← Back
CWE-269

3,315 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,315)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1H3c
11Secpath F100 C G3 Firmware
Secpath F500 6gw FirmwareSecpath F5010 Firmware+8 more
Jun 17, 2026
Dec 27, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
h3c firewall <= 3.10 ESS6703 has a privilege bypass vulnerability.
1Enlightenment
1Enlightenment
Jun 17, 2026
Dec 25, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the system library function mishandles pathnames that begin with a /dev/.. substring.
1Ibm
2Aix
Vios
Jun 17, 2026
Dec 23, 2022
N/A· v4
8.4 HIGH· v3
N/A· v2
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache_file command to obtain root privileges. IBM X-Force ID: 236690.
1Microfocus
1Zenworks
Jun 17, 2026
Dec 23, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
A vulnerability has been identified in Micro Focus ZENworks 2020 Update 3a and prior versions. This vulnerability allows administrators with rights to perform actions (e.g., install a bundle) on a set of managed devices,...Show more
A vulnerability has been identified in Micro Focus ZENworks 2020 Update 3a and prior versions. This vulnerability allows administrators with rights to perform actions (e.g., install a bundle) on a set of managed devices, to be able to exercise these rights on managed devices in the ZENworks zone but which are outside the scope of the administrator. This vulnerability does not result in the administrators gaining additional rights on the managed devices, either in the scope or outside the scope of the administrator.Show less
1Usememos
1Memos
Jun 17, 2026
Dec 23, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.
1Proofpoint
1Enterprise Protection
Jun 17, 2026
Dec 21, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions. This affects all versions 8.19.0 and below.
1Redhat
1Openstack
Jun 17, 2026
Dec 21, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead...Show more
A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.Show less
1Openstack
1Kolla
Jun 17, 2026
Dec 21, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.
1Wfs
1Heaven Burns Red
Jun 17, 2026
Dec 20, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
wfshbr64.sys and wfshbr32.sys specially crafted IOCTL allows arbitrary user to perform local privilege escalation
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Dec 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions.
1Vmware
1Vrealize Operations
Jun 17, 2026
Dec 16, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.
1Apple
4Ipados
Iphone OsMacos+1 more
Jun 17, 2026
Dec 15, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use a...Show more
A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.Show less
1Apple
4Ipados
Iphone OsTvos+1 more
Jun 17, 2026
Dec 15, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2, watchOS 9.2. A user may be able to elevate privileges.
1Microsoft
5Windows 10
Windows 11Windows Server 2019+2 more
Jun 17, 2026
Dec 13, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
1Secomea
12Sitemanager 1129 Firmware
Sitemanager 1139 FirmwareSitemanager 1149 Firmware+9 more
Jun 17, 2026
Dec 13, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.
1Sap
1Business Planning And Consolidation
Jun 17, 2026
Dec 13, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By impl...Show more
In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By implementing such transaction code, a malicious user may execute unauthorized transaction functionality. Under specific circumstances, a successful attack could enable an adversary to escalate their privileges to be able to read, change or delete system data.Show less
1Ikus Soft
1Rdiffweb
Jun 17, 2026
Dec 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2.
1Hpe
9Hf20 Firmware
Hf20c FirmwareHf20h Firmware+6 more
Jun 17, 2026
Dec 12, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.
1Hp
2Command Center
Omen Gaming Hub
Jun 17, 2026
Dec 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A potential security vulnerability has been identified in OMEN Gaming Hub and in HP Command Center which may allow escalation of privilege and/or denial of service. HP has released software updates to mitigate the potent...Show more
A potential security vulnerability has been identified in OMEN Gaming Hub and in HP Command Center which may allow escalation of privilege and/or denial of service. HP has released software updates to mitigate the potential vulnerability.Show less
1Devolutions
1Remote Desktop Manager
Jun 17, 2026
Dec 12, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated user to spoof a privileged account.