CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 68 of 99
- CVE-2023-46810HIGHCVSS 7.3EG 7.32024-05-31
A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute code as root.
- CVE-2023-4697HIGHCVSS 8.8EG 8.82023-09-01
Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.
- CVE-2023-47101HIGHCVSS 7.8EG 7.82023-10-30
The installer (aka openvpn-client-installer) in Securepoint SSL VPN Client before 2.0.40 allows local privilege escalation during installation or repair.
- CVE-2023-47132CRITICALCVSS 9.8EG 9.82024-02-08
An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.
- CVE-2023-47145HIGHCVSS 7.8EG 8.42024-01-07
IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using the MSI repair functionality. IBM X-Force ID: 270402.
- CVE-2023-47201HIGHCVSS 7.8EG 7.82024-01-23
A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execut…
- CVE-2023-47267CRITICALCVSS 9.8EG 9.82023-12-19
An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and Windows Enterprise VPN Client 6.87 allows attackers to gain escalated privileges via crafted changes to memory mapped fi…
- CVE-2023-47611HIGHCVSS 7.8EG 7.82023-11-10
A CWE-269: Improper Privilege Management vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to…
- CVE-2023-47629HIGHCVSS 8.0EG 8.02023-11-14
DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restrict users from signing up as privileged accounts. If a user is given an email sign-up link they can potentially create …
- CVE-2023-47682HIGHCVSS 7.2EG 7.22024-05-17
Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5.
- CVE-2023-47683HIGHCVSS 8.0EG 8.02024-05-17
Improper Privilege Management vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Privilege Escalation.This issue affects WordPress Social Login and Register (Discord, Google, Twitter…
- CVE-2023-47715MEDIUMCVSS 4.3EG 4.32024-03-21
IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor configuration. IBM X-Force ID: 271538.
- CVE-2023-47782HIGHCVSS 8.8EG 8.82024-05-17
Improper Privilege Management vulnerability in Thrive Themes Thrive Theme Builder allows Privilege Escalation.This issue affects Thrive Theme Builder: from n/a before 3.24.0.
- CVE-2023-47837HIGHCVSS 8.3EG 8.32024-06-04
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.
- CVE-2023-47868HIGHCVSS 7.3EG 7.32024-05-17
Improper Privilege Management vulnerability in wpForo wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: from n/a through 2.2.3.
- CVE-2023-48171HIGHCVSS 8.8EG 8.82024-08-12
An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.
- CVE-2023-4822HIGHCVSS 7.2EG 7.22023-10-16
Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permission…
- CVE-2023-48319MEDIUMCVSS 6.8EG 6.82024-05-17
Improper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6.
- CVE-2023-4834MEDIUMCVSS 4.3EG 4.32023-10-16
In Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an improperly implemented access validation allows an authenticated, low privileged attacker to gain read access to lim…
- CVE-2023-48406MEDIUMCVSS 6.7EG 6.72023-12-08
there is a possible permanent DoS or way for the modem to boot unverified firmware due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed f…
- CVE-2023-48418CRITICALCVSS 7.8EG 10.02024-01-02
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default value. This could lead to local escalation of privilege with no additional …
- CVE-2023-48419CRITICALCVSS 9.8EG 10.02024-01-02
An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege
- CVE-2023-48757HIGHCVSS 8.8EG 8.82024-05-17
Improper Privilege Management vulnerability in Crocoblock JetEngine allows Privilege Escalation.This issue affects JetEngine: from n/a through 3.2.4.
- CVE-2023-48902CRITICALCVSS 9.8EG 9.82024-03-21
An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car data, delete vehicles, and upload car images via authentication bypass in uploadCarImages.php.
- CVE-2023-49232CRITICALCVSS 9.8EG 9.82024-03-29
An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to brute-force the password reset PINs of administrative users.
- CVE-2023-4936MEDIUMCVSS 6.7EG 6.72023-10-11
It is possible to sideload a compromised DLL during the installation at elevated privilege.
- CVE-2023-4976CRITICALCVSS 9.3EG 9.32024-07-17
A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array.
- CVE-2023-50267MEDIUMCVSS 4.3EG 4.32023-12-28
MeterSphere is a one-stop open source continuous testing platform. Prior to 2.10.10-lts, the authenticated attackers can update resources which don't belong to him if the resource ID is known. This issue if fixed in 2.10.10-lts. There are…
- CVE-2023-50450HIGHCVSS 8.4EG 8.42025-06-23
An issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified actions with elevated privileges.
- CVE-2023-50677HIGHCVSS 8.8EG 8.82024-03-14
An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cgi component.
- CVE-2023-50700HIGHCVSS 7.8EG 7.82024-07-26
Insecure Permissions vulnerability in Deepin dde-file-manager 6.0.54 and earlier allows privileged operations to be called by unprivileged users via the D-Bus method.
- CVE-2023-50726MEDIUMCVSS 6.4EG 6.42024-03-13
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily override an Application's manifests with locally-defined manifests. Use of the feature shoul…
- CVE-2023-5080MEDIUMCVSS 6.8EG 6.82024-01-19
A privilege escalation vulnerability was reported in some Lenovo tablet products that could allow local applications access to device identifiers and system commands.
- CVE-2023-50890HIGHCVSS 8.8EG 8.82024-05-17
Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n/a through 1.36.20.
- CVE-2023-50921CRITICALCVSS 9.8EG 9.82024-01-03
An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4…
- CVE-2023-50957HIGHCVSS 8.0EG 8.02024-02-10
IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtaining encrypted data from clear text key storage. IBM X-Force ID: 275783.
- CVE-2023-51356HIGHCVSS 8.8EG 8.82024-05-17
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.
- CVE-2023-51386LOWCVSS 3.3EG 3.32023-12-22
Sandbox Accounts for Events provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially read data from the events table by sending request paylo…
- CVE-2023-51398HIGHCVSS 8.8EG 8.82024-05-17
Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Privilege Escalation.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.14.
- CVE-2023-51424CRITICALCVSS 9.8EG 9.82024-05-17
Improper Privilege Management vulnerability in Saleswonder Team WebinarIgnition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through 3.05.0.
- CVE-2023-51425CRITICALCVSS 9.8EG 9.82024-04-24
Improper Privilege Management vulnerability in Jacques Malgrange Rencontre – Dating Site allows Privilege Escalation.This issue affects Rencontre – Dating Site: from n/a through 3.10.1.
- CVE-2023-51429MEDIUMCVSS 5.5EG 6.02023-12-29
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
- CVE-2023-51430MEDIUMCVSS 5.5EG 5.52023-12-29
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
- CVE-2023-51433MEDIUMCVSS 5.5EG 5.52023-12-29
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
- CVE-2023-51435HIGHCVSS 7.1EG 7.12023-12-29
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
- CVE-2023-51476CRITICALCVSS 9.8EG 9.82024-05-17
Improper Privilege Management vulnerability in IOSS WP MLM Unilevel allows Privilege Escalation.This issue affects WP MLM Unilevel: from n/a through 4.0.
- CVE-2023-51479HIGHCVSS 8.8EG 8.82024-05-17
Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.
- CVE-2023-51481CRITICALCVSS 9.8EG 9.82024-05-17
Improper Privilege Management vulnerability in powerfulwp Local Delivery Drivers for WooCommerce allows Privilege Escalation.This issue affects Local Delivery Drivers for WooCommerce: from n/a through 1.9.0.
- CVE-2023-51483CRITICALCVSS 9.8EG 9.82024-05-17
Improper Privilege Management vulnerability in Glowlogix WP Frontend Profile allows Privilege Escalation.This issue affects WP Frontend Profile: from n/a through 1.3.1.
- CVE-2023-51546HIGHCVSS 7.2EG 7.22024-05-17
Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and…
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →