CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 83 of 99
- CVE-2025-57443MEDIUMCVSS 5.1EG 5.12025-10-02
FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library-validation) that allow unprivileged local attackers to inject code into the FrostWire process via the DYLD_INSERT_LIBR…
- CVE-2025-57759MEDIUMCVSS 4.3EG 4.32025-08-28
Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions. This issue has…
- CVE-2025-57760HIGHCVSS 8.8EG 8.82025-08-25
Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an authenticated user with RCE access can invoke the internal CLI command langflow supe…
- CVE-2025-57840LOWCVSS 2.2EG 2.22025-12-24
ADB(Android Debug Bridge) is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability.
- CVE-2025-58053CRITICALCVSS 9.8EG 9.82025-12-19
Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating any existing account with a self forged POST request, one can gain higher privileges. Version 1.2.0 fixes the issue.
- CVE-2025-58432HIGHCVSS 7.8EG 7.82025-09-17
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all prior versions, the /v2_1/files/file/uploadV2 endpoint allows file upload from ANY USER who has access to localhost. Fi…
- CVE-2025-59094HIGHCVSS 8.4EG 8.42026-01-26
A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sysdef.exe). Within this application it is possible to specify an arbitrary executable as well as the weekday and start t…
- CVE-2025-59247HIGHCVSS 8.8EG 8.82025-10-09
Azure PlayFab Elevation of Privilege Vulnerability
- CVE-2025-5931HIGHCVSS 8.8EG 8.82025-08-26
The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.5. This is due to the plugin not properly validating a user's identity prior to updating their password…
- CVE-2025-59514HIGHCVSS 7.8EG 7.82025-11-11
Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-5954CRITICALCVSS 9.8EG 9.82025-08-01
The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0. This is due to the plugin not restricting user role selection at the time of registr…
- CVE-2025-59693CRITICALCVSS 9.8EG 9.82025-12-02
The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to obtain debug access and escalate privi…
- CVE-2025-59697HIGHCVSS 7.2EG 7.22025-12-02
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloader configuration…
- CVE-2025-59705MEDIUMCVSS 6.8EG 6.82025-12-02
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe…
- CVE-2025-59790MEDIUMCVSS 5.4EG 5.42025-11-28
Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.
- CVE-2025-6042HIGHCVSS 7.3EG 7.32025-10-15
The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.4.0. This is due to the plugin assigning the editor ro…
- CVE-2025-6080HIGHCVSS 8.8EG 8.82025-08-16
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in all versions up to, and including, 67.7.0. This is due to the plugin not properly validating a user's capabilities pri…
- CVE-2025-61152MEDIUMCVSS 6.5EG 6.52025-10-10
python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A malicious actor can craft a forged token with arbitrary claims (e.g., is_admin=true) and bypass authent…
- CVE-2025-61429HIGHCVSS 8.8EG 8.82025-10-29
An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request.
- CVE-2025-61759MEDIUMCVSS 6.5EG 6.52025-10-21
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows low privileged attacker with logon to the in…
- CVE-2025-6177HIGHCVSS 7.4EG 7.42025-06-16
Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code execution via exploiting a debug shell (VT3 console) accessible through specific key combin…
- CVE-2025-61786LOWCVSS 3.3EG 3.32025-10-08
Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype.stat` and `Deno.FsFile.prototype.statSync` are not limited by the permission model check `--deny-read=./`. It's possib…
- CVE-2025-6182HIGHCVSS 8.5EG 8.52025-08-20
The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could exploit this behavior to install untrusted root certificates or remove trusted ones.
- CVE-2025-6254CRITICALCVSS 9.8EG 9.82026-06-10
The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles that a user can regist…
- CVE-2025-62592MEDIUMCVSS 6.0EG 6.02025-10-21
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the i…
- CVE-2025-62625MEDIUMCVSS 6.0EG 6.02026-05-14
Improper privilege management in the KVM key download component could allow an attacker to swap tokens and download sensitive keys, potentially resulting in unauthorized access to privileged resources and loss of confidentiality.
- CVE-2025-62686MEDIUMCVSS 6.2EG 6.22025-12-03
A local privilege escalation vulnerability exists in the Plugin Alliance InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 on macOS. Due to the absence of a hardened runtime and a __RESTRICT segment, a lo…
- CVE-2025-6366HIGHCVSS 8.8EG 8.82025-08-26
The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. This is due to the plugin not properly validating a user's capabilities prior to updating their profile in the el_update…
- CVE-2025-63909HIGHCVSS 7.8EG 7.82026-03-03
Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers to escalate privileges to root and read and write arbitrary files.
- CVE-2025-64336MEDIUMCVSS 5.4EG 5.42025-11-07
ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Photos feature is vulnerable to stored Cross-site Scripting (XSS). An authenticated regular user can upload a photo with a malicious Photo…
- CVE-2025-64338CRITICALCVSS 9.0EG 9.02025-11-07
ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular user can create a photo collection whose Collection Name contains HTML/JavaScript payloads, which making ClipBucket’s Ma…
- CVE-2025-64436MEDIUMCVSS 5.3EG 5.32025-11-07
KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration …
- CVE-2025-64487HIGHCVSS 7.6EG 7.62026-02-11
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability exists in the Outline document management system due to inconsistent authorization checks between user and group members…
- CVE-2025-64489HIGHCVSS 8.8EG 8.82025-11-08
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 contain a privilege escalation vulnerability where user sessions are not invali…
- CVE-2025-64507HIGHCVSS 7.8EG 7.82025-11-10
Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a container with an attached custom storage…
- CVE-2025-65621MEDIUMCVSS 5.4EG 5.42025-12-01
Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.
- CVE-2025-66173MEDIUMCVSS 6.2EG 6.22025-12-19
There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the …
- CVE-2025-66265MEDIUMCVSS 6.9EG 6.92025-11-26
CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allows attackers to replace configuration files (such as snmp.conf) or hijack DLLs to escalate…
- CVE-2025-66266CRITICALCVSS 9.3EG 9.32025-11-26
The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control. A local attacker can replace the executable with a malicious binary to execute code with SYSTEM privileges or simply c…
- CVE-2025-66314HIGHCVSS 7.5EG 7.52025-11-27
Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ElasticNet UME R32: ElasticNet_UME_R32_V16.23.20.04.
- CVE-2025-66315HIGHCVSS 8.8EG 8.82026-01-09
There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can execute write permissions in a specific directory.
- CVE-2025-66324HIGHCVSS 5.5EG 8.42025-12-08
Input verification vulnerability in the compression and decompression module. Impact: Successful exploitation of this vulnerability may affect app data integrity.
- CVE-2025-66374HIGHCVSS 7.8EG 7.82026-02-03
CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of an Administration task.
- CVE-2025-66428HIGHCVSS 8.8EG 8.82026-01-22
An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.
- CVE-2025-6723MEDIUMCVSS 5.8EG 5.82026-01-30
Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access controls. A local attacker may interfere with the pipe connection process and exploit the insufficient access restrictions…
- CVE-2025-67246HIGHCVSS 7.3EG 7.32026-01-15
A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control in the IOCTL handler. This driver exposes a device interface accessible to a normal user and handles attacker-controlle…
- CVE-2025-6758CRITICALCVSS 9.8EG 9.82025-08-19
The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, and including, 3.6. This is due to a lack of restriction in the …
- CVE-2025-6759HIGHCVSS 7.8EG 7.82025-07-08
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS
- CVE-2025-67727CRITICALCVSS 9.8EG 9.82025-12-12
Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI workflow is triggered in a way that grants the GitHub Actions workflow elevated permission…
- CVE-2025-67781CRITICALCVSS 9.9EG 9.92025-12-17
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileged processes to gain more privileges on Windows computers.
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →