← Back
CWE-269

2,777 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (2,777)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gl Inet
12Gl A1300 Firmware
Gl Ar300m FirmwareGl Ar750 Firmware+9 more
Jun 18, 2025
Jan 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2...Show more
An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.Show less
1Zte
1Zxcloud Irai
Jan 28, 2025
Jan 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to escalate local privileges.
1Google
1Pixel Watch Firmware
Feb 13, 2025
Jan 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a     possible way to access adb before SUW completion due to an insecure default     value. This could lead to local escalation of privilege with no ad...Show more
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a     possible way to access adb before SUW completion due to an insecure default     value. This could lead to local escalation of privilege with no additional     execution privileges needed. User interaction is not needed for     exploitationShow less
1Google
4Home Firmware
Home Mini FirmwareNest Audio Firmware+1 more
Nov 21, 2024
Jan 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege 
1Cloudflare
1Wrangler
Nov 21, 2024
Dec 29, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
The V8 inspector intentionally allows arbitrary code execution within the Workers sandbox for debugging. wrangler dev would previously start an inspector server listening on all network interfaces. This would allow an at...Show more
The V8 inspector intentionally allows arbitrary code execution within the Workers sandbox for debugging. wrangler dev would previously start an inspector server listening on all network interfaces. This would allow an attacker on the local network to connect to the inspector and run arbitrary code. Additionally, the inspector server did not validate Origin/Host headers, granting an attacker that can trick any user on the local network into opening a malicious website the ability to run code. If wrangler dev --remote was being used, an attacker could access production resources if they were bound to the worker. This issue was fixed in wrangler@3.19.0 and wrangler@2.20.2. Whilst wrangler dev's inspector server listens on local interfaces by default as of wrangler@3.16.0, an SSRF vulnerability in miniflare https://github.com/cloudflare/workers-sdk/security/advisories/GHSA-fwvg-2739-22v7  (CVE-2023-7078) allowed access from the local network until wrangler@3.18.0. wrangler@3.19.0 and wrangler@2.20.2 introduced validation for the Origin/Host headers. Show less
1Hihonor
1Magic Ui
Apr 17, 2025
Dec 29, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
1Hihonor
1Magic Ui
Nov 21, 2024
Dec 29, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
1Hihonor
1Magic Ui
Nov 21, 2024
Dec 29, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
1Hihonor
1Magic Os
Nov 21, 2024
Dec 29, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
1Hihonor
1Lge An00 Firmware
Nov 21, 2024
Dec 29, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions
1Hihonor
1Magichome
Nov 21, 2024
Dec 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
1Honor
1Magicos
Jan 27, 2026
Dec 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
1Honor
1Magicos
Jan 27, 2026
Dec 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
1Honor
1Magicos
Jan 27, 2026
Dec 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
1Metersphere
1Metersphere
Nov 21, 2024
Dec 28, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
MeterSphere is a one-stop open source continuous testing platform. Prior to 2.10.10-lts, the authenticated attackers can update resources which don't belong to him if the resource ID is known. This issue if fixed in 2.10...Show more
MeterSphere is a one-stop open source continuous testing platform. Prior to 2.10.10-lts, the authenticated attackers can update resources which don't belong to him if the resource ID is known. This issue if fixed in 2.10.10-lts. There are no known workarounds.Show less
1Sudo Project
1Sudo
Nov 21, 2024
Dec 23, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client...Show more
A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts retain privileges even after retracting them.Show less
1Amazon
1Awslabs Sandbox Accounts For Events
Nov 21, 2024
Dec 22, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Sandbox Accounts for Events provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially read data from the events table by se...Show more
Sandbox Accounts for Events provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially read data from the events table by sending request payloads to the events API, collecting information on planned events, timeframes, budgets and owner email addresses. This data access may allow users to get insights into upcoming events and join events which they have not been invited to. This issue has been patched in version 1.10.0.Show less
1Github
1Enterprise Server
Nov 21, 2024
Dec 21, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must have already existed in the target repo. This vulnerability affected all...Show more
Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must have already existed in the target repo. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1. Show less
1Github
1Enterprise Server
Nov 21, 2024
Dec 21, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper privilege management in all versions of GitHub Enterprise Server allows users with authorized access to the management console with an editor role to escalate their privileges by making requests to the endpoint...Show more
Improper privilege management in all versions of GitHub Enterprise Server allows users with authorized access to the management console with an editor role to escalate their privileges by making requests to the endpoint used for bootstrapping the instance. This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.12, 3.9.6, 3.10.3, and 3.11.0.Show less
1Thegreenbow
1Thegreenbow Vpn Client
Dec 17, 2025
Dec 19, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and Windows Enterprise VPN Client 6.87 allows attackers to gain escalated privileges via crafted changes...Show more
An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and Windows Enterprise VPN Client 6.87 allows attackers to gain escalated privileges via crafted changes to memory mapped file.Show less