← Back
CWE-269

3,313 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,313)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Teltonika Networks
1Trb245 Firmware
Jun 17, 2026
Aug 3, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper Access Control in Teltonika firmware TRB2_R_00.02.04.01 allows a low privileged user to perform unauthorized write operations.
1Ibm
1Cognos Analytics
Jun 17, 2026
Aug 3, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and subscriptions" page is visible and accessible to a less privileged user. IBM X-Force ID: 167449.
1Pi Hole
1Pi Hole
Jun 17, 2026
Jul 30, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core script as root without a password, which could allow an attacker to obtain root access via shell meta...Show more
An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core script as root without a password, which could allow an attacker to obtain root access via shell metacharacters to this script's setdns command.Show less
1Openclinic Ga Project
1Openclinic Ga
Jun 17, 2026
Jul 29, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which may allow the execution of arbitrary commands.
1Adobe
1Creative Cloud
Jun 17, 2026
Jul 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a lack of exploit mitigations vulnerability. Successful exploitation could lead to privilege escalation.
1Ufactory
3Xarm 5 Lite Firmware
Xarm 6 FirmwareXarm 7 Firmware
Jun 17, 2026
Jul 15, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or is...Show more
the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation.Show less
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Jul 14, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated att...Show more
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.Show less
1Microsoft
5Azure Storage Explorer
TypescriptVisual Studio 2017+2 more
Jun 17, 2026
Jul 14, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'.
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Jul 14, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
1Siemens
1Opcenter Execution Core
Jun 17, 2026
Jul 14, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2). Authenticated users could have access to resources they normally would not have. This vuln...Show more
A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2). Authenticated users could have access to resources they normally would not have. This vulnerability could allow an attacker to view internal information and perform unauthorized changes.Show less
1Rittal
5Cmc Iii Pu 7030.000 Firmware
Cmciii Pu 9333e0fb FirmwareIot Interface 3124.300+2 more
Jun 17, 2026
Jul 14, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is a least privilege violation.
1Checkpoint
1Zonealarm Extreme Security
Jun 17, 2026
Jul 6, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation...Show more
ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation and exploitation of Windows CVE-2020-00896 on unpatched systems.Show less
1Mcafee
1Total Protection
Jun 17, 2026
Jul 3, 2020
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edit files via symbolic link manipulation in a location they would otherwise not have access to. This i...Show more
Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edit files via symbolic link manipulation in a location they would otherwise not have access to. This is achieved through running a malicious script or program on the target machine.Show less
1Mcafee
1Total Protection
Jun 17, 2026
Jul 3, 2020
N/A· v4
6.3 MEDIUM· v3
1.9 LOW· v2
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee de...Show more
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.Show less
1Nextcloud
1Deck
Jun 17, 2026
Jul 2, 2020
N/A· v4
4.1 MEDIUM· v3
4.0 MEDIUM· v2
Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.
1Asrock
1Rgb Driver Firmware
Jun 17, 2026
Jun 29, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering a triple fault via a request to zero CR3.
1Gns3
1Ubridge
Jun 17, 2026
Jun 23, 2020
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary files because it handles configuration-file errors by printing the configuration file while executing...Show more
GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary files because it handles configuration-file errors by printing the configuration file while executing in a setuid root context.Show less
1Mattermost
1Mattermost Server
Nov 21, 2024
Jun 19, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.
1Mattermost
1Mattermost Server
Nov 21, 2024
Jun 19, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens.
1Mattermost
1Mattermost Server
Jun 17, 2026
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.