CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 70 of 99
- CVE-2024-0197HIGHCVSS 7.8EG 7.82024-02-27
A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via local access.
- CVE-2024-0219HIGHCVSS 7.8EG 7.82024-01-31
In Telerik JustDecompile versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik JustDecompile install is present, a lower pr…
- CVE-2024-0353HIGHCVSS 7.8EG 7.82024-02-15
Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.
- CVE-2024-0439HIGHCVSS 8.8EG 8.82024-02-26
As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most managers would not be savvy enough to modify these settings. They can use their token to still mo…
- CVE-2024-0622HIGHCVSS 8.8EG 8.82024-02-15
Local privilege escalation vulnerability affects OpenText Operations Agent product versions 12.15 and 12.20-12.25 when installed on Non-Windows platforms. The vulnerability could allow local privilege escalation.
- CVE-2024-0674MEDIUMCVSS 6.3EG 6.32024-01-30
Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local user to acquire root permissions by modifying the updatescript.js, inserting special code inside the script and creatin…
- CVE-2024-0751HIGHCVSS 8.8EG 8.82024-01-23
A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
- CVE-2024-0819HIGHCVSS 7.3EG 7.32024-02-27
Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and macOS, allow a low privileged user to elevate privileges by changing the personal password setting and establishing a rem…
- CVE-2024-0832HIGHCVSS 7.8EG 7.82024-01-31
In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Reporting install is present, a lower privileged…
- CVE-2024-0833HIGHCVSS 7.8EG 7.82024-01-31
In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Test Studio install is present, a lower…
- CVE-2024-10203HIGHCVSS 7.0EG 7.02024-11-07
Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines.
- CVE-2024-10273MEDIUMCVSS 6.5EG 6.52025-03-20
In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify models owned by others. The PATCH endpoint for models does not have appropriate privilege checks, enabling low-privile…
- CVE-2024-11128HIGHCVSS 7.8EG 7.82025-01-13
A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic library injection (DYLD injection) without being blocked by AppleMobileFileIntegrity (AMFI). This issue is caused by …
- CVE-2024-11218HIGHCVSS 8.6EG 8.62025-01-22
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it st…
- CVE-2024-1138HIGHCVSS 8.8EG 8.82024-03-12
The FTL Server component of TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlserver. Affected relea…
- CVE-2024-11467HIGHCVSS 7.8EG 7.82025-02-04
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the sys…
- CVE-2024-11721HIGHCVSS 8.1EG 8.12024-12-14
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.24.5. This is due to insufficient controls on the user role select field when utilizing the 'Role' field in…
- CVE-2024-11951CRITICALCVSS 9.8EG 9.82025-03-05
The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.0. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it…
- CVE-2024-12281CRITICALCVSS 9.8EG 9.82025-03-05
The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for un…
- CVE-2024-12284HIGHCVSS 8.8EG 8.82025-02-20
Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.
- CVE-2024-12398HIGHCVSS 8.8EG 8.82025-01-14
An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2) could allow an authenticated user with limited pr…
- CVE-2024-1250MEDIUMCVSS 6.5EG 6.52024-02-12
An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner …
- CVE-2024-12786HIGHCVSS 7.8EG 7.82024-12-19
A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected is the function shouldAcceptNewConnection of the file com.x1a0he.macOS.Adobe-Downloader.helper of the component XPC Serv…
- CVE-2024-13058MEDIUMCVSS 4.8EG 4.82024-12-30
An issue exists in SoftIron HyperCloud where authenticated, but non-admin users can create data pools, which could potentially impact the performance and availability of the backend software-defined storage subsystem. This issue only imp…
- CVE-2024-13343HIGHCVSS 8.8EG 8.82025-02-01
The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_assign_new_roles() function in all versions up to, and including, 31.3. This makes it possible for a…
- CVE-2024-13376HIGHCVSS 8.8EG 8.82025-03-14
The Industrial theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the _ajax_get_total_content_import_items() function in all versions up to, and…
- CVE-2024-13835HIGHCVSS 7.2EG 7.22025-03-08
The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, and including, 1.4.4. This is due to the plugin not properly verifying the existence of a multisite installation prior t…
- CVE-2024-13975HIGHCVSS 8.5EG 8.52025-07-25
A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected configurations, a local attacker who owns a client system with the file server agent installed…
- CVE-2024-13997HIGHCVSS 7.2EG 7.22025-11-03
Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the mi…
- CVE-2024-14004HIGHCVSS 8.8EG 8.82025-10-30
Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenticated user could manipulate NagVis configuration data or leverage insufficiently validate…
- CVE-2024-14009HIGHCVSS 7.2EG 7.22025-10-30
Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The System Profile feature is an administrative diagnostic/configuration capability. Due to improper access controls and…
- CVE-2024-1442MEDIUMCVSS 6.0EG 6.02024-03-07
A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.
- CVE-2024-1505HIGHCVSS 8.8EG 8.82024-03-13
The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.9.19. This is due to plugin allowing arbitrary user meta updates thro…
- CVE-2024-1575MEDIUMCVSS 6.5EG 6.52024-07-23
The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an authenticated user to escalate privileges and download the configuration files on a vulnerable device.
- CVE-2024-1764HIGHCVSS 7.6EG 7.62024-03-05
Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after the expiration under specific circumstances
- CVE-2024-1908MEDIUMCVSS 6.3EG 6.32024-03-21
An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use the Enterprise Actions GitHub Connect download token to fetch private repository data. An attacker would require an …
- CVE-2024-1973HIGHCVSS 8.5EG 8.52024-03-25
By leveraging the vulnerability, lower-privileged users of Content Manager can manipulate Content Manager clients to elevate privileges and perform unauthorized operations.
- CVE-2024-20021MEDIUMCVSS 6.7EG 6.72024-05-06
In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.…
- CVE-2024-2003HIGHCVSS 7.3EG 7.32024-06-21
Local privilege escalation vulnerability allowed an attacker to misuse ESET's file operations during a restore operation from quarantine.
- CVE-2024-2005CRITICALCVSS 9.0EG 9.02024-03-06
In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected. Blue Planet® has released software updates that address this …
- CVE-2024-20262MEDIUMCVSS 6.5EG 6.52024-03-13
A vulnerability in the Secure Copy Protocol (SCP) and SFTP feature of Cisco IOS XR Software could allow an authenticated, local attacker to create or overwrite files in a system directory, which could lead to a denial of service (DoS) cond…
- CVE-2024-20282MEDIUMCVSS 6.0EG 6.02024-04-03
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to root on an affected device. This vulnerability is due to insufficient protections for a se…
- CVE-2024-20374MEDIUMCVSS 6.5EG 6.52024-10-23
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker with Administrator-level privileg…
- CVE-2024-21034MEDIUMCVSS 6.1EG 6.12024-04-16
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated at…
- CVE-2024-21059HIGHCVSS 7.8EG 7.82024-04-16
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Or…
- CVE-2024-21101LOWCVSS 2.2EG 2.22024-04-16
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.5.33 and prior, 7.6.29 and prior, 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerabili…
- CVE-2024-21111HIGHCVSS 7.8EG 7.82024-04-16
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infr…
- CVE-2024-21118MEDIUMCVSS 5.3EG 5.32024-04-16
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions that are affected are 8.5.6 and 8.5.7. Easily exploitable vulnerability allows low privileged attacker…
- CVE-2024-21121MEDIUMCVSS 6.5EG 6.52024-04-16
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infr…
- CVE-2024-21141HIGHCVSS 8.2EG 8.22024-07-16
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.20. Easily exploitable vulnerability allows high privileged attacker with logon to the inf…
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →