CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 76 of 99
- CVE-2024-4545HIGHCVSS 7.7EG 7.72024-05-14
All versions of EnterpriseDB Postgres Advanced Server (EPAS) from 15.0 prior to 15.7.0 and from 16.0 prior to 16.3.0 may allow users using edbldr to bypass role permissions from pg_read_server_files. This could allow low privilege users t…
- CVE-2024-45461MEDIUMCVSS 5.7EG 5.72024-10-16
The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. In environments where the feature is enabled, due to missing access check enforcements, no…
- CVE-2024-45496CRITICALCVSS 9.9EG 9.92024-09-17
A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged security …
- CVE-2024-4555HIGHCVSS 7.7EG 7.72024-08-28
Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affects NetIQ Access Manager before 5.0.4.1 and before 5.1
- CVE-2024-45752HIGHCVSS 8.5EG 8.52024-09-19
logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an unrestricted D-Bus service, including setting malicious keyboard macros. This allows for privilege escalation with minim…
- CVE-2024-45919MEDIUMCVSS 6.5EG 6.52024-10-07
A security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the Request ID and Action Type parameters in /AssignToMe/SetAction, an attacker can bypass approval workflow…
- CVE-2024-46549HIGHCVSS 7.6EG 7.62024-09-30
An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connections by impersonating devices owned by other users.
- CVE-2024-46916HIGHCVSS 8.1EG 8.12025-08-29
Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesystem is properly mounted (e.g., leveraging a delete call in /etc/rc.d/init.d/mountfs to remo…
- CVE-2024-46989LOWCVSS 3.7EG 3.72024-09-18
spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Multiple caveats over the same indirect subject type on the same relation can result in no permission …
- CVE-2024-46999HIGHCVSS 7.3EG 7.32024-09-20
Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correctly. Deactivated user grants were still provided in token, which could lead to unauthorized access to applications and …
- CVE-2024-47000HIGHCVSS 8.1EG 8.12024-09-20
Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work correctly with service accounts. Deactivated service accounts retained the ability to request tokens, which could lead to un…
- CVE-2024-47770MEDIUMCVSS 4.6EG 4.62025-02-03
Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based environments. This vulnerability occurs whe…
- CVE-2024-47853HIGHCVSS 8.8EG 8.82025-08-26
An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into Mahara with Learning Tools Interoperability (LTI).
- CVE-2024-48729HIGHCVSS 7.1EG 7.12025-07-25
An issue in ETSI Open-Source MANO (OSM) 14.0.x before 14.0.3, 15.0.x before 15.0.2, 16.0.0, and 17.0.0 allows a remote authenticated attacker to escalate privileges via the /osm/admin/v1/users component.
- CVE-2024-48730MEDIUMCVSS 6.5EG 6.52025-07-25
The default configuration in ETSI Open-Source MANO (OSM) v.14.x, v.15.x, v.16.x, v.17.x does not impose any restrictions on the authentication attempts performed by the default admin user, allowing a remote attacker to escalate privileges.
- CVE-2024-48828MEDIUMCVSS 5.5EG 5.52025-03-17
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading…
- CVE-2024-48903HIGHCVSS 7.8EG 7.82024-10-22
An improper access control vulnerability in Trend Micro Deep Security Agent 20 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileg…
- CVE-2024-49035CRITICALCVSS 8.7EG 9.0⚠ KEV2024-11-26
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.
- CVE-2024-49558HIGHCVSS 7.8EG 7.82024-11-12
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading…
- CVE-2024-49742HIGHCVSS 7.8EG 7.82025-01-21
In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings due to a missing permission check. This could lead to local escalation of privilege with no additional…
- CVE-2024-4988HIGHCVSS 7.5EG 7.52024-05-21
The mobile application (com.transsion.videocallenhancer) interface has improper permission control, which can lead to the risk of private file leakage.
- CVE-2024-5009HIGHCVSS 8.4EG 8.42024-06-25
In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.InstallController.SetAdminPassword allows local attackers to modify admin's password.
- CVE-2024-50619HIGHCVSS 8.8EG 8.82026-02-11
Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privileged authenticated user can gain access to other people's accounts by tampering…
- CVE-2024-51324LOWCVSS 3.8EG 3.82025-02-11
An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (Bring Your Own Vulnerable Driver) attack.
- CVE-2024-51392HIGHCVSS 8.8EG 8.82025-05-29
An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the getPDF.php component
- CVE-2024-51521MEDIUMCVSS 5.7EG 5.72024-11-05
Input parameter verification vulnerability in the background service module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-52336HIGHCVSS 7.8EG 7.82024-11-26
A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw allows a local non-privileged user to execute a D-Bus c…
- CVE-2024-52516LOWCVSS 3.0EG 3.02024-11-15
Nextcloud Server is a self hosted personal cloud system. When a server is configured to only allow sharing with users that are in ones own groups, after a user was removed from a group, previously shared items were not unshared. It is reco…
- CVE-2024-52926HIGHCVSS 6.5EG 7.32024-11-18
Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.
- CVE-2024-53349HIGHCVSS 7.4EG 7.42025-03-21
Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escalation of privileges via the secretes component in the k8s cluster
- CVE-2024-53350HIGHCVSS 7.4EG 7.42025-03-21
Insecure permissions in kubeslice v1.3.1 allow attackers to gain access to the service account's token, leading to escalation of privileges.
- CVE-2024-53706HIGHCVSS 7.8EG 7.82025-01-09
A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to code execution.
- CVE-2024-54110MEDIUMCVSS 6.2EG 6.22024-12-12
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-54560MEDIUMCVSS 5.5EG 5.52025-03-10
A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, watchOS 11. A malicious app may be able to modify other apps without having App Management permission.
- CVE-2024-55215CRITICALCVSS 9.8EG 9.82025-02-07
An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.
- CVE-2024-5525HIGHCVSS 8.3EG 8.32024-05-31
Improper privilege management vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows a local user to access the application as an administrator without any provided credentials, allowing the attacker to perform…
- CVE-2024-55631HIGHCVSS 7.8EG 7.82024-12-31
An engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the t…
- CVE-2024-55632HIGHCVSS 7.8EG 7.82024-12-31
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code o…
- CVE-2024-5566MEDIUMCVSS 5.8EG 5.82024-07-16
An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related Personal Access Token. This vulnerability affected all versions of GitHub Enterprise Serv…
- CVE-2024-55949CRITICALCVSS 9.3EG 9.32024-12-16
MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa96…
- CVE-2024-55954HIGHCVSS 8.7EG 8.72025-01-16
OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Admin" role user to remove a "Root" user from the organization. This violates the intended pr…
- CVE-2024-56335HIGHCVSS 7.6EG 7.62024-12-20
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting groups from an organization given a few conditions: 1. The attack…
- CVE-2024-56447HIGHCVSS 7.8EG 7.82025-01-08
Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-57062MEDIUMCVSS 6.7EG 6.72025-03-13
An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive information via the session handling component.
- CVE-2024-5759MEDIUMCVSS 5.4EG 5.42024-06-12
An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges
- CVE-2024-5760HIGHCVSS 7.8EG 8.42024-09-11
The Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creation of a reverse shell in the tool. This is only applicable for products in the application released or manufactured befo…
- CVE-2024-57602CRITICALCVSS 9.8EG 9.82025-02-12
An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.
- CVE-2024-57604CRITICALCVSS 9.8EG 9.82025-02-12
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
- CVE-2024-57778HIGHCVSS 8.8EG 8.82025-02-14
An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from status code 500 to status code 200.
- CVE-2024-58104HIGHCVSS 7.3EG 7.32025-03-25
A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. Please note: an attacker must fir…
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →