← Back
CWE-269

3,323 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,323)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Printerlogic
2Vasion Print
Virtual Appliance
Jun 17, 2026
Mar 5, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Privilege Escalation V-2024-015.
-
-
Jun 17, 2026
Mar 4, 2025
4.7 MEDIUM· v4
N/A· v3
N/A· v2
A Sudo privilege misconfiguration vulnerability in PocketBook InkPad Color 3 on Linux, ARM allows attackers to read file contents on the device.This issue affects InkPad Color 3: U743k3.6.8.3671.
-
-
Jun 17, 2026
Mar 4, 2025
8.6 HIGH· v4
N/A· v3
N/A· v2
A privilege escalation vulnerability in PocketBook InkPad Color 3 allows attackers to escalate to root privileges if they gain physical access to the device. This issue affects InkPad Color 3 in version U743k3.6.8.3671.
1Apache
1Streampipes
Jun 17, 2026
Mar 3, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: through 0.95.1. Users are recommended...Show more
Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: through 0.95.1. Users are recommended to upgrade to version 0.97.0 which fixes the issue.Show less
1Sitesao
1Dhvc Form
Jun 17, 2026
Feb 28, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it p...Show more
The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on sites.Show less
1Infoblox
1Nios
Jun 17, 2026
Feb 27, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Infoblox NIOS through 8.6.4 executes with more privileges than required.
-
-
Jun 17, 2026
Feb 27, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
The Templines Elementor Helper Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.7. This is due to allowing arbitrary user meta updates. This makes it possible for au...Show more
The Templines Elementor Helper Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.7. This is due to allowing arbitrary user meta updates. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their role to Administrator. The vulnerability can only be exploited when the BuddyPress plugin is also installed and activated.Show less
1Bricksbuilder
1Bricks
Jun 17, 2026
Feb 27, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
The Bricks theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.6.1. This is due to insufficient validation checks placed on the create_autosave AJAX function. This makes it...Show more
The Bricks theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.6.1. This is due to insufficient validation checks placed on the create_autosave AJAX function. This makes it possible for authenticated attackers, with contributor-level access and above, to execute arbitrary PHP code with elevated (administrator-level) privileges. NOTE: Successful exploitation requires (1) the Bricks Builder to be enabled for posts (2) Builder access to be enabled for contributor-level users, and (3) "Code Execution" to be enabled for administrator-level users within the theme's settings.Show less
1Hcltech
1Dryice Mycloud
Jun 17, 2026
Feb 25, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure and potential for Server-Side Request Forgery (SSRF) and Denial of Servi...Show more
HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure and potential for Server-Side Request Forgery (SSRF) and Denial of Service(DOS) attacks from unauthenticated users.Show less
1Citrix
2Netscaler Agent
Netscaler Console
Jun 17, 2026
Feb 20, 2025
8.8 HIGH· v4
8.8 HIGH· v3
N/A· v2
Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.
-
-
Jun 17, 2026
Feb 19, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Symantec Diagnostic Tool (SymDiag), prior to 3.0.79, may be susceptible to a Privilege Escalation vulnerability.
-
-
Jun 17, 2026
Feb 14, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from status code 500 to status code 200.
-
-
Jun 17, 2026
Feb 13, 2025
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Int...Show more
CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when an attacker with standard privilege modifies the executable path of the windows services. To be exploited, services need to be restarted.Show less
1Easyappointments
1Easy!appointments
Jun 17, 2026
Feb 12, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.
-
-
Jun 17, 2026
Feb 11, 2025
N/A· v4
3.8 LOW· v3
N/A· v2
An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (Bring Your Own Vulnerable Driver) attack.
-
-
Jun 17, 2026
Feb 11, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
A DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
1Alembic
1Ash Authentication
Jun 17, 2026
Feb 11, 2025
6.3 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present since AshAuthentication v4.1.0 and who have used the magic link strate...Show more
Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present since AshAuthentication v4.1.0 and who have used the magic link strategy _or_ are manually revoking tokens are affected by revoked tokens being allowed to verify as valid. Unless one hase implemented any kind of custom token revocation feature in your application, then one will not be affected. The impact here for users using builtin functionality is that magic link tokens are reusable until they expire. With that said, magic link tokens are only valid for 10 minutes, so the surface area for abuse is extremely low here. The flaw is patched in version 4.4.9. Additionally a compile time warning is shown to users with remediation instructions if they upgrade. 4.4.9 ships with an upgrader, so those who use `mix igniter.upgrade ash_authentication` will have the necessary patch applied. Otherwise, one may run the upgrader manually as described in the error message. As a workaround, delete the generated `:revoked?` generic action in the token resource. This will cause it to use the one internal to Ash Authentication which has always been correct. Alternatively, manually make the changes that are included in the patch.Show less
-
-
Jun 17, 2026
Feb 11, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. This is due to the plugin not properly restricting what user meta can be updated during profile regi...Show more
The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible for unauthenticated attackers to register on the site as an administrator.Show less
-
-
Jun 17, 2026
Feb 6, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to conduct a privilege escalation attack due to the execution of...Show more
The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. A successful exploit could allow an attacker to execute arbitrary commands with elevated privileges.Show less
1Opensecurity
1Mobile Security Framework
Jun 17, 2026
Feb 5, 2025
8.5 HIGH· v4
5.5 MEDIUM· v3
N/A· v2
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to make...Show more
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to make use of an access token for materials for scopes which it should not be accepted. This issue has been addressed in version 4.3.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.Show less