CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 80 of 99
- CVE-2025-26707MEDIUMCVSS 5.3EG 5.32025-03-11
Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.
- CVE-2025-2713HIGHCVSS 7.8EG 7.82025-03-28
Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initi…
- CVE-2025-27468HIGHCVSS 7.0EG 7.02025-05-13
Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
- CVE-2025-27639HIGHCVSS 8.8EG 8.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Privilege Escalation V-2024-015.
- CVE-2025-27644HIGHCVSS 7.8EG 7.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Local Privilege Escalation V-2024-007.
- CVE-2025-27811HIGHCVSS 7.8EG 7.82025-06-04
A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a local attacker to escalate their privileges via a vulnerable COM interface in the target service.
- CVE-2025-27846MEDIUMCVSS 4.3EG 4.32025-08-14
In ESPEC North America Web Controller 3 before 3.3.8, an attacker with physical access can gain elevated privileges because GRUB and the BIOS are unprotected.
- CVE-2025-27847MEDIUMCVSS 4.3EG 4.32025-08-14
In ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout.
- CVE-2025-2798CRITICALCVSS 9.8EG 9.82025-04-04
The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during registration. This makes it possible for unauthenticated at…
- CVE-2025-28237HIGHCVSS 8.8EG 8.82025-04-18
An issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges via a crafted JSON payload.
- CVE-2025-28399CRITICALCVSS 9.8EG 9.82025-04-15
An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class.
- CVE-2025-28400MEDIUMCVSS 6.7EG 6.72025-04-07
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method
- CVE-2025-28401MEDIUMCVSS 6.7EG 6.72025-04-07
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter
- CVE-2025-2858HIGHCVSS 8.8EG 8.82025-03-28
Privilege escalation vulnerability in the saTECH BCU firmware version 2.1.3. An attacker with access to the CLI of the device could make use of the nice command to bypass all restrictions and elevate privileges as a superuser.
- CVE-2025-29033HIGHCVSS 7.3EG 7.32025-04-01
An issue in BambooHR Build v.25.0210.170831-83b08dd allows a remote attacker to escalate privileges via the /saml/index.php?r=" HTTP GET parameter.
- CVE-2025-29165CRITICALCVSS 9.8EG 9.82026-03-05
An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component
- CVE-2025-29800HIGHCVSS 7.8EG 7.82025-04-08
Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
- CVE-2025-29924HIGHCVSS 7.5EG 7.52025-03-19
XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it's possible for an user to get access to private information through the REST API - but could also be through another API - when a sub wiki is using …
- CVE-2025-29976HIGHCVSS 7.8EG 7.82025-05-13
Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally.
- CVE-2025-29999MEDIUMCVSS 6.7EG 6.72025-04-08
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application searches for executable files in the application folder without proper validation. This could allow an attacker to execute…
- CVE-2025-30475HIGHCVSS 8.1EG 8.12025-05-15
Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.
- CVE-2025-3101HIGHCVSS 8.8EG 8.82025-04-24
The Configurator Theme Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.4.7. This is due to the plugin not properly validating user meta fields prior to updating them in the database. …
- CVE-2025-3105HIGHCVSS 8.8EG 8.82025-04-04
The Vehica Core plugin for WordPress, used by the Vehica - Car Dealer & Listing WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 1.0.97. This is due to the plugin not properly validating user met…
- CVE-2025-31222HIGHCVSS 7.8EG 7.82025-05-12
A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. A user may be able to elevate pr…
- CVE-2025-31243HIGHCVSS 7.8EG 7.82025-07-30
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to gain root privileges.
- CVE-2025-31272HIGHCVSS 7.8EG 7.82026-06-11
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.
- CVE-2025-31282MEDIUMCVSS 4.6EG 4.62025-04-02
A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges…
- CVE-2025-31283MEDIUMCVSS 4.6EG 4.62025-04-02
A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. …
- CVE-2025-31284MEDIUMCVSS 4.6EG 4.62025-04-02
A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. …
- CVE-2025-31285MEDIUMCVSS 4.6EG 4.62025-04-02
A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. …
- CVE-2025-31286MEDIUMCVSS 4.6EG 4.62025-04-02
An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code. Please note: this issue has already been addressed on the backend service and is no longer consider…
- CVE-2025-32098MEDIUMCVSS 5.3EG 5.32025-09-02
An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insecure file delete operations during the update process.
- CVE-2025-3224HIGHCVSS 7.8EG 7.82025-04-28
A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate privileges to SYSTEM. During an update, Docker Desktop attempts to delete files and subd…
- CVE-2025-32345HIGHCVSS 7.8EG 7.82025-09-04
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escala…
- CVE-2025-3278CRITICALCVSS 9.8EG 9.82025-04-19
The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.4. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'use…
- CVE-2025-32955MEDIUMCVSS 6.0EG 6.02025-04-21
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Versions from 0.12.0 to before 2.12.0 are vulnerable to `disable-sudo` bypass. Harden-Runner includes a policy option `disable-sudo` to prevent the …
- CVE-2025-32974CRITICALCVSS 9.0EG 9.02025-04-30
XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 16.2.0, the required rights analysis doesn't consider TextAreas with default content type. When editing a page, XWiki wa…
- CVE-2025-33067HIGHCVSS 8.4EG 8.42025-06-10
Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
- CVE-2025-33187CRITICALCVSS 9.3EG 9.32025-11-25
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to SoC protected areas. A successful exploit of this vulnerability might lead to code execution, information disclosure, …
- CVE-2025-33188HIGHCVSS 8.0EG 8.02025-11-25
NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware controls. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of servi…
- CVE-2025-34078HIGHCVSS 7.8EG 7.82025-07-02
A local privilege escalation vulnerability exists in NSClient++ 0.5.2.35 when both the web interface and ExternalScripts features are enabled. The configuration file (nsclient.ini) stores the administrative password in plaintext and is rea…
- CVE-2025-34143CRITICALCVSS 9.3EG 9.32025-07-22
An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login as the privileged internal SYSTEM user by manipulating the username field. The SYSTEM account does not require a passw…
- CVE-2025-3418HIGHCVSS 8.8EG 8.82025-04-12
The WPC Admin Columns plugin for WordPress is vulnerable to privilege escalation in versions 2.0.6 to 2.1.0. This is due to the plugin not properly restricting user meta values that can be updated through the ajax_edit_save() function. Thi…
- CVE-2025-34187HIGHCVSS 8.8EG 8.82025-09-16
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are writable by web-facing users or accessible via command injec…
- CVE-2025-34204CRITICALCVSS 9.8EG 9.82025-09-19
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) contains multiple Docker containers that run primary application processes (for example PHP workers, Node.js servers and custom binaries)…
- CVE-2025-34251HIGHCVSS 8.6EG 8.62025-10-07
Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass vulnerability. The TCU runs the Android Debug Bridge (adbd) as root and, despite a “lockdown” check that disables adb shell, still permits…
- CVE-2025-3438MEDIUMCVSS 6.5EG 6.52025-05-02
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 4.17.4. This is due to a lack of restriction of role when registering…
- CVE-2025-36630HIGHCVSS 8.4EG 8.42025-07-02
In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
- CVE-2025-36631HIGHCVSS 8.4EG 8.42025-06-13
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
- CVE-2025-36633HIGHCVSS 8.8EG 8.82025-06-13
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation.
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →