CWE-269
2,750 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (2,750)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Intel 5Nuc7i3bnh Firmware Nuc7i3bnk FirmwareNuc7i5bnh Firmware+2 moreMay 13, 2026 Oct 11, 2017 N/A· v4 7.5 HIGH· v3 4.4 MEDIUM· v2 Incorrect policy enforcement in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows attackers with local or physical access to bypass enforcement of integrity...Show more |
2Debian X.org2Debian Linux X ServerMay 13, 2026 Oct 10, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 In X.Org Server (aka xserver and xorg-server) before 1.19.4, an attacker authenticated to an X server with the X shared memory extension enabled can cause aborts of the X server or replace shared memory segments of other...Show more |
An Improper Privilege Management issue was discovered in SpiderControl SCADA Web Server Version 2.02.0007 and prior. Authenticated, non-administrative local users are able to alter service executables with escalated priv...Show more |
1Jenkins 1Config File Provider May 13, 2026 Oct 5, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read access to Jenkins were able to access URLs directly that allowed...Show more |
An authentication vulnerability in HPE SiteScope product versions 11.2x and 11.3x, allows read-only accounts to view all SiteScope interfaces and monitors, potentially exposing sensitive data. |
An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch that results in that user gaining elevated privileges. |
An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to issue both delete and index requests agai...Show more |
In all Qualcomm products with Android releases from CAF using the Linux kernel, user-level permissions can be used to gain access to kernel memory, specifically the ION cache maintenance code is writing to a user supplie...Show more |
1Gentoo 1Sci Mathematics Gimps May 13, 2026 Sep 15, 2017 N/A· v4 7.3 HIGH· v3 6.9 MEDIUM· v2 The Gentoo sci-mathematics/gimps package before 28.10-r1 for Great Internet Mersenne Prime Search (GIMPS) allows local users to gain privileges by creating a hard link under /var/lib/gimps, because an unsafe "chown -R" c...Show more |
In eLux RP 5.x before 5.5.1000 LTSR and 5.6.x before 5.6.2 CR when classic desktop mode is used, it is possible to start applications other than defined, even if the user does not have permissions to change application d...Show more |
Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this file is owned by a non-root account (and similarly can have nagios.cfg owned by a non-root account),...Show more |
2Cloudfoundry Pivotal4Cf Release Elastic RuntimeUaa Release+1 moreMay 13, 2026 Sep 7, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allo...Show more |
1Netapp 1Storagegrid Webscale May 13, 2026 Aug 29, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 NetApp StorageGRID Webscale 10.2.x before 10.2.2.3, 10.3.x before 10.3.0.4, and 10.4.x before 10.4.0.2 allow remote authenticated users to delete arbitrary objects via unspecified vectors. |
Privilege escalation in Replibit Backup Manager earlier than version 2017.08.04 allows attackers to gain root privileges via sudo command execution. The vi program can be accessed through sudo, in order to navigate the f...Show more |
1Elasticsearch 2X Pack X Pack ReportingMay 13, 2026 Aug 18, 2017 N/A· v4 5.3 MEDIUM· v3 4.0 MEDIUM· v2 The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report w...Show more |
1Cisco 1Application Policy Infrastructure Controller May 13, 2026 Aug 17, 2017 N/A· v4 7.1 HIGH· v3 4.6 MEDIUM· v2 A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to gain higher privileges than the account is assigned. The attacker will be granted the privileg...Show more |
1Fujielectric 1Monitouch V Sft May 13, 2026 Aug 14, 2017 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 An Improper Privilege Management issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. Monitouch V-SFT is installed in a directory with weak access controls by default, which could all...Show more |
1Oracle 1Hospitality Reporting And Analytics May 13, 2026 Aug 8, 2017 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Mobile Apps). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulne...Show more |
1Oracle 1Java Advanced Management Console May 13, 2026 Aug 8, 2017 N/A· v4 7.4 HIGH· v3 6.5 MEDIUM· v2 Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.6. Easily exploitable vulnerability...Show more |
1Oracle 1Flexcube Private Banking May 13, 2026 Aug 8, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily expl...Show more |