CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 65 of 99
- CVE-2023-31469HIGHCVSS 8.8EG 8.82023-06-23
A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles. The…
- CVE-2023-3160HIGHCVSS 7.8EG 7.82023-08-14
The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having proper permissions.
- CVE-2023-32194HIGHCVSS 7.2EG 7.22024-10-16
A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject will receive * permissions for core namespaces. This can lead to someone being capable …
- CVE-2023-32196MEDIUMCVSS 6.6EG 6.62024-10-16
A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobjects when external=true, which in specific scenarios can lead to privilege escalation.
- CVE-2023-32197MEDIUMCVSS 6.6EG 6.62025-04-16
A Improper Privilege Management vulnerability in SUSE rancher in RoleTemplateobjects when external=true is set can lead to privilege escalation in specific scenarios.This issue affects rancher: from 2.7.0 before 2.7.14, from 2.8.0 before 2…
- CVE-2023-32244CRITICALCVSS 9.8EG 9.82024-05-17
Improper Privilege Management vulnerability in xtemos Woodmart Core allows Privilege Escalation.This issue affects Woodmart Core: from n/a through 1.0.36.
- CVE-2023-32426HIGHCVSS 7.8EG 7.82023-09-06
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3. An app may be able to gain root privileges.
- CVE-2023-32451HIGHCVSS 7.3EG 7.32024-02-06
Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during installation and uninstallation
- CVE-2023-32457HIGHCVSS 7.5EG 7.52023-08-29
Dell PowerScale OneFS, versions 8.2.2.x-9.5.0.x, contains an improper privilege management vulnerability. A remote attacker with low privileges could potentially exploit this vulnerability, leading to escalation of privileges.
- CVE-2023-32487HIGHCVSS 7.8EG 7.82023-08-16
Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to denial of service, code execution and information disclosur…
- CVE-2023-32490MEDIUMCVSS 6.7EG 6.72023-08-16
Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attacker could potentially exploit this vulnerability, leading to system takeover.
- CVE-2023-32559CRITICALCVSS 7.5EG 9.82023-08-24
A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use of the deprecated API `process.binding()` can bypass the policy mechanism by requiring internal mod…
- CVE-2023-32696HIGHCVSS 8.8EG 8.82023-05-30
CKAN is an open-source data management system for powering data hubs and data portals. Prior to versions 2.9.9 and 2.10.1, the `ckan` user (equivalent to www-data) owned code and configuration files in the docker container and the `ckan` u…
- CVE-2023-32713HIGHCVSS 7.8EG 7.82023-06-01
In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process within the Splunk App for Stream to escalate their privileges on the machine that runs the Splunk Enterprise instance, …
- CVE-2023-33327HIGHCVSS 8.8EG 8.82024-05-14
Improper Privilege Management vulnerability in Teplitsa of social technologies Leyka allows Privilege Escalation.This issue affects Leyka: from n/a through 3.30.2.
- CVE-2023-3379MEDIUMCVSS 5.3EG 5.32023-11-20
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.
- CVE-2023-33966HIGHCVSS 8.6EG 8.62023-05-31
Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` or `node:https` modules are incorrectly not checked against the network permission allow l…
- CVE-2023-33972HIGHCVSS 7.2EG 7.22023-09-27
Scylladb is a NoSQL data store using the seastar framework, compatible with Apache Cassandra. Authenticated users who are authorized to create tables in a keyspace can escalate their privileges to access a table in the same keyspace, even …
- CVE-2023-34043MEDIUMCVSS 6.7EG 6.72023-09-27
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
- CVE-2023-34045MEDIUMCVSS 6.6EG 6.62023-10-20
VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when install…
- CVE-2023-34057HIGHCVSS 7.8EG 7.82023-10-27
VMware Tools contains a local privilege escalation vulnerability. A malicious actor with local user access to a guest virtual machine may elevate privileges within the virtual machine.
- CVE-2023-34118HIGHCVSS 7.3EG 7.32023-07-11
Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.
- CVE-2023-34120HIGHCVSS 8.7EG 8.72023-06-13
Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potenti…
- CVE-2023-34146HIGHCVSS 7.8EG 7.82023-06-26
An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affe…
- CVE-2023-34147HIGHCVSS 7.8EG 7.82023-06-26
An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affe…
- CVE-2023-34148HIGHCVSS 7.8EG 7.82023-06-26
An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affe…
- CVE-2023-34465CRITICALCVSS 9.9EG 9.92023-06-23
XWiki Platform is a generic wiki platform. Starting in version 11.8-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.2, `Mail.MailConfig` can be edited by any logged-in user by default. Consequently, they can change the mail obfuscation …
- CVE-2023-3460CRITICALCVSS 9.8EG 9.82023-07-04
The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited …
- CVE-2023-3467HIGHCVSS 8.0EG 8.02023-07-19
Privilege Escalation to root administrator (nsroot)
- CVE-2023-3513HIGHCVSS 7.8EG 7.82023-07-14
Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access to gain SYSTEM privilege via communicating with the named pipe as a low-privilege user a…
- CVE-2023-3514HIGHCVSS 7.8EG 7.82023-07-14
Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access to gain SYSTEM privilege via communicating with the named pipe as a low-privilege user an…
- CVE-2023-35140MEDIUMCVSS 5.5EG 5.52023-11-07
The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local user with read-only access to modify system settings on a vulnerable device.
- CVE-2023-35667HIGHCVSS 7.8EG 7.82023-09-11
In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the settings due to a logic error in the code. This could lead to local escalation of privilege with no additional executi…
- CVE-2023-35671MEDIUMCVSS 5.5EG 5.52023-09-11
In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode due to a logic error in the code. This c…
- CVE-2023-35674CRITICALCVSS 7.8EG 9.0⚠ KEV2023-09-11
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…
- CVE-2023-35676HIGHCVSS 7.8EG 7.82023-09-11
In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution priv…
- CVE-2023-36024HIGHCVSS 7.1EG 7.12023-11-10
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2023-36100CRITICALCVSS 9.8EG 9.82023-09-01
An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/User/ChangeUser.
- CVE-2023-3636HIGHCVSS 8.8EG 8.82023-08-31
The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for authenticated attac…
- CVE-2023-36496HIGHCVSS 7.7EG 7.72024-02-01
Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.
- CVE-2023-36537HIGHCVSS 7.3EG 7.32023-07-11
Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.
- CVE-2023-36569HIGHCVSS 8.4EG 8.42023-10-10
Microsoft Office Elevation of Privilege Vulnerability
- CVE-2023-36628HIGHCVSS 8.8EG 8.82023-10-03
A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access through privilege escalation.
- CVE-2023-36657CRITICALCVSS 9.8EG 9.82023-09-15
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Built-in features of Windows (desktop shortcuts, narrator) can be abused for privilege escalation.
- CVE-2023-36721HIGHCVSS 7.0EG 7.02023-10-10
Windows Error Reporting Service Elevation of Privilege Vulnerability
- CVE-2023-36765HIGHCVSS 7.8EG 7.82023-09-12
Microsoft Office Elevation of Privilege Vulnerability
- CVE-2023-3699HIGHCVSS 8.7EG 8.72023-08-22
An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage devices configuration. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below a…
- CVE-2023-37058CRITICALCVSS 9.8EG 9.82024-06-17
Insecure Permissions vulnerability in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to escalate privileges via a crafted command.
- CVE-2023-37389HIGHCVSS 8.8EG 8.82024-05-17
Improper Privilege Management vulnerability in SAASPROJECT Booking Package Booking Package allows Privilege Escalation.This issue affects Booking Package: from n/a through 1.5.98.
- CVE-2023-37859HIGHCVSS 7.2EG 7.22023-08-09
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privileges allowing a remote attacker with knowledge of the SNMPv2 r/w community string to execute system commands as root.
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →