CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 77 of 99
- CVE-2024-5907HIGHCVSS 7.0EG 7.02024-06-12
A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully explo…
- CVE-2024-5909MEDIUMCVSS 5.5EG 5.52024-06-12
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and…
- CVE-2024-6151HIGHCVSS 7.8EG 7.82024-07-10
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS
- CVE-2024-6240HIGHCVSS 7.7EG 7.72024-06-21
Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the mal…
- CVE-2024-6286HIGHCVSS 7.8EG 7.82024-07-10
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
- CVE-2024-6325MEDIUMCVSS 6.5EG 6.52024-07-16
The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and CVE-2022-1161 https://www.rockwellautomation.com/en-…
- CVE-2024-6326MEDIUMCVSS 5.5EG 5.52024-07-16
An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes priva…
- CVE-2024-6359MEDIUMCVSS 6.4EG 6.42024-08-06
Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.
- CVE-2024-6411HIGHCVSS 8.8EG 8.82024-07-10
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This is due to a lack of validation on user-supplied data in the 'pm_upload_i…
- CVE-2024-6482HIGHCVSS 8.8EG 8.82024-09-14
The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a lack of validation and missing capability check on user-supplied data in the 'lwp_update_…
- CVE-2024-6624CRITICALCVSS 9.8EG 9.82024-07-11
The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to …
- CVE-2024-6677HIGHCVSS 7.8EG 7.82024-07-12
Privilege escalation in uberAgent
- CVE-2024-6758MEDIUMCVSS 6.5EG 6.52024-08-12
Improper Privilege Management in Sprecher Automation SPRECON-E below version 8.71j allows a remote attacker with low privileges to save unauthorized protection assignments.
- CVE-2024-6908MEDIUMCVSS 6.0EG 6.02024-07-19
Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin via a crafted PUT HTTP request, potentially leading to unauthorized access to sensitive system functions and data.
- CVE-2024-7048MEDIUMCVSS 5.4EG 6.32024-10-10
In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and overwrite files ma…
- CVE-2024-7291HIGHCVSS 7.2EG 7.22024-08-03
The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on user meta fields. This makes it possible for authenticated attackers, with …
- CVE-2024-7473HIGHCVSS 6.5EG 7.52024-10-29
An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update other users' prompts by manipulating the 'id' paramete…
- CVE-2024-7480MEDIUMCVSS 4.2EG 4.22024-08-08
An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.…
- CVE-2024-7493CRITICALCVSS 9.8EG 9.82024-09-06
The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin allowing arbitrary data to be passed to wp_insert_user() during registration. This makes i…
- CVE-2024-7890HIGHCVSS 7.3EG 7.32024-09-11
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
- CVE-2024-7960CRITICALCVSS 9.1EG 9.12024-09-12
The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The vulnerability exists due to having an incorrect privilege matrix that allows users to have …
- CVE-2024-8068CRITICALCVSS 8.0EG 9.0⚠ KEV2024-11-12
Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain
- CVE-2024-8100HIGHCVSS 8.7EG 8.72025-05-08
On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision.
- CVE-2024-8246HIGHCVSS 8.8EG 8.82024-09-14
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.8.11. This is d…
- CVE-2024-8247HIGHCVSS 8.8EG 8.82024-09-06
The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin not restricting what user meta can be updated as screen options. This makes it possible for…
- CVE-2024-8263LOWCVSS 2.7EG 2.72024-09-23
An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in…
- CVE-2024-8306HIGHCVSS 7.8EG 7.82024-09-11
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalatio…
- CVE-2024-8420CRITICALCVSS 9.8EG 9.82025-02-28
The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthe…
- CVE-2024-8424HIGHCVSS 7.8EG 7.82024-11-08
Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions.
- CVE-2024-8533HIGHCVSS 8.8EG 8.82024-09-12
A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.
- CVE-2024-8810MEDIUMCVSS 6.5EG 6.52024-11-07
A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator. An attacker would require an account with administrator access to install a malicious Git…
- CVE-2024-8853CRITICALCVSS 9.8EG 9.82024-09-20
The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers …
- CVE-2024-9002HIGHCVSS 7.8EG 7.82024-10-11
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity, and availability of the workstation when non-admin authenticated user tries to perform privilege escalati…
- CVE-2024-9192HIGHCVSS 8.8EG 8.82024-11-16
The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due to insufficient validation on user meta that can be updated in the wpvr_rate_request_result() function in all versions u…
- CVE-2024-9265CRITICALCVSS 9.8EG 9.82024-10-01
The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due to the plugin not properly restricting the roles that can set during registration through …
- CVE-2024-9431HIGHCVSS 8.8EG 8.82025-03-20
In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After logging into the system, users can change the passwords of other users, leading to potential account takeover.
- CVE-2024-9471MEDIUMCVSS 4.7EG 4.72024-10-09
A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privile…
- CVE-2024-9478CRITICALCVSS 10.0EG 10.02024-11-20
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.
- CVE-2024-9479CRITICALCVSS 10.0EG 10.02024-11-20
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.
- CVE-2024-9500HIGHCVSS 7.8EG 7.82024-11-15
A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to insecure privilege management.
- CVE-2024-9518CRITICALCVSS 9.8EG 9.82024-10-10
The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restriction on the 'form_actions' and 'userplus_update_user_profile' functions. This makes it possible for un…
- CVE-2024-9636CRITICALCVSS 9.8EG 9.82025-01-15
The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.3. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This m…
- CVE-2024-9941HIGHCVSS 8.8EG 8.82024-11-23
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gmgt_add_staff_member() function in all versions up to, and including, 67.1.0. This makes it…
- CVE-2025-0177CRITICALCVSS 9.8EG 9.82025-03-08
The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possib…
- CVE-2025-0180CRITICALCVSS 9.8EG 9.82025-02-11
The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This make…
- CVE-2025-0320HIGHCVSS 7.8EG 7.82025-06-17
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows
- CVE-2025-0327HIGHCVSS 7.8EG 7.82025-02-13
CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availabi…
- CVE-2025-0358HIGHCVSS 8.8EG 8.82025-06-02
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalation, enabling a lower-privileged user to gain administrator…
- CVE-2025-0416HIGHCVSS 8.9EG 8.92025-04-01
Local privilege escalation through insecure DCOM configuration in Valmet DNA versions prior to C2023. The DCOM object Valmet DNA Engineering has permissions that allow it to run commands as a user with the SeImpersonatePrivilege privilege…
- CVE-2025-0505CRITICALCVSS 10.0EG 10.02025-05-08
On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipul…
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →