CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 81 of 99
- CVE-2025-36640HIGHCVSS 8.8EG 8.82026-01-13
A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts which could lead to escalation of privileges.
- CVE-2025-36729HIGHCVSS 7.2EG 7.22025-08-26
A non-primary administrator user with admin rights to the web interface but without shell access permissions can display configuration of the device including the master admin password. This vulnerability also allows the user to give thems…
- CVE-2025-36890CRITICALCVSS 9.8EG 9.82025-09-04
Elevation of Privilege
- CVE-2025-36891HIGHCVSS 8.8EG 8.82025-09-04
Elevation of privilege
- CVE-2025-36896CRITICALCVSS 9.8EG 9.82025-09-04
WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.
- CVE-2025-36901HIGHCVSS 8.8EG 8.82025-09-04
WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223.
- CVE-2025-36904CRITICALCVSS 9.8EG 9.82025-09-04
WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.
- CVE-2025-37101HIGHCVSS 8.7EG 8.72025-06-26
A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perf…
- CVE-2025-37123HIGHCVSS 8.8EG 8.82025-09-16
A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to…
- CVE-2025-37186HIGHCVSS 7.8EG 7.82026-01-13
A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA) client. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution…
- CVE-2025-3761HIGHCVSS 8.8EG 8.82025-04-24
The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.16. This is due to the mt_save_profile() function not appropriately restricting access to un…
- CVE-2025-3852HIGHCVSS 8.8EG 8.82025-05-07
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.0 to 2.6.0. This is due to the plugin not properly validating a user's identity prior to updating their details lik…
- CVE-2025-39202HIGHCVSS 7.3EG 7.32025-06-24
A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and overwrite files causing information leak and data corruption.
- CVE-2025-40538CRITICALCVSS 7.2EG 9.12026-02-24
A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges. …
- CVE-2025-40548CRITICALCVSS 9.1EG 9.12025-11-18
A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk…
- CVE-2025-40594MEDIUMCVSS 6.3EG 6.32025-09-09
A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < V6.4 HF7), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed with…
- CVE-2025-4085HIGHCVSS 7.1EG 7.12025-04-29
An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
- CVE-2025-43019HIGHCVSS 7.8EG 7.82025-07-08
A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to escalate privileges via an arbitrary file deletion.
- CVE-2025-4315HIGHCVSS 8.8EG 8.82025-06-11
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This is due to the plugin allowing a user to update arbitrary user meta through th…
- CVE-2025-43188HIGHCVSS 7.8EG 7.82025-07-30
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious app may be able to gain root privileges.
- CVE-2025-43199CRITICALCVSS 9.8EG 9.82025-07-30
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A malicious app may be able to gain root privileges.
- CVE-2025-43248HIGHCVSS 7.8EG 7.82025-07-30
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may be able to gain root privileges.
- CVE-2025-43249HIGHCVSS 7.8EG 7.82025-07-30
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to gain root privileges.
- CVE-2025-43256HIGHCVSS 7.8EG 7.82025-07-30
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to gain root privileges.
- CVE-2025-43306HIGHCVSS 7.8EG 7.82026-05-26
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to gain root privileges.
- CVE-2025-43320HIGHCVSS 7.8EG 7.82025-12-12
The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.
- CVE-2025-43333HIGHCVSS 7.8EG 7.82025-09-15
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to gain root privileges.
- CVE-2025-4334CRITICALCVSS 9.8EG 9.82025-06-26
The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. This …
- CVE-2025-4335HIGHCVSS 8.8EG 8.82025-05-07
The Woocommerce Multiple Addresses plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.7.1. This is due to insufficient restrictions on user meta that can be updated through the save_multipl…
- CVE-2025-43512HIGHCVSS 7.8EG 7.82025-12-12
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may be able to elevate privileges.
- CVE-2025-43722MEDIUMCVSS 6.7EG 6.72025-09-08
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
- CVE-2025-44040HIGHCVSS 7.2EG 7.22025-05-21
An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication decisions may be made via PHP loose-equality comparisons if a specific MD5 value is present in the c…
- CVE-2025-45737MEDIUMCVSS 6.5EG 6.52025-06-27
An issue in NetEase (Hangzhou) Network Co., Ltd NeacSafe64 Driver before v1.0.0.8 allows attackers to escalate privileges via sending crafted IOCTL commands to the NeacSafe64.sys component.
- CVE-2025-4601HIGHCVSS 8.8EG 8.82025-06-10
The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is due to the theme not properly restricting user roles that can be updated as part of the i…
- CVE-2025-46116HIGHCVSS 8.8EG 8.82025-07-21
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI co…
- CVE-2025-46310MEDIUMCVSS 6.0EG 6.02026-02-11
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26. An attacker with root privileges may be able to delete protected system files.
- CVE-2025-4636HIGHCVSS 7.8EG 7.82025-05-30
Due to excessive privileges granted to the web user running the airpointer web platform, a malicious actor that gains control of the this user would be able to privilege escalate to the root user
- CVE-2025-46364CRITICALCVSS 9.1EG 9.12025-11-05
Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape Vulnerability to gain control of system.
- CVE-2025-4646HIGHCVSS 7.2EG 7.22025-05-13
Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.
- CVE-2025-4649MEDIUMCVSS 4.9EG 4.92025-05-13
Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display …
- CVE-2025-46576MEDIUMCVSS 5.4EG 5.42025-04-27
There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privilege restrictions and delete content.
- CVE-2025-4681HIGHCVSS 8.6EG 8.62025-06-10
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Abuse.This issue affects upKeeper Instant Privilege Access: before 1.4.0.
- CVE-2025-47411HIGHCVSS 8.1EG 8.12026-01-01
A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator. This vulnera…
- CVE-2025-47420HIGHCVSS 8.7EG 8.72025-05-06
266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.
- CVE-2025-47713HIGHCVSS 8.8EG 8.82025-06-10
A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can reset the password of user-accounts of Admin role type. This operation is not ap…
- CVE-2025-47849HIGHCVSS 8.8EG 8.82025-06-10
A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can get the API key and secret key of user-accounts of Admin role type in the same d…
- CVE-2025-47955HIGHCVSS 7.8EG 7.82025-06-10
Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
- CVE-2025-48613HIGHCVSS 7.8EG 7.82026-03-02
In VBMeta, there is a possible way to modify and resign VBMeta using a test key, assuming the original image was previously signed with the same key. This could lead to local escalation of privilege with no additional execution privileges …
- CVE-2025-48645HIGHCVSS 7.8EG 7.82026-03-02
In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n…
- CVE-2025-4879HIGHCVSS 7.8EG 7.82025-06-17
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →