 5.3EG 5.32023-07-10
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information disclosure due to improper privilege management when certain federation features are used. IBM X-Force ID: 252046.
- CVE-2023-29350HIGHCVSS 7.5EG 7.52023-05-05
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2023-29734CRITICALCVSS 9.8EG 9.82023-05-30
An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the database.
- CVE-2023-29819MEDIUMCVSS 5.5EG 5.52023-05-12
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload.
- CVE-2023-30024MEDIUMCVSS 6.6EG 6.62023-04-28
The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing unauthorized read/write access. Attackers can exploit this by replacing the original software with a malicious version, …
- CVE-2023-3027HIGHCVSS 7.8EG 7.82023-06-05
The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster) of taking advantage…
- CVE-2023-30601HIGHCVSS 7.8EG 7.82023-05-30
Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1. WORKAROU…
- CVE-2023-30617MEDIUMCVSS 6.5EG 6.52024-01-03
Kruise provides automated management of large-scale applications on Kubernetes. Starting in version 0.8.0 and prior to versions 1.3.1, 1.4.1, and 1.5.2, an attacker who has gained root privilege of the node that kruise-daemon run can lever…
- CVE-2023-30622MEDIUMCVSS 6.7EG 6.72023-04-24
Clusternet is a general-purpose system for controlling Kubernetes clusters across different environments. An issue in clusternet prior to version 0.15.2 can be leveraged to lead to a cluster-level privilege escalation. The clusternet has a…
- CVE-2023-30642MEDIUMCVSS 6.2EG 6.22023-07-06
Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege function.
- CVE-2023-30672MEDIUMCVSS 6.8EG 6.82023-07-06
Improper privilege management vulnerability in Samsung Smart Switch for Windows Installer prior to version 4.3.23043_3 allows attackers to cause permanent DoS via directory junction.
- CVE-2023-30680HIGHCVSS 8.4EG 8.42023-08-10
Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.
- CVE-2023-30713MEDIUMCVSS 6.2EG 6.22023-09-06
Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock.
- CVE-2023-30716MEDIUMCVSS 4.0EG 4.02023-09-06
Improper access control vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to trigger certain commands.
- CVE-2023-30717MEDIUMCVSS 4.0EG 4.02023-09-06
Sensitive information exposure vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to get unresettable identifiers.
- CVE-2023-3076CRITICALCVSS 9.8EG 9.82023-07-10
The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's …
- CVE-2023-30765HIGHCVSS 8.8EG 8.82023-07-10
Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege management configurations, resulting in privilege escalation.
- CVE-2023-30799CRITICALCVSS 9.1EG 9.12023-07-19
MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The …
- CVE-2023-30988HIGHCVSS 8.4EG 8.42023-07-16
The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to th…
- CVE-2023-30989HIGHCVSS 8.4EG 8.42023-07-16
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain all object access to the host o…
- CVE-2023-31005MEDIUMCVSS 6.2EG 6.22024-02-03
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a local user to escalate their privileges due to an improper…
- CVE-2023-31062CRITICALCVSS 9.8EG 9.82023-05-22
Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. When the attacker has access to a valid (but unprivileged) account, the exploit can be…
- CVE-2023-31175HIGHCVSS 8.8EG 8.82023-08-31
An Execution with Unnecessary Privileges vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run system commands with the highest level privilege on the system. See Instr…
- CVE-2023-31273CRITICALCVSS 10.0EG 10.02023-11-14
Protection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
- CVE-2023-31432HIGHCVSS 7.8EG 7.82023-08-02
Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid, a non-privileged user could obtain root privileges in Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c and …
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →