← Back
CWE-269

3,314 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,314)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Securepoint
1Openvpn Client
Jun 17, 2026
Jun 28, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration st...Show more
Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under "%APPDATA%\Securepoint SSL VPN" and add a external script file that is executed as privileged user.Show less
1Weidmueller
8Ie Wl Bl Ap Cl Eu Firmware
Ie Wl Bl Ap Cl Us FirmwareIe Wl Vl Ap Br Cl Eu Firmware+5 more
Jun 17, 2026
Jun 25, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settings functionality. A specially crafted user name entry can cause the ove...Show more
In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settings functionality. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.Show less
1Remotemouse
1Emote Interactive Studio
Jun 17, 2026
Jun 24, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder feature to navigate to cmd.exe. It binds to local ports to listen for inc...Show more
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder feature to navigate to cmd.exe. It binds to local ports to listen for incoming connections.Show less
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Jun 24, 2021
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update s...Show more
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. *Note: This issue only affected Windows operating systems older than Win 10 build 1709. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.10.1, Firefox < 87, and Firefox ESR < 78.10.1.Show less
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Jun 24, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Fi...Show more
If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.Show less
1Avaya
1Aura Utility Services
Jun 17, 2026
Jun 24, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Affects all 7.x versions of Avaya Aura Utility Services
1Avaya
1Aura Utility Services
Jun 17, 2026
Jun 24, 2021
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user. Affects all 7.x versions of Avaya Aura...Show more
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user. Affects all 7.x versions of Avaya Aura Utility ServicesShow less
1Synology
1Download Station
Jun 17, 2026
Jun 18, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors.
1Zoll
1Defibrillator Dashboard
Jun 17, 2026
Jun 16, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilege user to escalate privileges to an administrative level user.
1Samsung
1Internet
Jun 17, 2026
Jun 11, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activity in specific condition.
1Qnap
1Helpdesk
Jun 17, 2026
Jun 11, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise the security of the software. This issue affects: QNAP Systems Inc. He...Show more
An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise the security of the software. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.4.Show less
1Mcafee
1Agent
Jun 17, 2026
Jun 10, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Improper privilege management vulnerability in McAfee Agent for Windows prior to 5.7.3 allows a local user to modify event information in the MA event folder. This allows a local user to either add false events or remove...Show more
Improper privilege management vulnerability in McAfee Agent for Windows prior to 5.7.3 allows a local user to modify event information in the MA event folder. This allows a local user to either add false events or remove events from the event logs prior to them being sent to the ePO server.Show less
1Intel
1Computing Improvement Program
Jun 17, 2026
Jun 9, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Incorrect default privileges in the Intel(R) Computing Improvement Program before version 2.4.6522 may allow an authenticated user to potentially enable an escalation of privilege via local access.
1Raspap
1Raspap
Jun 17, 2026
Jun 9, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /installers/common.sh component that can result in remote command executio...Show more
Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /installers/common.sh component that can result in remote command execution with root privileges.Show less
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Jun 8, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Jun 8, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Windows Common Log File System Driver Elevation of Privilege Vulnerability
1Johnsoncontrols
1Metasys
Jun 17, 2026
Jun 4, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically craft...Show more
Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system. This issue affects: Johnson Controls Metasys version 11.0 and prior versions.Show less
1Qemu
1Qemu
Nov 21, 2024
May 28, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary co...Show more
An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.Show less
3Netapp
OracleVmware
32Commerce Guided Search
Communications Brm Elastic Charging EngineCommunications Cloud Native Core Binding Support Function+29 more
Jun 17, 2026
May 27, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticat...Show more
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.Show less
1Schneider Electric
2Homelynk Firmware
Spacelynk Firmware
Jun 17, 2026
May 26, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unauthorized code is loaded into the system folder.