← Back
CWE-269

3,307 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,307)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Sep 2, 2026
Sep 2, 2026
9.2 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit admin...Show more
Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.Show less
-
-
Sep 3, 2026
Sep 2, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users...Show more
The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted administrator over them.Show less
-
-
Sep 3, 2026
Sep 2, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles...Show more
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities and then escalate it to administrator.Show less
-
-
Sep 3, 2026
Sep 2, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a subscriber-level...Show more
The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a subscriber-level user to gain administrator access after the site owner restores or migrates the site.Show less
-
-
Sep 2, 2026
Sep 2, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 't...Show more
The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when the 'externalId' parameter is set to 0. This makes it possible for unauthenticated attackers to escalate their privileges to administrator by first elevating to the manager role, then creating a provider entity linked to an administrator user ID and overwriting that administrator's password.Show less
1Google
1Chrome
Sep 3, 2026
Sep 2, 2026
N/A· v4
4.2 MEDIUM· v3
N/A· v2
Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security sever...Show more
Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)Show less
1Hpe
1Arubaos Cx
Sep 4, 2026
Sep 1, 2026
N/A· v4
8.2 HIGH· v3
N/A· v2
Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could c...Show more
Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could compromise system integrity and further expose sensitive information.Show less
1Hpe
1Arubaos Cx
Sep 4, 2026
Sep 1, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.
1Hpe
1Arubaos Cx
Sep 4, 2026
Sep 1, 2026
N/A· v4
5.7 MEDIUM· v3
N/A· v2
A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information f...Show more
A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable system.Show less
1Arubanetworks
1Fabric Composer
Sep 2, 2026
Sep 1, 2026
N/A· v4
2.5 LOW· v3
N/A· v2
A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user with local access to elevate their user p...Show more
A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user with local access to elevate their user privileges and make limited modifications on the affected system.Show less
1Arubanetworks
1Fabric Composer
Sep 3, 2026
Sep 1, 2026
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A local privilege escalation vulnerability in HPE Networking Fabric Composer could allow an authenticated privileged user on the underlying host to elevate their user privileges to those of a higher role. A successful ex...Show more
A local privilege escalation vulnerability in HPE Networking Fabric Composer could allow an authenticated privileged user on the underlying host to elevate their user privileges to those of a higher role. A successful exploit allows the attacker to change the state of certain settings of the affected system.Show less
1Arubanetworks
1Fabric Composer
Sep 3, 2026
Sep 1, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vuln...Show more
A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.Show less
1Arubanetworks
1Fabric Composer
Sep 3, 2026
Sep 1, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to upstream AFC dependencies to view sensitive information....Show more
A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to upstream AFC dependencies to view sensitive information. Successful exploitation could allow an attacker to access data beyond what is authorized by the user's existing privilege level, potentially leading to further unauthorized access.Show less
1Arubanetworks
1Fabric Composer
Sep 2, 2026
Sep 1, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root p...Show more
A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges, leading to a complete compromise of the affected host.Show less
1Arubanetworks
1Fabric Composer
Sep 2, 2026
Sep 1, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulne...Show more
Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.Show less
1Arubanetworks
1Fabric Composer
Sep 2, 2026
Sep 1, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-chan...Show more
A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform.Show less
1Arubanetworks
1Fabric Composer
Sep 2, 2026
Sep 1, 2026
N/A· v4
7.6 HIGH· v3
N/A· v2
A sensitive information disclosure vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to access data beyond what is authori...Show more
A sensitive information disclosure vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to access data beyond what is authorized by the user's existing privilege level, potentially leading to further unauthorized access.Show less
1Arubanetworks
1Fabric Composer
Sep 2, 2026
Sep 1, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Local privilege-escalation vulnerabilities have been discovered in HPE Networking Fabric Composer. Successful exploitation of these vulnerabilities could allow a local attacker to achieve arbitrary code execution with ro...Show more
Local privilege-escalation vulnerabilities have been discovered in HPE Networking Fabric Composer. Successful exploitation of these vulnerabilities could allow a local attacker to achieve arbitrary code execution with root privileges on the underlying operating system of the affected system.Show less
1Arubanetworks
1Fabric Composer
Sep 2, 2026
Sep 1, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated remote attacker to gain administrative privileges leading to compl...Show more
A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated remote attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.Show less
-
-
Sep 1, 2026
Sep 1, 2026
5.5 MEDIUM· v4
8.3 HIGH· v3
7.5 HIGH· v2
A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bea...Show more
A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 5.8.1.11 is sufficient to fix this issue. It is recommended to upgrade the affected component.Show less