CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 74 of 99
- CVE-2024-34146MEDIUMCVSS 6.5EG 6.52024-05-02
Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing attackers with a previously configured SSH public key but lacking Overall/Read permission t…
- CVE-2024-34331CRITICALCVSS 9.8EG 9.82024-09-23
A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root.
- CVE-2024-34332HIGHCVSS 7.8EG 7.82024-06-10
An issue in SiSoftware SANDRA v31.66 (SANDRA.sys 15.18.1.1) and before allows an attacker to escalate privileges via a crafted buffer sent to the Kernel Driver using the DeviceIoControl Windows API.
- CVE-2024-34370HIGHCVSS 7.2EG 7.22024-05-17
Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.
- CVE-2024-34454HIGHCVSS 7.4EG 7.42024-05-26
Nintendo Wii U OS 5.5.5 allows man-in-the-middle attackers to forge SSL certificates as though they came from a Root CA, because there is a secondary verification mechanism that only checks whether a CA is known and ignores the CA details …
- CVE-2024-34457MEDIUMCVSS 6.5EG 6.52024-07-22
On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should …
- CVE-2024-3470MEDIUMCVSS 5.9EG 5.92024-04-19
An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use a deploy key pertaining to an organization to bypass an organization ruleset. An attacker would require access to a v…
- CVE-2024-34725HIGHCVSS 7.0EG 7.42024-07-09
In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User intera…
- CVE-2024-34741HIGHCVSS 7.8EG 7.82024-08-15
In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while lock screen visibility settings are restricted by the user due to a logic error in the co…
- CVE-2024-34743HIGHCVSS 7.8EG 7.82024-08-15
In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…
- CVE-2024-3507HIGHCVSS 7.7EG 7.72024-05-08
Improper privilege management vulnerability in Lunar software that affects versions 6.0.2 through 6.6.0. This vulnerability allows an attacker to perform a secondary process injection into the Lunar application and abuse those rights to ac…
- CVE-2024-35430HIGHCVSS 8.1EG 8.12024-05-30
In ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks while exporting data from the application.
- CVE-2024-36046CRITICALCVSS 9.8EG 9.82025-02-27
Infoblox NIOS through 8.6.4 executes with more privileges than required.
- CVE-2024-36056MEDIUMCVSS 5.4EG 5.42024-05-26
Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory via IOCTL 0x9c406490 (for IoAllocateMdl, MmBuildMdlForNonPagedPool, and MmMapLockedPages), leading to NT AUTHORITY\SYS…
- CVE-2024-36077HIGHCVSS 8.8EG 8.82024-05-22
Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation. The attacker can elevate their privilege to the internal system role, which allows them to execute commands o…
- CVE-2024-36439CRITICALCVSS 9.4EG 9.42024-08-22
Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash value, without knowing the actual device password.
- CVE-2024-36499MEDIUMCVSS 6.8EG 6.82024-06-14
Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-36500HIGHCVSS 7.8EG 7.82024-06-14
Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-36586HIGHCVSS 8.8EG 8.82024-06-13
An issue in AdGuardHome v0.93 to latest allows unprivileged attackers to escalate privileges via overwriting the AdGuardHome binary.
- CVE-2024-37107HIGHCVSS 8.8EG 8.82024-06-24
Improper Privilege Management vulnerability in Membership Software WishList Member X allows Privilege Escalation.This issue affects WishList Member X: from n/a before 3.26.7.
- CVE-2024-37126MEDIUMCVSS 6.7EG 6.72024-07-02
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain of root-level access.
- CVE-2024-37133MEDIUMCVSS 6.7EG 6.72024-07-02
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain of root-level access.
- CVE-2024-37364MEDIUMCVSS 6.8EG 6.82024-06-06
Ariane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attackers to obtain sensitive information (such as hotel invoice content with PII), and potentially create unauthorized room…
- CVE-2024-37455HIGHCVSS 8.8EG 8.82024-07-09
Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n/a through 1.36.31.
- CVE-2024-37484HIGHCVSS 8.8EG 8.82024-07-09
Improper Privilege Management vulnerability in Dylan James Zephyr Project Manager allows Privilege Escalation.This issue affects Zephyr Project Manager: from n/a through 3.3.97.
- CVE-2024-37560HIGHCVSS 8.0EG 8.02024-07-12
Improper Privilege Management vulnerability in IqbalRony WP User Switch allows Privilege Escalation.This issue affects WP User Switch: from n/a through 1.1.0.
- CVE-2024-37665HIGHCVSS 8.8EG 8.82024-06-12
An access control issue in Wvp GB28181 Pro 2.0 allows authenticated attackers to escalate privileges to Administrator via a crafted POST request.
- CVE-2024-37726MEDIUMCVSS 6.8EG 6.82024-07-03
Insecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to escalate privileges via the Export System Info function in MSI.CentralServer.exe
- CVE-2024-37858CRITICALCVSS 9.8EG 9.82024-07-29
SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php.
- CVE-2024-37952HIGHCVSS 8.8EG 8.82024-07-09
Improper Privilege Management vulnerability in themeenergy BookYourTravel allows Privilege Escalation.This issue affects BookYourTravel: from n/a through 8.18.17.
- CVE-2024-37980CRITICALCVSS 9.8EG 9.82024-09-10
Microsoft SQL Server Elevation of Privilege Vulnerability
- CVE-2024-38014CRITICALCVSS 7.8EG 9.0⚠ KEV2024-09-10
Windows Installer Elevation of Privilege Vulnerability
- CVE-2024-38089CRITICALCVSS 9.1EG 9.12024-07-09
Microsoft Defender for IoT Elevation of Privilege Vulnerability
- CVE-2024-3828HIGHCVSS 8.8EG 8.82024-05-14
The Spectra Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.5. This is due to the plugin allowing lower-privileged users to create registration forms and set the default role to admi…
- CVE-2024-38487HIGHCVSS 7.0EG 7.02026-06-16
api-gateway container running with root privilege would allow an attacker to escape the container and access host system to perform unintended actions.
- CVE-2024-38499HIGHCVSS 8.8EG 8.82024-12-17
CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored crede…
- CVE-2024-38770CRITICALCVSS 9.8EG 9.82024-08-01
Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Privilege Escalation, Authentication Bypass.This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.20.
- CVE-2024-38775HIGHCVSS 7.2EG 7.22024-08-01
Improper Privilege Management vulnerability in WebAppick CTX Feed allows Privilege Escalation.This issue affects CTX Feed: from n/a through 6.5.6.
- CVE-2024-38818MEDIUMCVSS 6.7EG 6.72024-10-09
VMware NSX contains a local privilege escalation vulnerability. An authenticated malicious actor may exploit this vulnerability to obtain permissions from a separate group role than previously assigned.
- CVE-2024-38830HIGHCVSS 7.8EG 7.82024-11-26
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance running VMware Aria Ope…
- CVE-2024-39206HIGHCVSS 7.5EG 7.52024-07-02
An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials used in a backup due to enginesettings.list being encrypted with a hard coded key.
- CVE-2024-39302LOWCVSS 3.7EG 3.72024-06-28
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file permissions in the `/usr/local/bigbluebutton/core/vendor/bundle/ruby/2.7.0/ge…
- CVE-2024-39342MEDIUMCVSS 6.6EG 6.62024-09-23
Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Security.dll) with a custom AES encryption process that relies on static hard-coded key value…
- CVE-2024-39574MEDIUMCVSS 6.7EG 6.72024-09-10
Dell PowerScale InsightIQ, version 5.1, contain an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.
- CVE-2024-39633HIGHCVSS 8.8EG 8.82024-08-01
Improper Privilege Management vulnerability in IdeaBox PowerPack for Beaver Builder allows Privilege Escalation.This issue affects PowerPack for Beaver Builder: from n/a through 2.33.0.
- CVE-2024-39634HIGHCVSS 8.8EG 8.82024-08-01
Improper Privilege Management vulnerability in IdeaBox PowerPack Pro for Elementor allows Privilege Escalation.This issue affects PowerPack Pro for Elementor: from n/a through 2.10.14.
- CVE-2024-39819MEDIUMCVSS 6.7EG 6.72024-07-15
Integrity check in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct a privilege escalation via local access.
- CVE-2024-39924HIGHCVSS 8.8EG 8.82024-09-13
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. It per…
- CVE-2024-39925HIGHCVSS 6.5EG 7.52024-09-13
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a result, the shared organization key is not rotated when a member departs. Consequently, the …
- CVE-2024-4017HIGHCVSS 8.8EG 8.82024-04-19
Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (filesystem modules) allows DLL Side-Loading.This issue affects U-Series Appliance: from 3.4 before 4.0.3.
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →