← Back
CWE-269

3,313 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,313)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
1Fusionsphere Openstack
Jun 17, 2026
Jun 18, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
FusionSphere OpenStack 6.5.1 have an improper permissions management vulnerability. The software does not correctly perform a privilege assignment when an actor attempts to perform an action. Successful exploit could all...Show more
FusionSphere OpenStack 6.5.1 have an improper permissions management vulnerability. The software does not correctly perform a privilege assignment when an actor attempts to perform an action. Successful exploit could allow certain user to do certain operations beyond its privilege.Show less
1Schneider Electric
1Easergy T300 Firmware
Jun 17, 2026
Jun 16, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A CWE-269: Improper privilege management (write) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to elevate their privileges and delete files.
1Pandorafms
1Pandora Fms
Jun 17, 2026
Jun 11, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Artica Pandora FMS 7.44 allows privilege escalation.
1Pydio
1Cells
Jun 17, 2026
Jun 11, 2020
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Cells Enterprise OVF (such as version 2.0.3) have a looser policy restriction allowing the “pydio” use...Show more
The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Cells Enterprise OVF (such as version 2.0.3) have a looser policy restriction allowing the “pydio” user to execute any privileged command using sudo. In version 2.0.4 of the appliance, the user pydio is responsible for running all the services and binaries that are contained in the Pydio Cells web application package, such as mysqld, cells, among others. This user has privileges restricted to run those services and nothing more.Show less
1Ciphermail
2Gateway
Webmail Messenger
Jun 17, 2026
Jun 11, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger 1.1.1 through 3.1.1-0. Attackers with administrative access to the web in...Show more
An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger 1.1.1 through 3.1.1-0. Attackers with administrative access to the web interface have multiple options to escalate their privileges to the Unix root account.Show less
1Hashicorp
1Vault
Jun 17, 2026
Jun 10, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the default time-to-live lease duration instead of the engine-configured se...Show more
HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the default time-to-live lease duration instead of the engine-configured setting. This may lead to generated GCP credentials being valid for longer than intended. Fixed in 1.4.2.Show less
1Mcafee
1Virusscan Enterprise
Jun 17, 2026
Jun 10, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Privilege Escalation vulnerability during daily DAT updates when using McAfee Virus Scan Enterprise (VSE) prior to 8.8 Patch 15 allows local users to cause the deletion and creation of files they would not normally have...Show more
Privilege Escalation vulnerability during daily DAT updates when using McAfee Virus Scan Enterprise (VSE) prior to 8.8 Patch 15 allows local users to cause the deletion and creation of files they would not normally have permission to through altering the target of symbolic links. This is timing dependent.Show less
1Mcafee
1Virusscan Enterprise
Jun 17, 2026
Jun 10, 2020
N/A· v4
6.8 MEDIUM· v3
6.9 MEDIUM· v2
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow unauthorized users to interact with the On-Access Scan Messages - Threat Al...Show more
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow unauthorized users to interact with the On-Access Scan Messages - Threat Alert Window when the Windows Login Screen is locked.Show less
1Mcafee
1Virusscan Enterprise
Jun 17, 2026
Jun 10, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow local users to interact with the On-Access Scan Messages - Threat Alert Win...Show more
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow local users to interact with the On-Access Scan Messages - Threat Alert Window with elevated privileges via running McAfee Tray with elevated privileges.Show less
1Mcafee
1Total Protection
Jun 17, 2026
Jun 10, 2020
N/A· v4
8.2 HIGH· v3
6.9 MEDIUM· v2
Privilege escalation vulnerability in McAfee Total Protection (ToPS) for Mac OS prior to 4.6 allows local users to gain root privileges via incorrect protection of temporary files.
1Lenovo
100Thinkpad 11e Firmware
Thinkpad 11e Yoga Gen 6 FirmwareThinkpad 13 2nd Gen Firmware+97 more
Jun 17, 2026
Jun 9, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
1Elastic
1Elasticsearch
Jun 17, 2026
Jun 3, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication to...Show more
The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.Show less
3Fedoraproject
NetappSystemd Project
4Active Iq Unified Manager
FedoraSolidfire & Hci Management Node+1 more
Jun 17, 2026
Jun 3, 2020
N/A· v4
6.7 MEDIUM· v3
6.2 MEDIUM· v2
systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. N...Show more
systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000082.Show less
1Quickbox
1Quickbox
Jun 17, 2026
Jun 1, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as root without a password, which allows an attacker to obtain sensitive information...Show more
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as root without a password, which allows an attacker to obtain sensitive information via a grep of a /root/*.db or /etc/shadow file.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraSympa+1 more
Jun 17, 2026
May 27, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Sympa before 6.2.56 allows privilege escalation.
1Johnsoncontrols
1Kantech Entrapass
Jun 17, 2026
May 26, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.
3Canonical
DebianNetqmail
3Debian Linux
NetqmailUbuntu Linux
Jun 17, 2026
May 26, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root...Show more
qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first.Show less
2Debian
Opensuse
2Debian Linux
Open Build Service
Jun 17, 2026
May 19, 2020
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/access is disabled This issue affects: Open Build Service versions prior to...Show more
a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/access is disabled This issue affects: Open Build Service versions prior to 2.10.5.Show less
1Ivanti
1Workspace Control
Jun 17, 2026
May 18, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when st...Show more
In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when starting an application with elevated rights.Show less
1Health
1Covidsafe
Jun 17, 2026
May 18, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
COVIDSafe through v1.0.17 allows a remote attacker to access phone name and model information because a BLE device can have four roles and COVIDSafe uses all of them. This allows for re-identification of a device, and po...Show more
COVIDSafe through v1.0.17 allows a remote attacker to access phone name and model information because a BLE device can have four roles and COVIDSafe uses all of them. This allows for re-identification of a device, and potentially identification of the owner's name.Show less