← Back
CWE-269

3,315 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,315)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
4Windows 10
Windows Server 2016Windows Server 2019+1 more
Aug 10, 2026
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Win32k Elevation of Privilege Vulnerability
1Microsoft
7Windows 10
Windows 8.1Windows Rt 8.1+4 more
Aug 10, 2026
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows SMB Elevation of Privilege Vulnerability
1Microsoft
4Windows 10
Windows Server 2016Windows Server 2019+1 more
Aug 10, 2026
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability
1Microsoft
2Windows 7
Windows Server 2008
Aug 10, 2026
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows DNS Elevation of Privilege Vulnerability
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Aug 10, 2026
Sep 15, 2021
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Aug 10, 2026
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Subsystem for Linux Elevation of Privilege Vulnerability
1Microsoft
9Windows 10
Windows 7Windows 8.1+6 more
Aug 10, 2026
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Event Tracing Elevation of Privilege Vulnerability
1Microsoft
9Windows 10
Windows 7Windows 8.1+6 more
Aug 10, 2026
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Common Log File System Driver Elevation of Privilege Vulnerability
1Microsoft
4Windows 10
Windows Server 2016Windows Server 2019+1 more
Aug 10, 2026
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Bind Filter Driver Elevation of Privilege Vulnerability
1Siemens
1Teamcenter Visualization
Jun 17, 2026
Sep 14, 2021
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). Th...Show more
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The "surrogate" functionality on the user profile of the application does not perform sufficient access control that could lead to an account takeover. Any profile on the application can perform this attack and access any other user assigned tasks via the "inbox/surrogate tasks".Show less
1Siemens
10Ruggedcom Rox Mx5000 Firmware
Ruggedcom Rox Rx1400 FirmwareRuggedcom Rox Rx1500 Firmware+7 more
Jun 17, 2026
Sep 14, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCOM ROX RX1500 (All versions < V2.14.1), RUGGEDCOM ROX RX1501 (All versions < V2....Show more
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCOM ROX RX1500 (All versions < V2.14.1), RUGGEDCOM ROX RX1501 (All versions < V2.14.1), RUGGEDCOM ROX RX1510 (All versions < V2.14.1), RUGGEDCOM ROX RX1511 (All versions < V2.14.1), RUGGEDCOM ROX RX1512 (All versions < V2.14.1), RUGGEDCOM ROX RX1524 (All versions < V2.14.1), RUGGEDCOM ROX RX1536 (All versions < V2.14.1), RUGGEDCOM ROX RX5000 (All versions < V2.14.1). The command line interface of affected devices insufficiently restrict file read and write operations for low privileged users. This could allow an authenticated remote attacker to escalate privileges and gain root access to the device.Show less
1Apache
1Airflow
Jun 17, 2026
Sep 9, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in...Show more
The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.Show less
1Apple
6Ipados
Iphone OsMac Os X+3 more
Jun 17, 2026
Sep 8, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3....Show more
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local attacker may be able to elevate their privileges.Show less
1Apple
1Macos
Jun 17, 2026
Sep 8, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3. A local attacker may be able to elevate their privileges.
1Apple
6Ipados
Iphone OsMac Os X+3 more
Jun 17, 2026
Sep 8, 2021
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3....Show more
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to execute arbitrary code with kernel privileges.Show less
1Apple
2Mac Os X
Macos
Jun 17, 2026
Sep 8, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A local attacker may be able to elevate their privil...Show more
The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A local attacker may be able to elevate their privileges.Show less
1Apple
3Ipados
Iphone OsTvos
Jun 17, 2026
Sep 8, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.5 and iPadOS 14.5, tvOS 14.5. A local user may be able to create or modify privileged files.
1Apple
6Ipados
Iphone OsMac Os X+3 more
Jun 17, 2026
Sep 8, 2021
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A validation issue was addressed with improved logic. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A mal...Show more
A validation issue was addressed with improved logic. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to gain root privileges.Show less
1Owncloud
1Owncloud
Jun 17, 2026
Sep 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions.
1Ghost
1Ghost
Jun 17, 2026
Sep 3, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authenticated users (including contributors) to view admin-level API keys via...Show more
Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authenticated users (including contributors) to view admin-level API keys via the integrations API endpoint, leading to a privilege escalation vulnerability. This issue is patched in Ghost version 4.10.0. As a workaround, disable all non-Administrator accounts to prevent API access. It is highly recommended to regenerate all API keys after patching or applying the workaround.Show less