CWE-269
3,315 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (3,315)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default value. This could lead to local escalation of privilege with no ad...Show more |
1Google 4Home Firmware Home Mini FirmwareNest Audio Firmware+1 moreJun 17, 2026 Jan 2, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege
|
The V8 inspector intentionally allows arbitrary code execution within the Workers sandbox for debugging. wrangler dev would previously start an inspector server listening on all network interfaces. This would allow an at...Show more |
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
|
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
|
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
|
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
|
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions
|
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. |
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
|
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
|
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
|
MeterSphere is a one-stop open source continuous testing platform. Prior to 2.10.10-lts, the authenticated attackers can update resources which don't belong to him if the resource ID is known. This issue if fixed in 2.10...Show more |
A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client...Show more |
1Amazon 1Awslabs Sandbox Accounts For Events Jun 17, 2026 Dec 22, 2023 N/A· v4 3.3 LOW· v3 N/A· v2 Sandbox Accounts for Events provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially read data from the events table by se...Show more |
Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must have already existed in the target repo. This vulnerability affected all...Show more |
Improper privilege management in all versions of GitHub Enterprise Server allows users with authorized access to the management console with an editor role to escalate their privileges by making requests to the endpoint...Show more |
1Thegreenbow 1Thegreenbow Vpn Client Jun 17, 2026 Dec 19, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and Windows Enterprise VPN Client 6.87 allows attackers to gain escalated privileges via crafted changes...Show more |
An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage. |
1Beyondtrust 1Privilege Management For Windows Jun 17, 2026 Dec 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and specifying that it runs at medium integrity with the user owning the process, this se...Show more |