CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 71 of 99
- CVE-2024-21324HIGHCVSS 7.2EG 7.22024-04-09
Microsoft Defender for IoT Elevation of Privilege Vulnerability
- CVE-2024-21622HIGHCVSS 8.8EG 8.82024-01-03
Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. This has bee…
- CVE-2024-21638CRITICALCVSS 9.1EG 9.12024-01-10
Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP Address space easily and effectively. By design there is no write access to customers' Azu…
- CVE-2024-21807HIGHCVSS 8.8EG 8.82024-08-14
Improper initialization in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-21813HIGHCVSS 7.9EG 7.92024-05-16
Exposure of resource to wrong sphere in some Intel(R) DTT software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-21888CRITICALCVSS 8.8EG 9.02024-01-31
A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.
- CVE-2024-21892HIGHCVSS 7.8EG 7.82024-02-20
On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated privileges with the only exception of CAP_NET_BIND_SERVICE. Due to a bug in the implement…
- CVE-2024-21966HIGHCVSS 7.3EG 7.32025-02-11
A DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
- CVE-2024-21985HIGHCVSS 7.6EG 7.62024-01-26
ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authenticated user with multiple remote accounts with differing roles to perform actions via REST A…
- CVE-2024-21989HIGHCVSS 8.1EG 8.12024-04-17
ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x are susceptible to a vulnerability which when successfully exploited could allow a read-only user to escalate their privileges.
- CVE-2024-22008HIGHCVSS 7.8EG 7.82024-03-11
In config_gov_time_windows of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- CVE-2024-22036CRITICALCVSS 9.1EG 9.12025-04-16
A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot jail and gain root access to the Rancher container itself. In production environments, further privilege escalation is pos…
- CVE-2024-22068MEDIUMCVSS 6.0EG 6.02024-10-10
Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series: …
- CVE-2024-22069HIGHCVSS 7.1EG 7.12024-08-08
There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to chan…
- CVE-2024-22106HIGHCVSS 7.8EG 8.82024-07-02
Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Denial of Service (DoS).
- CVE-2024-22145HIGHCVSS 8.8EG 8.82024-05-17
Incorrect Privilege Assignment vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.
- CVE-2024-22157CRITICALCVSS 9.8EG 9.82024-05-17
Improper Privilege Management vulnerability in WebWizards SalesKing allows Privilege Escalation.This issue affects SalesKing: from n/a through 1.6.15.
- CVE-2024-22235MEDIUMCVSS 6.7EG 6.72024-02-21
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
- CVE-2024-22237HIGHCVSS 7.8EG 7.82024-02-06
Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain root access to the system.
- CVE-2024-22239MEDIUMCVSS 5.3EG 5.32024-02-06
Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain regular shell access.
- CVE-2024-22264HIGHCVSS 7.2EG 7.22024-05-08
VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious actor with admin privileges on VMware Avi Load Balancer can create, modify, execute and delete files as a root user on the host system.
- CVE-2024-22278MEDIUMCVSS 6.4EG 6.42024-08-02
Incorrect user permission validation in Harbor <v2.9.5 and Harbor <v2.10.3 allows authenticated users to modify configurations.
- CVE-2024-2228HIGHCVSS 7.1EG 7.12024-03-22
This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.
- CVE-2024-22341MEDIUMCVSS 5.3EG 5.32025-02-22
IBM Watson Query on Cloud Pak for Data 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4.6.6, 4.7.0 through 4.7.4, and 4.8.0 through 4.8.7 could allow unauthorized data access from a remote data source object due to improper privil…
- CVE-2024-22752HIGHCVSS 8.1EG 8.12024-03-07
Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use of crafted executable launched from the application installation directory.
- CVE-2024-22774HIGHCVSS 7.8EG 7.82024-05-14
An issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges via the ccsservice.exe component.
- CVE-2024-22795HIGHCVSS 7.0EG 7.02024-02-08
Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Compliance Status component.
- CVE-2024-22893HIGHCVSS 7.5EG 7.52024-09-25
OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password hash using a timing attack.
- CVE-2024-22922CRITICALCVSS 9.8EG 9.82024-01-25
An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php
- CVE-2024-2297HIGHCVSS 7.1EG 7.12025-02-27
The Bricks theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.6.1. This is due to insufficient validation checks placed on the create_autosave AJAX function. This makes it possible for authe…
- CVE-2024-23253HIGHCVSS 3.3EG 7.52024-03-08
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to access a user's Photos Library.
- CVE-2024-23276HIGHCVSS 7.8EG 7.82024-03-08
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.
- CVE-2024-23457HIGHCVSS 7.8EG 7.82024-05-01
The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninstall password is enforced. This affects Zscaler Client Connector on Windows prior to 4.2.0.209
- CVE-2024-23537HIGHCVSS 8.4EG 8.42024-03-29
Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.9.0, which fixes the issue.
- CVE-2024-23620HIGHCVSS 8.8EG 8.82024-01-26
An improper privilege management vulnerability exists in IBM Merge Healthcare eFilm Workstation. A local, authenticated attacker can exploit this vulnerability to escalate privileges to SYSTEM.
- CVE-2024-23710HIGHCVSS 7.8EG 8.42024-05-07
In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary app code as a privileged app due to a logic error in the code. This could lead to local escalation of privilege with no a…
- CVE-2024-23711HIGHCVSS 7.8EG 7.82024-07-09
In DevmemXIntUnreserveRange of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed…
- CVE-2024-23713HIGHCVSS 7.8EG 7.82024-05-07
In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution …
- CVE-2024-23764MEDIUMCVSS 6.7EG 6.72024-02-08
Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Server Security 15 and later, WithSecure Email and Server Security 15 and later, and WithSecure Elements Endpoin…
- CVE-2024-2390HIGHCVSS 7.8EG 7.82024-03-18
As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in …
- CVE-2024-2431MEDIUMCVSS 5.5EG 5.52024-03-13
An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode.
- CVE-2024-2432MEDIUMCVSS 4.5EG 4.52024-03-13
A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successf…
- CVE-2024-2433MEDIUMCVSS 4.3EG 4.32024-03-13
An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded fil…
- CVE-2024-24402CRITICALCVSS 9.8EG 9.82024-02-26
An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.
- CVE-2024-24409HIGHCVSS 8.8EG 8.82024-11-08
Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.
- CVE-2024-24694MEDIUMCVSS 5.9EG 5.92024-04-09
Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2024-24747HIGHCVSS 8.8EG 8.82024-01-31
MinIO is a High Performance Object Storage. When someone creates an access key, it inherits the permissions of the parent key. Not only for `s3:*` actions, but also `admin:*` actions. Which means unless somewhere above in the access-key hi…
- CVE-2024-24778MEDIUMCVSS 6.5EG 6.52025-03-03
Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: through 0.95.1. Users are recommended to upgrade to vers…
- CVE-2024-24830CRITICALCVSS 9.9EG 9.92024-02-08
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any a…
- CVE-2024-24892HIGHCVSS 8.1EG 8.12024-03-25
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Management vulnerability in openEuler migration-tools on Linux allows Command Injection, Restful Privilege Elevation. This vulne…
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →