CWE-269
2,750 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (2,750)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Oracle 1Flexcube Universal Banking May 13, 2026 Aug 8, 2017 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3,...Show more |
1Oracle 1Agile Product Lifecycle Management May 13, 2026 Aug 8, 2017 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows low privil...Show more |
1Oracle 1Primavera P6 Enterprise Project Portfolio Management May 13, 2026 Aug 8, 2017 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2 and 16.1. E...Show more |
1Oracle 1Hospitality Reporting And Analytics May 13, 2026 Aug 8, 2017 N/A· v4 7.7 HIGH· v3 4.0 MEDIUM· v2 Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Reporting). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnera...Show more |
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with access to a low-privileged user account to read or write files on the file system of the SiPass in...Show more |
1Abb 2Vsn300 Firmware Vsn300 For React FirmwareMay 13, 2026 Aug 7, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. The web application does not p...Show more |
GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group to add themselves to any project that is inside a subgroup. |
main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this no...Show more |
1Project Hashtopussy 1Hashtopussy May 13, 2026 Jul 27, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Incorrect Access Control vulnerability in Hashtopussy 0.4.0 allows remote authenticated users to execute actions that should only be available for administrative roles, as demonstrated by an action=createVoucher request...Show more |
OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to execute arbitrary OS commands via a crafted request. |
In Moodle 3.x, course creators are able to change system default settings for courses. |
1Intenogroup 1Inteno Router Firmware May 13, 2026 Jul 17, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the "user" password m...Show more |
ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resulting in privilege escalation. ATutor versions 2.2.1 and earlier are vulnerable...Show more |
2Cloudfoundry Pivotal Software3Cloud Foundry Cf Cloud Foundry UaaCloud Foundry Uaa BoshMay 13, 2026 Jul 10, 2017 N/A· v4 6.6 MEDIUM· v3 6.0 MEDIUM· v2 In Cloud Foundry cf-release versions prior to v264; UAA release all versions of UAA v2.x.x, 3.6.x versions prior to v3.6.13, 3.9.x versions prior to v3.9.15, 3.20.x versions prior to v3.20.0, and other versions prior to...Show more |
A vulnerability in the installation procedure for Cisco Prime Network Software could allow an authenticated, local attacker to elevate their privileges to root privileges. More Information: CSCvd47343. Known Affected Rel...Show more |
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary code at the root privilege level on an affected system, because of Incorrect Permissions. More Informa...Show more |
systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended. |
1Ibm 1Sterling B2b Integrator May 13, 2026 Jun 22, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-...Show more |
1Cambium Networks 4Epmp 1000 Firmware Epmp 1000 Hotspot FirmwareEpmp 2000 Firmware+1 moreMay 13, 2026 Jun 21, 2017 N/A· v4 7.6 HIGH· v3 6.5 MEDIUM· v2 An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted, which may allow an attacker to gain access to sensitive information a...Show more |
1Cambium Networks 4Epmp 1000 Firmware Epmp 1000 Hotspot FirmwareEpmp 2000 Firmware+1 moreMay 13, 2026 Jun 21, 2017 N/A· v4 6.8 MEDIUM· v3 6.0 MEDIUM· v2 An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration export, an attacker is able to remotely trigger device configuration backups using specific MIBs. T...Show more |