CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 67 of 99
- CVE-2023-41715HIGHCVSS 8.8EG 8.82023-10-17
SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel.
- CVE-2023-41743HIGHCVSS 7.8EG 8.82023-08-31
Local privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278, Acronis Cyber Protect Cloud Agent (Windows) before build…
- CVE-2023-41776HIGHCVSS 7.8EG 7.82024-01-03
There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to escalate local privileges.
- CVE-2023-41784MEDIUMCVSS 5.5EG 6.62024-01-04
Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro
- CVE-2023-41806HIGHCVSS 7.5EG 8.22023-11-23
Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability causes that a bad privilege assignment could cause a DOS attack that affects the availability of the Pandora FMS server. This…
- CVE-2023-41807CRITICALCVSS 8.8EG 9.12023-11-23
Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows a user to escalate permissions on the system shell. This issue affects Pandora FMS: from 700 through 773.
- CVE-2023-41808HIGHCVSS 7.5EG 8.52023-11-23
Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows an unauthorised user to escalate and read sensitive files as if they were root. This issue affects Pandora FMS: from 7…
- CVE-2023-41954HIGHCVSS 8.6EG 8.62024-05-17
Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.
- CVE-2023-41955HIGHCVSS 8.8EG 8.82024-05-17
Improper Privilege Management vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation.This issue affects Essential Addons for Elementor: from n/a through 5.8.8.
- CVE-2023-41957HIGHCVSS 8.6EG 8.62024-05-17
Improper Privilege Management vulnerability in smp7, wp.Insider Simple Membership allows Privilege Escalation.This issue affects Simple Membership: from n/a through 4.3.4.
- CVE-2023-41966HIGHCVSS 8.8EG 8.82023-10-26
The application suffers from a privilege escalation vulnerability. A user with read permissions can elevate privileges by sending a HTTP POST to set a parameter.
- CVE-2023-41972HIGHCVSS 7.3EG 7.32024-03-26
In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121 and later.
- CVE-2023-4239HIGHCVSS 6.5EG 8.82023-08-09
The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated att…
- CVE-2023-42468MEDIUMCVSS 5.3EG 5.32023-09-13
The com.cutestudio.colordialer application through 2.1.8-2 for Android allows a remote attacker to initiate phone calls without user consent, because of improper export of the com.cutestudio.dialer.activities.DialerActivity component. A th…
- CVE-2023-4278HIGHCVSS 7.5EG 7.52023-09-11
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor. They can then add courses and/or posts.
- CVE-2023-4293HIGHCVSS 6.5EG 8.82023-08-12
The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restriction on the 'wpdmpp_update_profile' function. This makes it…
- CVE-2023-42952MEDIUMCVSS 4.4EG 4.42024-02-21
The issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.1. An app with root privileges may be able to access private information.
- CVE-2023-43018HIGHCVSS 7.5EG 7.52023-11-03
IBM CICS TX Standard 11.1 and Advanced 10.1, 11.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: …
- CVE-2023-43120HIGHCVSS 8.8EG 8.82023-10-16
An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attackers to gain escalated privileges via crafted HTTP request.
- CVE-2023-43317HIGHCVSS 8.8EG 8.82024-01-24
An issue in Coign CRM Portal v.06.06 allows a remote attacker to escalate privileges via the userPermissionsList parameter in Session Storage component.
- CVE-2023-43457CRITICALCVSS 9.8EG 9.82023-09-25
An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint.
- CVE-2023-43506HIGHCVSS 7.8EG 7.82023-10-25
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role. A successful exploit allows malicious users to execute arbitrary code with…
- CVE-2023-43591HIGHCVSS 7.8EG 7.82023-11-15
Improper privilege management in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2023-43663MEDIUMCVSS 4.3EG 4.32023-09-28
PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionali…
- CVE-2023-43664MEDIUMCVSS 4.3EG 4.32023-09-28
PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list all modules without any access rights: method `ajaxProcessGetPossibleHookingListForModule` doesn't check access rights. …
- CVE-2023-43766HIGHCVSS 7.8EG 7.82023-09-22
Certain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoi…
- CVE-2023-43845CRITICALCVSS 9.8EG 9.82024-05-28
Aten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged telnet account. The user is not asked to change the credentials after first login. If not changed, attackers can log in to the telnet console and gain administrato…
- CVE-2023-43960HIGHCVSS 8.8EG 8.82023-10-11
An issue in DLINK DPH-400SE FRU 2.2.15.8 allows a remote attacker to escalate privileges via the User Modify function in the Maintenance/Access function component.
- CVE-2023-4404CRITICALCVSS 9.8EG 9.82023-08-23
The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insufficient restriction on the 'update_core_user' function. This makes it possible for unauthent…
- CVE-2023-44105CRITICALCVSS 9.8EG 9.82023-10-11
Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2023-44106CRITICALCVSS 9.8EG 9.82023-10-11
API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2023-44217HIGHCVSS 7.8EG 7.82023-10-03
A local privilege escalation vulnerability in SonicWall Net Extender MSI client for Windows 10.2.336 and earlier versions allows a local low-privileged user to gain system privileges through running repair functionality.
- CVE-2023-44219HIGHCVSS 7.8EG 7.82023-10-27
A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earlier versions allows a local low-privileged user to gain system privileges through running the recovery feature.
- CVE-2023-44250HIGHCVSS 8.8EG 8.82024-01-10
An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version 7.4.0 through 7.4.1 allows an authenticated attacker to perform elevated…
- CVE-2023-44282HIGHCVSS 7.8EG 7.82023-11-16
Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges.…
- CVE-2023-44292HIGHCVSS 7.8EG 7.82023-11-16
Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges.…
- CVE-2023-44809CRITICALCVSS 9.8EG 9.82023-10-16
D-Link device DIR-820L 1.05B03 is vulnerable to Insecure Permissions.
- CVE-2023-45083MEDIUMCVSS 4.4EG 4.42023-12-05
An Improper Privilege Management vulnerability exists in HyperCloud that will impact the ability for a user to authenticate against the management plane. An authenticated admin-level user may be able to delete the "admin" or "serveradmin"…
- CVE-2023-45253HIGHCVSS 7.8EG 7.82023-12-01
An issue was discovered in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, allows attackers to manipulate files and escalate privileges via RollingFileAppender.DeleteFile method performed by the log4net library.
- CVE-2023-45320MEDIUMCVSS 6.7EG 6.72024-05-16
Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-45581HIGHCVSS 8.8EG 8.82024-02-15
An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site administrator with Super Admin privileges to perform global administrative operations affecti…
- CVE-2023-45883HIGHCVSS 7.8EG 7.82023-10-19
A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers a repair of the software, a pop-up window opens with SYSTEM privileges. Standard users may use this…
- CVE-2023-4607HIGHCVSS 8.8EG 8.82023-10-25
An authenticated XCC user can change permissions for any user through a crafted API command.
- CVE-2023-46145HIGHCVSS 8.8EG 8.82024-05-17
Improper Privilege Management vulnerability in Themify Themify Ultra allows Privilege Escalation.This issue affects Themify Ultra: from n/a through 7.3.5.
- CVE-2023-46277HIGHCVSS 7.8EG 7.82023-10-20
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.)
- CVE-2023-4662CRITICALCVSS 9.8EG 10.02023-09-15
Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion. This issue affects Saphira Connect: before 9.
- CVE-2023-46647HIGHCVSS 8.8EG 8.82023-12-21
Improper privilege management in all versions of GitHub Enterprise Server allows users with authorized access to the management console with an editor role to escalate their privileges by making requests to the endpoint used for bootstrapp…
- CVE-2023-46756MEDIUMCVSS 5.3EG 5.32023-11-08
Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows.
- CVE-2023-46758HIGHCVSS 7.5EG 7.52023-11-08
Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.
- CVE-2023-46771HIGHCVSS 7.5EG 7.52023-11-08
Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality.
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →