← Back
CWE-269

3,314 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,314)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xscreensaver Project
1Xscreensaver
Jun 17, 2026
Apr 21, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Debian xscreensaver 5.42+dfsg1-1 package for XScreenSaver has cap_net_raw enabled for the /usr/libexec/xscreensaver/sonar file, which allows local users to gain privileges because this is arguably incompatible with t...Show more
The Debian xscreensaver 5.42+dfsg1-1 package for XScreenSaver has cap_net_raw enabled for the /usr/libexec/xscreensaver/sonar file, which allows local users to gain privileges because this is arguably incompatible with the design of the Mesa 3D Graphics library dependency.Show less
3Fedoraproject
RedhatSamba
3Cifs Utils
Enterprise LinuxFedora
Jun 17, 2026
Apr 19, 2021
N/A· v4
6.1 MEDIUM· v3
4.9 MEDIUM· v2
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data...Show more
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.Show less
1Broadcom
1Vmware Nsx T Data Center
Jun 17, 2026
Apr 19, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
VMware NSX-T contains a privilege escalation vulnerability due to an issue with RBAC (Role based access control) role assignment. Successful exploitation of this issue may allow attackers with local guest user account to...Show more
VMware NSX-T contains a privilege escalation vulnerability due to an issue with RBAC (Role based access control) role assignment. Successful exploitation of this issue may allow attackers with local guest user account to assign privileges higher than their own permission level.Show less
1Curveballjs
1A12n Server
Jun 17, 2026
Apr 16, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow editing users in version 0.18.0. This feature should only have been accessible to admins. Unfortunatel...Show more
a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow editing users in version 0.18.0. This feature should only have been accessible to admins. Unfortunately, privileges were incorrectly checked allowing any logged in user to make this change. Patched in v0.18.2.Show less
1Mendix
1Mendix
Jun 17, 2026
Apr 16, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications using Mendix 8 (All versions < V8.17.0), Mendix Applications using Mendix 8 (V8.12) (All versions <...Show more
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications using Mendix 8 (All versions < V8.17.0), Mendix Applications using Mendix 8 (V8.12) (All versions < V8.12.5), Mendix Applications using Mendix 8 (V8.6) (All versions < V8.6.9), Mendix Applications using Mendix 9 (All versions < V9.0.5). Authenticated, non-administrative users could modify their privileges by manipulating the user role under certain circumstances, allowing them to gain administrative privileges.Show less
1Mcafee
1Data Loss Prevention Endpoint
Jun 17, 2026
Apr 15, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to write to arbitrary controlled kernel addresses. This is achieved...Show more
Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to write to arbitrary controlled kernel addresses. This is achieved by launching applications, suspending them, modifying the memory and restarting them when they are monitored by McAfee DLP through the hdlphook driver.Show less
1Zulip
1Zulip Server
Jun 17, 2026
Apr 15, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being able to receive message traffic to public streams that should have been...Show more
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being able to receive message traffic to public streams that should have been only accessible to members of the organization.Show less
1Zulip
1Zulip Server
Jun 17, 2026
Apr 15, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (previously is_api_super_user) resulted in users with this permission being able to send messages appeari...Show more
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (previously is_api_super_user) resulted in users with this permission being able to send messages appearing as if sent by a system bot, including to other organizations hosted by the same Zulip installation.Show less
1Pi Hole
1Pi Hole
Jun 17, 2026
Apr 14, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security...Show more
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security advisory for details.Show less
1Microsoft
6Visual Studio
Visual Studio 2017Visual Studio 2019+3 more
Jun 17, 2026
Apr 13, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability
1Microsoft
6Visual Studio
Visual Studio 2017Visual Studio 2019+3 more
Jun 17, 2026
Apr 13, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability
1Pega
1Pega Platform
Jun 17, 2026
Apr 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.
1Samsung
1Experience Service
Jun 17, 2026
Apr 9, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to execute privileged action.
1Google
1Android
Jun 17, 2026
Apr 9, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the API in softsimd.
1Google
1Android
Jun 17, 2026
Apr 9, 2021
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to access running processesdelete some local files.
1Google
1Android
Jun 17, 2026
Apr 9, 2021
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to delete certain local files.
1Sonicwall
11Email Security
Email Security Appliance 3300 FirmwareEmail Security Appliance 4300 Firmware+8 more
Aug 12, 2026
Apr 9, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
3Debian
FedoraprojectMediawiki
3Debian Linux
FedoraMediawiki
Jun 17, 2026
Apr 9, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently hav...Show more
An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently have permissions for.Show less
1Litespeedtech
1Openlitespeed
Jun 17, 2026
Apr 7, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execute commands on the host system.
1Mongodb
1Compass
Jun 17, 2026
Apr 6, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This issue affects: MongoDB...Show more
A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This issue affects: MongoDB Inc. MongoDB Compass 1.x version 1.3.0 on Windows and later versions; 1.x versions prior to 1.25.0 on Windows.Show less