← Back
CWE-269

3,313 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,313)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Aug 19, 2026
Mar 11, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Print Spooler Elevation of Privilege Vulnerability
1Samsung
1Android
Jun 17, 2026
Mar 4, 2021
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.
1Google
1Android
Jun 17, 2026
Mar 4, 2021
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Improper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to acquire notification access via sending a crafted malicious intent.
1Mbconnectline
2Mbconnect24
Mymbconnect24
Jun 17, 2026
Mar 2, 2021
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to kill web2go sessions in the account he should...Show more
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to kill web2go sessions in the account he should not have access to.Show less
2Helmholz
Mbconnectline
4Mbconnect24
Mymbconnect24Myrex24+1 more
Jun 17, 2026
Mar 2, 2021
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot dev...Show more
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices in his account without having corresponding permissions.Show less
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Feb 25, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Event Tracing Elevation of Privilege Vulnerability
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Feb 25, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Kernel Elevation of Privilege Vulnerability
1Microsoft
4Endpoint Protection
Security EssentialsSystem Center Endpoint Protection+1 more
Jun 17, 2026
Feb 25, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Microsoft Defender Elevation of Privilege Vulnerability
1Azure Iot Cli Extension
1
Jun 17, 2026
Feb 25, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Azure IoT CLI extension Elevation of Privilege Vulnerability
1Microsoft
1Psexec
Jun 17, 2026
Feb 25, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Sysinternals PsExec Elevation of Privilege Vulnerability
1Microsoft
1System Center Operations Manager
Jun 17, 2026
Feb 25, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
System Center Operations Manager Elevation of Privilege Vulnerability
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Feb 25, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Installer Elevation of Privilege Vulnerability
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Feb 25, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Win32k Elevation of Privilege Vulnerability
1Cisco
2Aci Multi Site Orchestrator
Application Policy Infrastructure Controller
Jun 17, 2026
Feb 24, 2021
N/A· v4
10.0 CRITICAL· v3
9.3 HIGH· v2
A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. T...Show more
A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to improper token validation on a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to receive a token with administrator-level privileges that could be used to authenticate to the API on affected MSO and managed Cisco Application Policy Infrastructure Controller (APIC) devices.Show less
1Rangerstudio
1Directus
Jun 17, 2026
Feb 23, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: This vulnerability only affects products that are no longer supported by t...Show more
In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: This vulnerability only affects products that are no longer supported by the maintainerShow less
1Collaboraoffice
1Online
Jun 17, 2026
Feb 23, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
"loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" checks, if it was invoked by the "lool" user, and refuses to run with priv...Show more
"loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" checks, if it was invoked by the "lool" user, and refuses to run with privileges, if it's not the case. In the vulnerable version of "loolforkit" this check was wrong, so a normal user could start "loolforkit" and eventually get local root privileges.Show less
1Cisco
1Identity Services Engine
Jun 17, 2026
Feb 17, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information. These vulnerabilities are due to improper enforcement of...Show more
Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information. These vulnerabilities are due to improper enforcement of administrator privilege levels for sensitive data. An attacker with read-only administrator access to the Admin portal could exploit these vulnerabilities by browsing to one of the pages that contains sensitive data. A successful exploit could allow the attacker to collect sensitive information regarding the configuration of the system. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Apache
1Airflow
Jun 17, 2026
Feb 17, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to hit that endpoint. This is low-severity issue as the attacker needs to b...Show more
The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to hit that endpoint. This is low-severity issue as the attacker needs to be aware of certain parameters to pass to that endpoint and even after can just get some metadata about a DAG and a Task. This issue affects Apache Airflow 2.0.0.Show less
1Mcafee
1Web Gateway
Jun 17, 2026
Feb 17, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Privilege escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.8 allows an authenticated user to gain elevated privileges through the User Interface and execute commands on the appliance via incorrect improp...Show more
Privilege escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.8 allows an authenticated user to gain elevated privileges through the User Interface and execute commands on the appliance via incorrect improper neutralization of user input in the troubleshooting page.Show less
1Racom
1M!dge Firmware
Jun 17, 2026
Feb 16, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for privilege escalation via configd.