← Back
CWE-269

3,315 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,315)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ofcms Project
1Ofcms
Jun 17, 2026
Mar 16, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.
1Opendoas Project
1Opendoas
Jun 17, 2026
Mar 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTE: TIOCSTI is unavailable in OpenBSD 6.0 and later, and can be made unavailable i...Show more
OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTE: TIOCSTI is unavailable in OpenBSD 6.0 and later, and can be made unavailable in the Linux kernel 6.2 and later.Show less
1Minio
1Minio
Jun 17, 2026
Mar 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Minio is a Multi-Cloud Object Storage framework. Starting with RELEASE.2020-12-23T02-24-12Z and prior to RELEASE.2023-03-13T19-46-17Z, a user with `consoleAdmin` permissions can potentially create a user that matches the...Show more
Minio is a Multi-Cloud Object Storage framework. Starting with RELEASE.2020-12-23T02-24-12Z and prior to RELEASE.2023-03-13T19-46-17Z, a user with `consoleAdmin` permissions can potentially create a user that matches the root credential `accessKey`. Once this user is created successfully, the root credential ceases to work appropriately. The issue is patched in RELEASE.2023-03-13T19-46-17Z. There are ways to work around this via adding higher privileges to the disabled root user via `mc admin policy set`.Show less
1Microsoft
10Windows 10 1507
Windows 10 1607Windows 10 1809+7 more
Jun 17, 2026
Mar 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Accounts Picture Elevation of Privilege Vulnerability
1Ibexa
3Digital Experience Platform
Ez PlatformEz Platform Kernel
Jun 17, 2026
Mar 12, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges.
1Trendmicro
1Apex One
Jun 17, 2026
Mar 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated privileges and create arbitrary directories with arbitrary ownership.
1Fortinet
1Fortinac
Jun 17, 2026
Mar 7, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6, FortiNAC version 9.1.0 through 9.1.8, FortiNAC all versions 8.8, FortiNAC all versions 8.7, FortiNAC...Show more
A improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6, FortiNAC version 9.1.0 through 9.1.8, FortiNAC all versions 8.8, FortiNAC all versions 8.7, FortiNAC all versions 8.6, FortiNAC all versions 8.5, FortiNAC version 8.3.7 allows attacker to escalation of privilege via specially crafted commands.Show less
1Zohocorp
4Manageengine Assetexplorer
Manageengine Servicedesk PlusManageengine Servicedesk Plus Msp+1 more
Jun 17, 2026
Mar 6, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports.
2Debian
Systemd Project
2Debian Linux
Systemd
Jun 17, 2026
Mar 3, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not...Show more
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output.Show less
1Starsoftcomm
1Coocare
Jun 17, 2026
Mar 3, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
starsoftcomm CooCare 5.304 allows local attackers to escalate privileges and execute arbitrary commands via a crafted file upload.
1Xwiki
1Xwiki
Jun 17, 2026
Mar 2, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author o...Show more
XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by annotating the document. This has been patched in XWiki 13.10.11, 14.4.7 and 14.10. There is no easy workaround except to upgrade.Show less
1Thingsboard
1Thingsboard
Jul 9, 2026
Mar 1, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and become an Administrator (TENANT_ADMIN) or (SYS_ADMIN) on the web application. It...Show more
An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and become an Administrator (TENANT_ADMIN) or (SYS_ADMIN) on the web application. It is important to note that in order to accomplish this, the attacker must know the corresponding API's parameter (authority : value).Show less
1Amd
1Ryzen Master
Jun 17, 2026
Mar 1, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentially leading to privilege escalation and code execution by the lower privileged us...Show more
Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentially leading to privilege escalation and code execution by the lower privileged user. Show less
1Apple
1Macos
Jun 17, 2026
Feb 27, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey 12.6.3. An app may be able to gain root privileges.
1Apple
3Ipados
Iphone OsTvos
Jun 17, 2026
Feb 27, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
This issue was addressed with improved checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.
1Apple
1Macos
Jun 17, 2026
Feb 27, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6, macOS Big Sur 11.7. An app may be able to gain elevated privileges.
1Huawei
1Hilink Ai Life
Jun 17, 2026
Feb 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.
1Huawei
1Hilink Ai Life
Jun 17, 2026
Feb 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.
1Thingsboard
1Thingsboard
Jun 17, 2026
Feb 23, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by modifying the scope via the scopes parame...Show more
ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by modifying the scope via the scopes parameter.Show less
1Ibm
1Db2
Jun 17, 2026
Feb 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a specially crafted table access is used. IBM X-Force ID: 241671.