← Back
CWE-269

3,313 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,313)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Citrix
1Gateway Plug In
Jun 17, 2026
Dec 14, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, lead to privilege escalation attacks
1Cisco
2Jabber
Jabber For Mobile Platforms
Jun 17, 2026
Dec 11, 2020
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileg...Show more
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
2Jabber
Jabber For Mobile Platforms
Jun 17, 2026
Dec 11, 2020
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileg...Show more
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
2Jabber
Jabber For Mobile Platforms
Jun 17, 2026
Dec 11, 2020
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileg...Show more
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Dec 10, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
2Redhat
Samba
3Enterprise Linux
SambaStorage
Jun 17, 2026
Dec 3, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the att...Show more
A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.Show less
1Mcafee
1Total Protection
Jun 17, 2026
Dec 1, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Privilege Escalation vulnerability in Microsoft Windows client McAfee Total Protection (MTP) prior to 16.0.29 allows local users to gain elevated privileges via careful manipulation of a folder by creating a junction lin...Show more
Privilege Escalation vulnerability in Microsoft Windows client McAfee Total Protection (MTP) prior to 16.0.29 allows local users to gain elevated privileges via careful manipulation of a folder by creating a junction link. This exploits a lack of protection through a timing issue and is only exploitable in a small time window.Show less
1Huawei
1Fusioncompute
Jun 17, 2026
Dec 1, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may access some specific files and get the ad...Show more
FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may access some specific files and get the administrator privilege in the affected products. Successful exploit will cause privilege escalation.Show less
1Lenovo
1Pcmanager
Jun 17, 2026
Nov 30, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user to execute code with elevated privileges.
1Octobercms
1October
Jun 17, 2026
Nov 23, 2020
N/A· v4
4.2 MEDIUM· v3
4.6 MEDIUM· v2
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.470, backend users with the default "Publisher" system role have acc...Show more
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.470, backend users with the default "Publisher" system role have access to create & manage users where they can choose which role the new user has. This means that a user with "Publisher" access has the ability to escalate their access to "Developer" access. Issue has been patched in Build 470 (v1.0.470) & v1.1.1.Show less
1Schneider Electric
1Operator Terminal Expert Runtime
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver in...Show more
A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator Terminal Expert.Show less
1Endress
4Orsg35 Firmware
Orsg45 FirmwareRsg35 Firmware+1 more
Jun 17, 2026
Nov 19, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-based user interface with a role-based acce...Show more
Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-based user interface with a role-based access system. Users with different roles have different write and read privileges. The access system is based on dynamic "tokens". The vulnerability is that user sessions are not closed correctly and a user with fewer rights is assigned the higher rights when he logs on.Show less
1Cisco
2Expressway
Telepresence Video Communication Server
Jun 17, 2026
Nov 18, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restri...Show more
A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restricted destinations. The vulnerability is due to improper validation of specific connection information by the TURN server within the affected software. An attacker could exploit this issue by sending specially crafted network traffic to the affected software. A successful exploit could allow the attacker to send traffic through the affected software to destinations beyond the application, possibly allowing the attacker to gain unauthorized network access.Show less
1Cisco
1Iot Field Network Director
Jun 17, 2026
Nov 18, 2020
N/A· v4
4.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the user management functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to manage user information for users in different domains on an affected system...Show more
A vulnerability in the user management functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to manage user information for users in different domains on an affected system. The vulnerability is due to improper domain access control. An attacker could exploit this vulnerability by manipulating JSON payloads to target different domains on an affected system. A successful exploit could allow the attacker to manage user information for users in different domains on an affected system.Show less
1Cisco
1Iot Field Network Director
Jun 17, 2026
Nov 18, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to view lists of users from different domains that are configured on an affected...Show more
A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to view lists of users from different domains that are configured on an affected system. The vulnerability is due to improper access control. An attacker could exploit this vulnerability by sending an API request that alters the domain for a requested user list on an affected system. A successful exploit could allow the attacker to view lists of users from different domains on the affected system.Show less
1Cisco
1Iot Field Network Director
Jun 17, 2026
Nov 18, 2020
N/A· v4
8.7 HIGH· v3
5.5 MEDIUM· v2
A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is...Show more
A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is due to insufficient authorization in the SOAP API. An attacker could exploit this vulnerability by sending SOAP API requests to affected devices for devices that are outside their authorized domain. A successful exploit could allow the attacker to access and modify information on devices that belong to a different domain.Show less
1Citrix
3Virtual Apps And Desktops
XenappXendesktop
Jun 17, 2026
Nov 16, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9
1Rconfig
1Rconfig
Jun 17, 2026
Nov 13, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Nov 12, 2020
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator per...Show more
An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator performs a context switch into that device. This vulnerability allows an attacker to gain privileged access to the Panorama web interface. An attacker requires some knowledge of managed firewalls to exploit this issue. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.17; PAN-OS 9.0 versions earlier than PAN-OS 9.0.11; PAN-OS 9.1 versions earlier than PAN-OS 9.1.5.Show less
1Microsoft
1Azure Sphere
Jun 17, 2026
Nov 11, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Azure Sphere Elevation of Privilege Vulnerability