← Back
CWE-269

3,328 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,328)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Apr 12, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
The WPC Admin Columns plugin for WordPress is vulnerable to privilege escalation in versions 2.0.6 to 2.1.0. This is due to the plugin not properly restricting user meta values that can be updated through the ajax_edit_s...Show more
The WPC Admin Columns plugin for WordPress is vulnerable to privilege escalation in versions 2.0.6 to 2.1.0. This is due to the plugin not properly restricting user meta values that can be updated through the ajax_edit_save() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their role to that of an administrator.Show less
1Apple
1Macos
Jun 17, 2026
Apr 11, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
An app may be able to elevate privileges. This issue is fixed in macOS 14. This issue was addressed by removing the vulnerable code.
1Apple
3Ipados
Iphone OsMacos
Jun 17, 2026
Apr 11, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access sensitive user data.
1Microsoft
1Autoupdate
Jun 17, 2026
Apr 8, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
-
-
Jun 17, 2026
Apr 8, 2025
5.4 MEDIUM· v4
6.7 MEDIUM· v3
N/A· v2
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application searches for executable files in the application folder without proper validation. This could allow an...Show more
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application searches for executable files in the application folder without proper validation. This could allow an attacker to execute arbitrary code with administrative privileges by placing a malicious executable in the same directory.Show less
1Ruoyi
1Ruoyi
Jun 17, 2026
Apr 7, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter
1Ruoyi
1Ruoyi
Jun 17, 2026
Apr 7, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method
1Xtendify
1Woffice
Jun 17, 2026
Apr 4, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during registration. This makes it possible for...Show more
The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during registration. This makes it possible for unauthenticated attackers to register with an Administrator role if a custom login form is being used. This can be combined with CVE-2025-2797 to bypass the user approval process if an Administrator can be tricked into taking an action such as clicking a link.Show less
-
-
Jun 17, 2026
Apr 4, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
The Vehica Core plugin for WordPress, used by the Vehica - Car Dealer & Listing WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 1.0.97. This is due to the plugin not properly...Show more
The Vehica Core plugin for WordPress, used by the Vehica - Car Dealer & Listing WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 1.0.97. This is due to the plugin not properly validating user meta fields prior to updating them in the database. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change escalate their privileges to Administrator.Show less
1Trendmicro
1Trend Vision One
Jun 17, 2026
Apr 2, 2025
N/A· v4
9.0 CRITICAL· v3
N/A· v2
An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code. Please note: this issue has already been addressed on the backend service and is...Show more
An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code. Please note: this issue has already been addressed on the backend service and is no longer considered an active vulnerability.Show less
1Trendmicro
1Trend Vision One
Jun 17, 2026
Apr 2, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately esc...Show more
A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.Show less
1Trendmicro
1Trend Vision One
Jun 17, 2026
Apr 2, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then change the role of the account and ultimately escala...Show more
A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.Show less
1Trendmicro
1Trend Vision One
Jun 17, 2026
Apr 2, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could then change the role of the account and ultimately es...Show more
A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.Show less
1Trendmicro
1Trend Vision One
Jun 17, 2026
Apr 2, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could then change the role of the account and ultimately...Show more
A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.Show less
-
-
Jun 17, 2026
Apr 1, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
An issue in BambooHR Build v.25.0210.170831-83b08dd allows a remote attacker to escalate privileges via the /saml/index.php?r=" HTTP GET parameter.
-
-
Jun 17, 2026
Apr 1, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can escalate their privileges to root on the appliance running VMware Aria Operations.
-
-
Jun 17, 2026
Apr 1, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to privilege escalation in all versions up to, and including, 1.6.26. This is due to insufficient role restrictions in the 'process_register'...Show more
The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to privilege escalation in all versions up to, and including, 1.6.26. This is due to insufficient role restrictions in the 'process_register' function. This makes it possible for unauthenticated attackers to register an account with the Administrator role.Show less
-
-
Aug 26, 2026
Apr 1, 2025
8.9 HIGH· v4
N/A· v3
N/A· v2
Local privilege escalation through insecure DCOM configuration in Valmet DNA versions prior to C2023. The DCOM object Valmet DNA Engineering has permissions that allow it to run commands as a user with the SeImpersonateP...Show more
Local privilege escalation through insecure DCOM configuration in Valmet DNA versions prior to C2023. The DCOM object Valmet DNA Engineering has permissions that allow it to run commands as a user with the SeImpersonatePrivilege privilege. The SeImpersonatePrivilege privilege is a Windows permission that allows a process to impersonate another user. An attacker can use this vulnerability to escalate their privileges and take complete control of the system.Show less
1Apple
1Macos
Jun 17, 2026
Mar 31, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A user may be able to elevate privileges.
1Adtran
1411 Firmware
Jun 17, 2026
Mar 31, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Adtran 411 ONT vL80.00.0011.M2 allows attackers to escalate privileges via unspecified vectors.