CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 69 of 99
- CVE-2023-51776HIGHCVSS 7.8EG 7.82024-07-02
Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.
- CVE-2023-52093HIGHCVSS 7.8EG 7.82024-01-23
An exposed dangerous function vulnerability in the Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2023-52105HIGHCVSS 7.5EG 7.52024-01-16
The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.
- CVE-2023-52107HIGHCVSS 7.5EG 7.52024-01-16
Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-52114HIGHCVSS 7.5EG 7.52024-01-16
Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.
- CVE-2023-52116HIGHCVSS 7.5EG 7.52024-01-16
Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.
- CVE-2023-5214CRITICALCVSS 9.8EG 9.82023-10-06
In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.
- CVE-2023-52209HIGHCVSS 8.0EG 8.02024-08-01
Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows Privilege Escalation.This issue affects WPForms User Registration: from n/a through 2.1.0.
- CVE-2023-52337HIGHCVSS 7.8EG 7.82024-01-23
An improper access control vulnerability in Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a local attacker to escalate privileges on affected installations. Please note: an a…
- CVE-2023-52431HIGHCVSS 8.8EG 8.82024-02-13
The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form value and an empty cookie (if signed cookies are disabled).
- CVE-2023-52543MEDIUMCVSS 6.2EG 6.22024-04-08
Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2023-52716HIGHCVSS 7.5EG 7.52024-04-07
Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2023-53908HIGHCVSS 8.8EG 8.82025-12-17
HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a sp…
- CVE-2023-5402CRITICALCVSS 9.8EG 9.82023-10-04
A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the transfer command is used over the network.
- CVE-2023-5408HIGHCVSS 7.2EG 8.22023-11-02
A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modifies the node role label could steer workloads from the control plane and etcd nodes onto d…
- CVE-2023-5549MEDIUMCVSS 5.3EG 5.32023-11-09
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
- CVE-2023-5622HIGHCVSS 8.8EG 8.82023-10-26
Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by replacing a specially crafted file.
- CVE-2023-5650MEDIUMCVSS 5.5EG 5.52023-11-28
An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W…
- CVE-2023-5671HIGHCVSS 7.8EG 7.82023-10-25
HP Print and Scan Doctor for Windows may potentially be vulnerable to escalation of privilege. HP is releasing software updates to mitigate the potential vulnerability.
- CVE-2023-5739HIGHCVSS 7.8EG 7.82023-10-31
Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege.
- CVE-2023-5797MEDIUMCVSS 5.5EG 5.52023-11-28
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through …
- CVE-2023-5847HIGHCVSS 7.3EG 7.32023-11-01
Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privileges on Windows and Linux hosts.
- CVE-2023-5960MEDIUMCVSS 5.5EG 5.52023-11-28
An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VPN series firmware versions 4.30 through 5.37 could allow an authenticated local attacker to access…
- CVE-2023-5978HIGHCVSS 7.5EG 7.52023-11-08
In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service incorrectly validates that updated constraints are strictly subsets of the active constraints. When only a list of reso…
- CVE-2023-5993HIGHCVSS 7.8EG 7.82024-02-27
A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level via local access.
- CVE-2023-6006MEDIUMCVSS 6.7EG 6.72023-11-14
This vulnerability potentially allows local attackers to escalate privileges on affected installations of PaperCut NG. An attacker must have local write access to the C Drive. In addition, Print Archiving must be enabled or the attacker ne…
- CVE-2023-6099CRITICALCVSS 9.8EG 9.82023-11-13
A vulnerability classified as critical has been found in Shenzhen Youkate Industrial Facial Love Cloud Payment System up to 1.0.55.0.0.1. This affects an unknown part of the file /SystemMng.ashx of the component Account Handler. The manipu…
- CVE-2023-6119HIGHCVSS 7.8EG 7.82023-11-16
An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain access to files that usually require a higher privilege level. This is caused by GetSusp not corre…
- CVE-2023-6218HIGHCVSS 7.2EG 7.22023-11-29
In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privilege escalation path associated with group administrators has been identified. It is possible for a group administrat…
- CVE-2023-6477MEDIUMCVSS 6.7EG 6.72024-02-22
An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with adm…
- CVE-2023-6507MEDIUMCVSS 4.9EG 6.12023-12-08
An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. When using the `extra_groups=` parameter with an empty list as a value (ie `extr…
- CVE-2023-6735HIGHCVSS 8.8EG 8.82024-01-12
Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
- CVE-2023-6740HIGHCVSS 8.8EG 8.82024-01-12
Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
- CVE-2023-6793LOWCVSS 2.7EG 2.72023-12-13
An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage.
- CVE-2023-6804MEDIUMCVSS 5.5EG 6.52023-12-21
Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must have already existed in the target repo. This vulnerability affected all versions of GitHub …
- CVE-2023-6998HIGHCVSS 7.7EG 7.72023-12-30
Improper privilege management vulnerability in CoolKit Technology eWeLink on Android and iOS allows application lockscreen bypass.This issue affects eWeLink before 5.2.0.
- CVE-2023-7016HIGHCVSS 7.8EG 7.82024-02-27
A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access.
- CVE-2023-7080HIGHCVSS 8.0EG 8.02023-12-29
The V8 inspector intentionally allows arbitrary code execution within the Workers sandbox for debugging. wrangler dev would previously start an inspector server listening on all network interfaces. This would allow an attacker on the local…
- CVE-2023-7090HIGHCVSS 8.8EG 8.82023-12-23
A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts retain privi…
- CVE-2023-7241HIGHCVSS 7.9EG 7.92024-05-01
Privilege Escalation in WRSA.EXE in Webroot Antivirus 8.0.1X- 9.0.35.12 on Windows64 bit and 32 bit allows malicious software to abuse WRSA.EXE to delete arbitrary and protected files.
- CVE-2023-7342HIGHCVSS 8.8EG 8.82026-04-02
HiSecOS web server versions 03.4.00 prior to 04.1.00 contains a privilege escalation vulnerability that allows authenticated users with operator or auditor roles to escalate privileges to the administrator role by sending specially crafted…
- CVE-2023-7343HIGHCVSS 7.8EG 7.82026-04-02
Hirschmann Industrial HiVision versions 05.0.00 through 08.3.01 prior to 08.3.02 contain an arbitrary code execution vulnerability triggered when an administrator opens a maliciously crafted project file. Successful exploitation allows the…
- CVE-2024-0003CRITICALCVSS 9.1EG 9.12024-09-23
A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access.
- CVE-2024-0024HIGHCVSS 7.8EG 7.82024-05-07
In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges …
- CVE-2024-0046HIGHCVSS 7.8EG 7.82024-03-11
In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed.…
- CVE-2024-0049HIGHCVSS 7.8EG 7.82024-03-11
In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2024-0082HIGHCVSS 8.2EG 8.22024-04-08
NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause improper privilege management by sending open file requests to the application. A successful exploit of this vulnerability might lead to local escal…
- CVE-2024-0096HIGHCVSS 7.5EG 7.52024-05-14
NVIDIA ChatRTX for Windows contains a vulnerability in Chat RTX UI, where a user can cause an improper privilege management issue by sending user inputs to change execution flow. A successful exploit of this vulnerability might lead to inf…
- CVE-2024-0097HIGHCVSS 7.5EG 7.52024-05-14
NVIDIA ChatRTX for Windows contains a vulnerability in ChatRTX UI, where a user can cause an improper privilege management issue by exploiting interprocess communication between different processes. A successful exploit of this vulnerabili…
- CVE-2024-0172HIGHCVSS 7.9EG 7.92024-04-03
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →