← Back
CWE-269

3,315 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,315)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Jungo
Mitsubishielectric
35Cpu Module Logging Configuration Tool
Cw ConfiguratorData Transfer+32 more
Jun 17, 2026
Jul 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code.
2Jungo
Mitsubishielectric
35Cpu Module Logging Configuration Tool
Cw ConfiguratorData Transfer+32 more
Jun 17, 2026
Jul 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.
2Jungo
Mitsubishielectric
35Cpu Module Logging Configuration Tool
Cw ConfiguratorData Transfer+32 more
Jun 17, 2026
Jul 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.
2Jungo
Mitsubishielectric
35Cpu Module Logging Configuration Tool
Cw ConfiguratorData Transfer+32 more
Jun 17, 2026
Jul 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Denial of Service (DoS).
2Jungo
Mitsubishielectric
35Cpu Module Logging Configuration Tool
Cw ConfiguratorData Transfer+32 more
Jun 17, 2026
Jul 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.
1Dell
1Powerscale Onefs
Jun 17, 2026
Jul 2, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain o...Show more
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain of root-level access.Show less
1Dell
1Powerscale Onefs
Jun 17, 2026
Jul 2, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain o...Show more
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain of root-level access.Show less
1Dell
1Powerscale Onefs
Jun 17, 2026
Jul 2, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to privilege escalation...Show more
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to privilege escalation.Show less
-
-
Jun 17, 2026
Jun 28, 2024
N/A· v4
3.7 LOW· v3
N/A· v2
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file permissions in the `/usr/local/bigbluebutton/core/vendor/b...Show more
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file permissions in the `/usr/local/bigbluebutton/core/vendor/bundle/ruby/2.7.0/gems/resque-2.6.0` directory with the goal of privilege escalation, potentially exposing sensitive information on the server. This issue has been patched in version(s) 2.6.18, 2.7.8 and 3.0.0-alpha.7. Show less
-
-
Jun 17, 2026
Jun 27, 2024
7.3 HIGH· v4
7.8 HIGH· v3
N/A· v2
The XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local privilege escalation.
1Progress
1Whatsup Gold
Jun 17, 2026
Jun 25, 2024
N/A· v4
8.4 HIGH· v3
N/A· v2
In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.InstallController.SetAdminPassword allows local attackers to modify admin's password.
1Wishlistmember
1Wishlist Member X
Jun 17, 2026
Jun 24, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Privilege Management vulnerability in Membership Software WishList Member X allows Privilege Escalation.This issue affects WishList Member X: from n/a before 3.26.7.
1Canonical
2Snapd
Ubuntu Linux
Jun 17, 2026
Jun 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snap...Show more
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snaps into the cgroup of the main daemon within the snap itself when reloading system units. This may grant additional privileges to a container within the snap that were not originally intended.Show less
1Parallels
1Parallels Desktop
Jun 17, 2026
Jun 21, 2024
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with...Show more
Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.Show less
-
-
Jun 17, 2026
Jun 21, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Local privilege escalation vulnerability allowed an attacker to misuse ESET's file operations during a restore operation from quarantine.
1Depicter
1Depicter
Jun 17, 2026
Jun 20, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with contributor...Show more
The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with contributor access and above, to generate a valid nonce for any WordPress action/function. This could be used to invoke functionality that is protected only by nonce checks.Show less
1Unionman
1Jlink Ax1800 Firmware
Jul 9, 2026
Jun 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure Permissions vulnerability in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to escalate privileges via a crafted command.
-
-
Jun 17, 2026
Jun 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal without authentication.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Jun 14, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Jun 14, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.