CWE-269
3,313 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (3,313)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Huawei 1Fusionsphere Openstack Jun 17, 2026 Jun 18, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 FusionSphere OpenStack 6.5.1 have an improper permissions management vulnerability. The software does not correctly perform a privilege assignment when an actor attempts to perform an action. Successful exploit could all...Show more |
1Schneider Electric 1Easergy T300 Firmware Jun 17, 2026 Jun 16, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A CWE-269: Improper privilege management (write) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to elevate their privileges and delete files. |
Artica Pandora FMS 7.44 allows privilege escalation. |
The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Cells Enterprise OVF (such as version 2.0.3) have a looser policy restriction allowing the “pydio” use...Show more |
1Ciphermail 2Gateway Webmail MessengerJun 17, 2026 Jun 11, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger 1.1.1 through 3.1.1-0. Attackers with administrative access to the web in...Show more |
HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the default time-to-live lease duration instead of the engine-configured se...Show more |
Privilege Escalation vulnerability during daily DAT updates when using McAfee Virus Scan Enterprise (VSE) prior to 8.8 Patch 15 allows local users to cause the deletion and creation of files they would not normally have...Show more |
1Mcafee 1Virusscan Enterprise Jun 17, 2026 Jun 10, 2020 N/A· v4 6.8 MEDIUM· v3 6.9 MEDIUM· v2 Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow unauthorized users to interact with the On-Access Scan Messages - Threat Al...Show more |
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow local users to interact with the On-Access Scan Messages - Threat Alert Win...Show more |
Privilege escalation vulnerability in McAfee Total Protection (ToPS) for Mac OS prior to 4.6 allows local users to gain root privileges via incorrect protection of temporary files. |
1Lenovo 100Thinkpad 11e Firmware Thinkpad 11e Yoga Gen 6 FirmwareThinkpad 13 2nd Gen Firmware+97 moreJun 17, 2026 Jun 9, 2020 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege. |
The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication to...Show more |
3Fedoraproject NetappSystemd Project4Active Iq Unified Manager FedoraSolidfire & Hci Management Node+1 moreJun 17, 2026 Jun 3, 2020 N/A· v4 6.7 MEDIUM· v3 6.2 MEDIUM· v2 systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. N...Show more |
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as root without a password, which allows an attacker to obtain sensitive information...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraSympa+1 moreJun 17, 2026 May 27, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Sympa before 6.2.56 allows privilege escalation. |
1Johnsoncontrols 1Kantech Entrapass Jun 17, 2026 May 26, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files. |
3Canonical DebianNetqmail3Debian Linux NetqmailUbuntu LinuxJun 17, 2026 May 26, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root...Show more |
2Debian Opensuse2Debian Linux Open Build ServiceJun 17, 2026 May 19, 2020 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/access is disabled This issue affects: Open Build Service versions prior to...Show more |
In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when st...Show more |
COVIDSafe through v1.0.17 allows a remote attacker to access phone name and model information because a BLE device can have four roles and COVIDSafe uses all of them. This allows for re-identification of a device, and po...Show more |