CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 75 of 99
- CVE-2024-4018HIGHCVSS 8.8EG 8.82024-04-19
Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api modules) allows Privilege Escalation.This issue affects U-Series Appliance: from 3.4 before 4.0.3.
- CVE-2024-40458HIGHCVSS 7.8EG 7.82025-05-22
An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modification of TCP packets.
- CVE-2024-40459HIGHCVSS 7.8EG 7.82025-05-22
An issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the application manager function
- CVE-2024-40460HIGHCVSS 7.8EG 7.82025-05-22
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXE
- CVE-2024-40461HIGHCVSS 7.8EG 7.82025-05-22
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE component
- CVE-2024-40462HIGHCVSS 7.8EG 7.82025-05-22
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE component
- CVE-2024-40657HIGHCVSS 7.8EG 7.82024-09-11
In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed…
- CVE-2024-40658HIGHCVSS 7.8EG 7.82024-09-11
In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n…
- CVE-2024-40662HIGHCVSS 7.8EG 7.82024-09-11
In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede…
- CVE-2024-40781HIGHCVSS 7.8EG 8.42024-07-29
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A local attacker may be able to elevate their privileges.
- CVE-2024-40802HIGHCVSS 7.8EG 7.82024-07-29
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A local attacker may be able to elevate their privileges.
- CVE-2024-40861HIGHCVSS 7.8EG 7.82024-09-17
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An app may be able to gain root privileges.
- CVE-2024-41199HIGHCVSS 7.2EG 7.22025-05-22
An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.
- CVE-2024-41228HIGHCVSS 7.6EG 7.62024-09-23
A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write arbitrary files.
- CVE-2024-41666MEDIUMCVSS 4.7EG 4.72024-07-24
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD has a Web-based terminal that allows users to get a shell inside a running pod, just as they would with kubectl exec. Starting in version 2.6.0, when the adm…
- CVE-2024-41797MEDIUMCVSS 4.3EG 4.32025-06-10
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.1), SCALANCE XC316-8 (6GK5324-8TS00-2AC2) (All versions < V3.1), SCALANCE XC324-4 (6GK5328-4TS00-2AC2) (All versions < V3.1), SCALANCE XC324-4 EEC…
- CVE-2024-41903MEDIUMCVSS 6.6EG 6.62024-08-13
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application mounts the container's root filesystem with read and write privileges. This could allow an attacker to alter…
- CVE-2024-41949LOWCVSS 3.0EG 3.02024-08-01
biscuit-rust is the Rust implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can be generated without transferring the whole token to the third-party authority. Instead, …
- CVE-2024-42036LOWCVSS 2.5EG 2.52024-08-08
Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-42050HIGHCVSS 7.0EG 7.02024-07-28
The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM via an oplock on CredProvider_Inst.reg.
- CVE-2024-42366CRITICALCVSS 9.0EG 9.02024-08-08
VRCX is an assistant/companion application for VRChat. In versions prior to 2024.03.23, a CefSharp browser with over-permission and cross-site scripting via overlay notification can be combined to result in remote command execution. These …
- CVE-2024-42440MEDIUMCVSS 6.2EG 6.22024-08-14
Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local ac…
- CVE-2024-42441MEDIUMCVSS 6.2EG 6.22024-08-14
Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local a…
- CVE-2024-4259CRITICALCVSS 9.8EG 9.82024-09-03
Missing Authorization vulnerability in SAMPAŞ Holding AKOS (AkosCepVatandasService), SAMPAŞ Holding AKOS (TahsilatService) allows Collect Data as Provided by Users. This issue affects AKOS (AkosCepVatandasService): before V2.0; AKOS (T…
- CVE-2024-42774HIGHCVSS 7.5EG 7.52024-08-22
An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room entries in the administrator section.
- CVE-2024-42798HIGHCVSS 7.6EG 7.62024-09-16
An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take over the administrator acco…
- CVE-2024-42995HIGHCVSS 8.3EG 8.32024-08-16
VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module to disable arbitrary modules.
- CVE-2024-43121CRITICALCVSS 9.1EG 9.12024-08-13
Improper Privilege Management vulnerability in realmag777 HUSKY allows Privilege Escalation.This issue affects HUSKY: from n/a through 1.3.6.1.
- CVE-2024-43199HIGHCVSS 7.8EG 8.82024-08-07
Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user.
- CVE-2024-43245CRITICALCVSS 9.8EG 9.82024-08-19
Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch: from n/a through 2.3.4.
- CVE-2024-43311CRITICALCVSS 9.8EG 9.82024-08-19
Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affects Login As Users: from n/a through 1.4.2.
- CVE-2024-43401CRITICALCVSS 9.0EG 9.02024-08-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIW…
- CVE-2024-43403HIGHCVSS 8.8EG 8.82024-08-20
Kanister is a data protection workflow management tool. The kanister has a deployment called default-kanister-operator, which is bound with a ClusterRole called edit via ClusterRoleBinding. The "edit" ClusterRole is one of Kubernetes defau…
- CVE-2024-4341HIGHCVSS 6.5EG 7.22024-07-08
Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in ExtremePacs Extreme XDS allows Collect Data as Provided by Users. This issue affects Extreme XDS: before 3928.
- CVE-2024-43446LOWCVSS 3.5EG 3.52025-01-27
An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTR…
- CVE-2024-4390MEDIUMCVSS 6.5EG 6.52024-06-20
The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with contributor access and above, …
- CVE-2024-4395HIGHCVSS 7.8EG 7.82024-06-27
The XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local privilege escalation.
- CVE-2024-44076CRITICALCVSS 9.8EG 9.82024-08-19
In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.
- CVE-2024-44097CRITICALCVSS 9.8EG 9.82024-10-02
According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network…
- CVE-2024-44147HIGHCVSS 5.5EG 7.72024-09-17
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An app may gain unauthorized access to Local Network.
- CVE-2024-44250HIGHCVSS 8.2EG 8.22026-04-02
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
- CVE-2024-4428CRITICALCVSS 9.8EG 9.82024-08-29
Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Managment Portal allows Collect Data as Provided by Users. This issue affects Managment Portal: through 21.05.2024.
- CVE-2024-44439MEDIUMCVSS 5.9EG 5.92024-10-04
An issue in Shanghai Zhouma Network Technology CO., Ltd IMS Intelligent Manufacturing Collaborative Internet of Things System v.1.9.1 allows a remote attacker to escalate privileges via the open port.
- CVE-2024-44540MEDIUMCVSS 6.6EG 6.62024-09-23
Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART Debugging Port.
- CVE-2024-44893CRITICALCVSS 9.8EG 9.82024-09-10
An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.
- CVE-2024-45041HIGHCVSS 8.3EG 8.32024-09-09
External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a same-name ClusterRole. This…
- CVE-2024-45058HIGHCVSS 8.1EG 8.12024-08-28
i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to the 2.9 branch, an attacker with only minimal viewing privileges in the settings section …
- CVE-2024-45173HIGHCVSS 8.8EG 8.82024-09-05
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MOR is vulnerable to a privilege escalation attack. The Linux user www-data running the C-MOR web in…
- CVE-2024-45297MEDIUMCVSS 5.3EG 5.32024-10-07
Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the label/name of that tag. This issue has been patched in the latest stable, beta and tests-passed version of Discourse. Al…
- CVE-2024-45373HIGHCVSS 8.8EG 8.82024-09-25
Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →