← Back
CWE-269

3,313 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,313)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6Canonical
DebianFedoraproject+3 more
6Bind
Debian LinuxFedora+3 more
Jun 17, 2026
Aug 21, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has...Show more
In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to change a specific subset of the zone's content could abuse these unintended additional privileges to update other contents of the zone.Show less
1Sierrawireless
1Aleos
Jun 17, 2026
Aug 21, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the command shell.
1Sintef
1Urx
Jun 17, 2026
Aug 21, 2020
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operation...Show more
Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operations as demonstrated in our video. In our PoC we demonstrate how a malicious actor could 'cook' a custom URCap that when deployed by the user (intendedly or unintendedly) compromises the systemShow less
1Mcafee
1Total Protection
Jun 17, 2026
Aug 21, 2020
N/A· v4
6.9 MEDIUM· v3
3.3 LOW· v2
Privilege Escalation vulnerability in the installer in McAfee McAfee Total Protection (MTP) trial prior to 4.0.161.1 allows local users to change files that are part of write protection rules via manipulating symbolic li...Show more
Privilege Escalation vulnerability in the installer in McAfee McAfee Total Protection (MTP) trial prior to 4.0.161.1 allows local users to change files that are part of write protection rules via manipulating symbolic links to redirect a McAfee file operations to an unintended file.Show less
1Zulip
1Zulip Server
Jun 17, 2026
Aug 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.
1Zulip
1Zulip Server
Jun 17, 2026
Aug 21, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link.
3Canonical
Net SnmpNetapp
6Cloud Backup
Hci Management NodeNet Snmp+3 more
Jun 17, 2026
Aug 20, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
1Nodebb
1Nodebb
Jun 17, 2026
Aug 20, 2020
N/A· v4
9.9 CRITICAL· v3
6.5 MEDIUM· v2
NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io cal...Show more
NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io call to the server. This could lead to a privilege escalation event due via an account takeover. As a workaround you may cherry-pick the following commit from the project's repository to your running instance of NodeBB: 16cee1b03ba3eee177834a1fdac4aa8a12b39d2a. This is fixed in version 1.14.3.Show less
1Elastic
1Elasticsearch
Jun 17, 2026
Aug 18, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling...Show more
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden. This could result in an attacker gaining additional permissions against a restricted index.Show less
1Elastic
1Enterprise Search
Jun 17, 2026
Aug 18, 2020
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These crede...Show more
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could allow the developer user to conduct operations with the same permissions of the App Search administrator.Show less
1Microsoft
6Windows 10
Windows 8.1Windows Rt 8.1+3 more
Jun 17, 2026
Aug 17, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. To exploit this vulnerability, an authenticated at...Show more
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges.Show less
1Textpattern
1Textpattern
Nov 21, 2024
Aug 14, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.
2Fedoraproject
Trousers Project
2Fedora
Trousers
Jun 17, 2026
Aug 13, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (which contains various settings related to...Show more
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (which contains various settings related to this daemon).Show less
2Fedoraproject
Trousers Project
2Fedora
Trousers
Jun 17, 2026
Aug 13, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed.
1Mcafee
1Data Loss Prevention
Jun 17, 2026
Aug 13, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Privilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows a low privileged remote attacker to create new rule sets via incorrect validation of user credentials.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Aug 11, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog. This vulnerability could allo...Show more
An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog. This vulnerability could allow an unauthenticated attacker to escalate privileges on a Windows host. An attacker does not require any privilege on the target system in order to exploit this vulnerability. One option is the self-service option on the Windows login screen. Upon selecting this option, the thick-client software is launched, which connects to a remote ADSelfService Plus server to facilitate self-service operations. An unauthenticated attacker having physical access to the host could trigger a security alert by supplying a self-signed SSL certificate to the client. The View Certificate option from the security alert allows an attacker to export a displayed certificate to a file. This can further cascade to a dialog that can open Explorer as SYSTEM. By navigating from Explorer to \windows\system32, cmd.exe can be launched as a SYSTEM.Show less
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 8, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
2Jetbrains
Oracle
3Banking Extensibility Workbench
Communications Cloud Native Core PolicyKotlin
Jun 17, 2026
Aug 8, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the sy...Show more
In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.Show less
1Softperfect
1Ram Disk
Jun 17, 2026
Aug 4, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can allow an unprivileged user to delete any file on the filesystem. An...Show more
An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can allow an unprivileged user to delete any file on the filesystem. An attacker can send a malicious IRP to trigger this vulnerability.Show less
1Skygroup
1Skysea Client View
Jun 17, 2026
Aug 4, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unauthorized privileges and modify/obtain sensitive information or perform unintended operations via unsp...Show more
Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unauthorized privileges and modify/obtain sensitive information or perform unintended operations via unspecified vectors.Show less