CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 84 of 99
- CVE-2025-67792HIGHCVSS 7.8EG 7.82025-12-17
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate a DriveLock process to execute arbitrary commands on Windows computers.
- CVE-2025-67793CRITICALCVSS 9.8EG 9.82025-12-17
An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" privilege can promote themselves or other DOC users to the Supervisor role through an API …
- CVE-2025-67826HIGHCVSS 7.7EG 7.72025-12-22
An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ultimate Security antivirus can be exploited by a local unprivileged user on default installations of the product. Insecu…
- CVE-2025-67905HIGHCVSS 8.7EG 8.72026-02-17
Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic li…
- CVE-2025-68697HIGHCVSS 7.1EG 7.12025-12-26
n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code node runs in legacy (non-task-runner) JavaScript execution mode, authenticated users with workflow editing access can i…
- CVE-2025-69257MEDIUMCVSS 6.7EG 6.72025-12-30
theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.1.1, the application loads custom Python rules and configuration files from user-writable locations (e.g., `~/.con…
- CVE-2025-6934CRITICALCVSS 9.8EG 9.82025-07-01
The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is…
- CVE-2025-6943MEDIUMCVSS 4.0EG 4.02025-07-02
Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables.
- CVE-2025-69689HIGHCVSS 8.8EG 8.82026-04-27
The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dialog processes user-supplied paths with elevated permissions, which can be exploited by a local attacker to perform actio…
- CVE-2025-69875HIGHCVSS 7.8EG 7.82026-02-03
A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined file…
- CVE-2025-6994CRITICALCVSS 9.8EG 9.82025-08-06
The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.3. This is due to the plugin allowing users who are registering new accounts to set their own role or by sup…
- CVE-2025-7044HIGHCVSS 6.5EG 7.72025-12-03
An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server imp…
- CVE-2025-70795MEDIUMCVSS 5.5EG 5.52026-04-17
STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficie…
- CVE-2025-70887HIGHCVSS 8.8EG 8.82026-03-25
An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and the context.py components
- CVE-2025-70888CRITICALCVSS 9.8EG 9.82026-03-25
An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c component
- CVE-2025-7341CRITICALCVSS 9.8EG 9.82025-07-15
The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the temp_file_delete() function in all versio…
- CVE-2025-7406HIGHCVSS 7.8EG 7.82026-06-30
Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in roo…
- CVE-2025-7779HIGHCVSS 8.8EG 8.82025-09-30
Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True Image (macOS) before build 42389, Acronis True Image for SanDisk (macOS) before build 42198, Acronis True Image for Wes…
- CVE-2025-7784MEDIUMCVSS 6.5EG 6.52025-07-18
A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper …
- CVE-2025-7851CRITICALCVSS 9.8EG 9.82025-10-21
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
- CVE-2025-8107MEDIUMCVSS 6.3EG 6.32025-07-24
In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability only affects OceanBase tenants in Oracle mode…
- CVE-2025-8218HIGHCVSS 8.8EG 8.82025-08-19
The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'change_role_member' parameter in all versions up to, and including, 3.5. This is due to a lack of restriction in the …
- CVE-2025-8309HIGHCVSS 8.1EG 8.12025-08-20
There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions …
- CVE-2025-8453MEDIUMCVSS 6.7EG 6.72025-08-20
CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code execution when a privileged engineer user with console access modifies a configuration file used by a root-level daemon to…
- CVE-2025-8489CRITICALCVSS 9.8EG 9.82025-10-31
The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting…
- CVE-2025-8572CRITICALCVSS 9.8EG 9.82026-02-14
The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user registration. This makes it possible fo…
- CVE-2025-8660CRITICALCVSS 9.8EG 9.82025-08-11
Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed.
- CVE-2025-8899HIGHCVSS 8.8EG 8.82026-03-07
The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.3.20. This is due to videowhisper_register_form() function not restricting user r…
- CVE-2025-8900CRITICALCVSS 9.8EG 9.82025-11-03
The Doccure Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and excluding, 1.5.4. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'user_type…
- CVE-2025-9038HIGHCVSS 7.5EG 7.52025-09-22
Improper Privilege Management vulnerability in GE Vernova S1 Agile Configuration Software on Windows allows Privilege Escalation.This issue affects S1 Agile Configuration Software: 3.1 and previous version.
- CVE-2025-9059HIGHCVSS 8.8EG 8.82025-09-11
The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking.
- CVE-2025-9067HIGHCVSS 7.8EG 7.82025-10-14
A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair and hijack the resulting console window. This allows the launch…
- CVE-2025-9068HIGHCVSS 7.8EG 7.82025-10-14
A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can initiate a repair and hi…
- CVE-2025-9912MEDIUMCVSS 6.3EG 6.32026-06-16
Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privilege.
- CVE-2025-9966HIGHCVSS 7.3EG 7.32025-09-23
Improper privilege management vulnerability in Novakon P series allows attackers to gain root privileges if one service is compromized.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06…
- CVE-2026-0009HIGHCVSS 7.8EG 7.82026-06-01
In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2026-0016LOWCVSS 3.3EG 3.32026-06-01
In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disclosure with no additional execution priv…
- CVE-2026-0019HIGHCVSS 7.8EG 7.82026-06-17
In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl…
- CVE-2026-0023HIGHCVSS 7.8EG 8.42026-03-02
In createSessionInternal of PackageInstallerService.java, there is a possible way for an app to update its ownership due to a missing permission check. This could lead to local escalation of privilege with no additional execution privilege…
- CVE-2026-0029CRITICALCVSS 8.4EG 9.82026-03-02
In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi…
- CVE-2026-0032HIGHCVSS 7.8EG 7.82026-03-02
In multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need…
- CVE-2026-0046MEDIUMCVSS 6.2EG 6.22026-06-01
In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed.…
- CVE-2026-0048MEDIUMCVSS 6.8EG 6.82026-06-01
In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User int…
- CVE-2026-0050LOWCVSS 3.3EG 3.32026-06-01
In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User intera…
- CVE-2026-0055MEDIUMCVSS 6.2EG 6.22026-06-01
In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a path traversal error. This could lead to local escalation of privilege with no addi…
- CVE-2026-0063HIGHCVSS 7.8EG 7.82026-06-17
In setAllowedCarriers of PhoneInterfaceManager.java, there is a possible way to disable carrier restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed.…
- CVE-2026-0086MEDIUMCVSS 6.8EG 6.82026-06-01
In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…
- CVE-2026-0089HIGHCVSS 7.8EG 7.82026-06-01
In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. U…
- CVE-2026-0091HIGHCVSS 7.8EG 7.82026-06-01
In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction …
- CVE-2026-0275MEDIUMCVSS 6.7EG 6.72026-07-09
A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform actions on the device with root privileges. This issue on…
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →