CWE-269
3,315 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (3,315)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 5Windows 10 Windows 11Windows Server 2016+2 moreJun 17, 2026 Aug 9, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Partition Management Driver Elevation of Privilege Vulnerability |
1Microsoft 5Windows 10 Windows 11Windows Server 2016+2 moreJun 17, 2026 Aug 9, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Win32k Elevation of Privilege Vulnerability |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreJun 17, 2026 Aug 9, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Active Directory Domain Services Elevation of Privilege Vulnerability |
Azure Batch Node Agent Elevation of Privilege Vulnerability |
1Microsoft 2Open Management Infrastructure System Center Operations ManagerJun 17, 2026 Aug 9, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability |
Improper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5.04.8 in Android 11 and above allows local attacker to execute hidden function for developer by chan...Show more |
An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 Aug 4, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.5.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypa...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 Aug 4, 2022 N/A· v4 6.7 MEDIUM· v3 N/A· v2 In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, certain iRules commands may allow an attacker to bypass the access control re...Show more |
fof/byobu is a private discussions extension for Flarum forum. Affected versions were found to not respect private discussion disablement by users. Users of Byobu should update the extension to version 1.1.7, where this...Show more |
1Simple Membership Plugin 1Simple Membership Jun 17, 2026 Aug 1, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due to insufficient checking of a user supplied parameter. |
1Simple Membership Plugin 1Simple Membership Jun 17, 2026 Aug 1, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing members to escalate to a higher membership level by using a crafted POST requ...Show more |
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provider types. IBM X-Force ID: 229962. |
Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin privileges over the network. These APIs were consumed in the SF Mobile...Show more |
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI comman...Show more |
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI comman...Show more |
An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.10 may allow a local attacker to perform an arbitrar...Show more |
1Zyxel 25Atp100 Firmware Atp100w FirmwareAtp200 Firmware+22 moreJun 17, 2026 Jul 19, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 t...Show more |
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Jul 18, 2022 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their...Show more |
1Schneider Electric 2Acti9 Powertag Link C (a9xelc10 A) Firmware Acti9 Powertag Link C (a9xelc10 B) FirmwareJun 17, 2026 Jul 13, 2022 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing credentials. Affected Products: Acti9 PowerTag Link C (A9XELC10-A) (V1.7.5 and prior), Acti9 PowerTag Li...Show more |