CWE-269
3,313 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (3,313)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, lead to privilege escalation attacks |
1Cisco 2Jabber Jabber For Mobile PlatformsJun 17, 2026 Dec 11, 2020 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileg...Show more |
1Cisco 2Jabber Jabber For Mobile PlatformsJun 17, 2026 Dec 11, 2020 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileg...Show more |
1Cisco 2Jabber Jabber For Mobile PlatformsJun 17, 2026 Dec 11, 2020 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileg...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Dec 10, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
2Redhat Samba3Enterprise Linux SambaStorageJun 17, 2026 Dec 3, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the att...Show more |
Privilege Escalation vulnerability in Microsoft Windows client McAfee Total Protection (MTP) prior to 16.0.29 allows local users to gain elevated privileges via careful manipulation of a folder by creating a junction lin...Show more |
FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may access some specific files and get the ad...Show more |
A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user to execute code with elevated privileges. |
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.470, backend users with the default "Publisher" system role have acc...Show more |
1Schneider Electric 1Operator Terminal Expert Runtime Jun 17, 2026 Nov 19, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver in...Show more |
1Endress 4Orsg35 Firmware Orsg45 FirmwareRsg35 Firmware+1 moreJun 17, 2026 Nov 19, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-based user interface with a role-based acce...Show more |
1Cisco 2Expressway Telepresence Video Communication ServerJun 17, 2026 Nov 18, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restri...Show more |
1Cisco 1Iot Field Network Director Jun 17, 2026 Nov 18, 2020 N/A· v4 4.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the user management functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to manage user information for users in different domains on an affected system...Show more |
1Cisco 1Iot Field Network Director Jun 17, 2026 Nov 18, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to view lists of users from different domains that are configured on an affected...Show more |
1Cisco 1Iot Field Network Director Jun 17, 2026 Nov 18, 2020 N/A· v4 8.7 HIGH· v3 5.5 MEDIUM· v2 A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is...Show more |
1Citrix 3Virtual Apps And Desktops XenappXendesktopJun 17, 2026 Nov 16, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9 |
lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7. |
An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator per...Show more |
Azure Sphere Elevation of Privilege Vulnerability |