CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 72 of 99
- CVE-2024-24970MEDIUMCVSS 6.5EG 6.52024-07-19
Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software Driver which might allow escalation of privilege.
- CVE-2024-25086HIGHCVSS 7.8EG 7.82024-07-02
Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.
- CVE-2024-25088HIGHCVSS 7.8EG 7.82024-07-02
Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.
- CVE-2024-25106CRITICALCVSS 9.1EG 9.12024-02-08
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulner…
- CVE-2024-25343CRITICALCVSS 9.1EG 9.12024-04-26
Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords.
- CVE-2024-25842HIGHCVSS 7.5EG 7.52024-03-03
An issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module for PrestaShop before version 9.0, allows remote attackers to escalate privilege and obtain sensitive information …
- CVE-2024-25847CRITICALCVSS 9.8EG 9.82024-03-03
SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send:…
- CVE-2024-25961MEDIUMCVSS 6.0EG 6.02024-03-28
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.
- CVE-2024-25987MEDIUMCVSS 6.7EG 6.72024-03-11
In pt_sysctl_command of pt.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati…
- CVE-2024-25990MEDIUMCVSS 6.4EG 6.42024-03-11
In pktproc_perftest_gen_rx_packet_sktbuf_mode of link_rx_pktproc.c, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction…
- CVE-2024-26169CRITICALCVSS 7.8EG 9.0⚠ KEV2024-03-12
Windows Error Reporting Service Elevation of Privilege Vulnerability
- CVE-2024-26247MEDIUMCVSS 4.7EG 4.72024-03-22
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- CVE-2024-26314HIGHCVSS 7.8EG 7.82024-07-02
Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code.
- CVE-2024-27181HIGHCVSS 8.8EG 8.82024-08-02
In Apache Linkis <= 1.5.0, Privilege Escalation in Basic management services where the attacking user is a trusted account allows access to Linkis's Token information. Users are advised to upgrade to version 1.6.0, which fixes this is…
- CVE-2024-27207CRITICALCVSS 9.1EG 9.12024-03-11
Exported broadcast receivers allowing malicious apps to bypass broadcast protection.
- CVE-2024-27210HIGHCVSS 7.8EG 7.82024-03-11
In policy_check of fvp.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitati…
- CVE-2024-27222HIGHCVSS 7.8EG 7.82024-03-11
In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GRANT_URI_PERMISSIONS Attack. This could lead to local escalation of privilege with no additional exe…
- CVE-2024-27224HIGHCVSS 7.8EG 7.82024-03-11
In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2024-27233HIGHCVSS 7.8EG 7.82024-03-11
In ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi…
- CVE-2024-27247MEDIUMCVSS 5.5EG 5.52024-04-09
Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.
- CVE-2024-27264HIGHCVSS 7.4EG 7.42024-05-22
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-For…
- CVE-2024-27301HIGHCVSS 7.3EG 7.32024-03-14
Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability inside the postinstall installer script to make the installer execute arbitrary code as root. The cause of the vulnerabi…
- CVE-2024-27357MEDIUMCVSS 5.8EG 5.82024-07-26
An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, and WithSecure MDR through 23.x for macOS. Local Privilege Escalation can occur during installations o…
- CVE-2024-27442HIGHCVSS 7.8EG 7.82024-08-12
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the zimbra user with root privileges for specific mailbox operations. However, an attacker can …
- CVE-2024-27518HIGHCVSS 7.8EG 7.82024-04-29
An issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges via a restore of a crafted DLL file into the C:\Program Files\SUPERAntiSpyware folder.
- CVE-2024-27710CRITICALCVSS 9.8EG 9.82024-07-05
An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the authentication mechanism.
- CVE-2024-27711HIGHCVSS 8.8EG 8.82024-07-05
An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the Sin-up process function in the account settings.
- CVE-2024-27811HIGHCVSS 7.8EG 7.82024-06-10
The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to elevate privileges.
- CVE-2024-27826HIGHCVSS 7.8EG 7.82024-07-29
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.6, macOS Sonoma 14.5, macOS Ventura 13.6.8, tvOS 17.5, visionOS 1.3, watchOS 10.5. A local attacker may be able to …
- CVE-2024-28197HIGHCVSS 7.5EG 7.52024-03-11
Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent (browser) and its user sessions. Although the cookie was handled according to best practices, it was accessible on subdomains of the ZI…
- CVE-2024-28241HIGHCVSS 7.3EG 7.32024-04-25
The GLPI Agent is a generic management agent. Prior to version 1.7.2, a local user can modify GLPI-Agent code or used DLLs to modify agent logic and even gain higher privileges. Users should upgrade to GLPI-Agent 1.7.2 to receive a patch. …
- CVE-2024-28247HIGHCVSS 7.6EG 7.62024-03-27
The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side software. A vulnerability has been discovered in Pihole that allows an authenticated user on the platform to read internal se…
- CVE-2024-28391CRITICALCVSS 9.8EG 9.82024-03-14
SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProdu…
- CVE-2024-2859MEDIUMCVSS 6.8EG 6.82024-04-27
By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could expose SANnav to a remote attacker should they gain access to the root account.
- CVE-2024-28813HIGHCVSS 8.4EG 8.42024-09-30
An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activate remote SSH access to the appliance via an unexpected network interface.
- CVE-2024-28851MEDIUMCVSS 4.0EG 4.02024-03-15
The Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive MetaStore Connector has addressed a potential elevation of privilege vulnerability in a `helper script` for the Hive MetaS…
- CVE-2024-28904HIGHCVSS 7.8EG 7.82024-04-09
Microsoft Brokering File System Elevation of Privilege Vulnerability
- CVE-2024-28905HIGHCVSS 7.8EG 7.82024-04-09
Microsoft Brokering File System Elevation of Privilege Vulnerability
- CVE-2024-29052HIGHCVSS 7.8EG 7.82024-04-09
Windows Storage Elevation of Privilege Vulnerability
- CVE-2024-29150HIGHCVSS 8.8EG 8.82024-05-07
An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of improper privilege management, an authenticated attacker is able to create sym…
- CVE-2024-29210LOWCVSS 2.8EG 2.82024-05-07
A local privilege escalation (LPE) vulnerability has been identified in Phish Alert Button for Outlook (PAB), specifically within its configuration management functionalities. This vulnerability allows a regular user to modify the applicat…
- CVE-2024-29667CRITICALCVSS 9.8EG 9.82024-03-29
SQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote attacker to escalate privileges and obtain sensitive information via the ids parameter.
- CVE-2024-29741HIGHCVSS 7.8EG 7.82024-04-05
In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo…
- CVE-2024-29779HIGHCVSS 7.8EG 7.82024-09-13
there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2024-29784HIGHCVSS 7.8EG 7.82024-06-13
In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed …
- CVE-2024-29975MEDIUMCVSS 6.7EG 6.72024-06-04
** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an aut…
- CVE-2024-29976MEDIUMCVSS 6.5EG 6.52024-06-04
** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could al…
- CVE-2024-30007HIGHCVSS 8.8EG 8.82024-05-14
Microsoft Brokering File System Elevation of Privilege Vulnerability
- CVE-2024-30150MEDIUMCVSS 5.3EG 5.32025-02-25
HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure and potential for Server-Side Request Forgery (SSRF) and Denial of Service(DOS) attacks fro…
- CVE-2024-30473MEDIUMCVSS 4.9EG 4.92024-07-18
Dell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privileged attacker could potentially exploit this vulnerability, gaining access to unauthorized end points.
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →