← Back
CWE-269

3,313 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,313)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sun Denshi
1Universal Forensic Extraction Device Firmware
Jun 17, 2026
May 15, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command prompt via the Windows file dialog that is reachable via the Certificate-Based Authentication optio...Show more
Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command prompt via the Windows file dialog that is reachable via the Certificate-Based Authentication option of the Wireless Network Connection screen.Show less
1Mcafee
1Active Response
Jun 17, 2026
May 8, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Privilege Escalation vulnerability in McAfee Active Response (MAR) for Mac prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.
1Mcafee
1Active Response
Jun 17, 2026
May 8, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Privilege Escalation vulnerability in McAfee Active Response (MAR) for Linux prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.
1Mcafee
1Active Response
Jun 17, 2026
May 8, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Privilege Escalation vulnerability in McAfee Active Response (MAR) for Windows prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access t...Show more
Privilege Escalation vulnerability in McAfee Active Response (MAR) for Windows prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.Show less
1Mcafee
1Endpoint Detection And Response
Jun 17, 2026
May 8, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Mac prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been grant...Show more
Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Mac prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.Show less
1Mcafee
1Endpoint Detection And Response
Jun 17, 2026
May 8, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Linux prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been gra...Show more
Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Linux prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.Show less
1Mcafee
1Endpoint Detection And Response
Jun 17, 2026
May 8, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Windows prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been g...Show more
Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Windows prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.Show less
1Mcafee
1Mvision Endpoint
Jun 17, 2026
May 8, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.5.0.94 allows a malicious script or program to perform functions that the local executing user has not been granted access to.
1Mcafee
1Virusscan Enterprise
Jun 17, 2026
May 8, 2020
N/A· v4
8.4 HIGH· v3
3.6 LOW· v2
Privilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Linux prior to 2.0.3 Hotfix 2635000 allows local users to delete files the user would otherwise not have access to via manipulating symbolic lin...Show more
Privilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Linux prior to 2.0.3 Hotfix 2635000 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.Show less
1Mcafee
1Virusscan Enterprise
Jun 17, 2026
May 8, 2020
N/A· v4
8.4 HIGH· v3
3.6 LOW· v2
Privilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Windows prior to 8.8 Patch 14 Hotfix 116778 allows local users to delete files the user would otherwise not have access to via manipulating symb...Show more
Privilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Windows prior to 8.8 Patch 14 Hotfix 116778 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.Show less
1Mcafee
1Endpoint Security
Jun 17, 2026
May 8, 2020
N/A· v4
8.4 HIGH· v3
3.6 LOW· v2
Privilege Escalation vulnerability in McAfee Endpoint Security (ENS) for Mac prior to 10.6.9 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a Mc...Show more
Privilege Escalation vulnerability in McAfee Endpoint Security (ENS) for Mac prior to 10.6.9 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.Show less
1Mcafee
1Endpoint Security
Jun 17, 2026
May 8, 2020
N/A· v4
8.4 HIGH· v3
3.6 LOW· v2
Privilege Escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 Hotfix 199847 allows local users to delete files the user would otherwise not have access to via manipulating symbolic link...Show more
Privilege Escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 Hotfix 199847 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.Show less
1Eaton
1Intelligent Power Manager
Jun 17, 2026
May 7, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests. This can result...Show more
Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests. This can result in non-admin users manipulating the system configurations via uploading the configurations with incorrect parameters.Show less
2Canonical
Openstack
2Keystone
Ubuntu Linux
Jun 17, 2026
May 7, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escalated permission, such...Show more
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escalated permission, such as obtaining admin while the user is on a limited viewer role. This potentially allows a malicious user to act as the admin on a project another user has the admin role on, which can effectively grant that user global admin privileges.Show less
1Ibm
1Maximo Anywhere
Jun 17, 2026
May 6, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 does not have device jailbreak detection which could result in an attacker gaining sensitive information about the device. IBM X-Force ID: 160199.
1Bmcsoftware
1Control M/agent
Jun 17, 2026
Apr 30, 2020
N/A· v4
8.8 HIGH· v3
8.5 HIGH· v2
BMC Control-M/Agent 7.0.00.000 has an Insecure File Copy.
1Netgear
5Jnr1010 Firmware
Jwnr2010 FirmwareWnr1000 Firmware+2 more
Nov 21, 2024
Apr 28, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Certain NETGEAR devices are affected by authentication bypass. This affects JNR1010v2 before 1.1.0.48, JWNR2010v5 before 1.1.0.48, WNR1000v4 before 1.1.0.48, WNR2020 before 1.1.0.48, and WNR2050 before 1.1.0.48.
2Apport Project
Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Apr 28, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Apport reads and writes information on a crashed process to /proc/pid with elevated privileges. Apport then determines which user the crashed process belongs to by reading /proc/pid through get_pid_info() in data/apport....Show more
Apport reads and writes information on a crashed process to /proc/pid with elevated privileges. Apport then determines which user the crashed process belongs to by reading /proc/pid through get_pid_info() in data/apport. An unprivileged user could exploit this to read information about a privileged running process by exploiting PID recycling. This information could then be used to obtain ASLR offsets for a process with an existing memory corruption vulnerability. The initial fix introduced regressions in the Python Apport library due to a missing argument in Report.add_proc_environ in apport/report.py. It also caused an autopkgtest failure when reading /proc/pid and with Python 2 compatibility by reading /proc maps. The initial and subsequent regression fixes are in 2.20.11-0ubuntu16, 2.20.11-0ubuntu8.6, 2.20.9-0ubuntu7.12, 2.20.1-0ubuntu2.22 and 2.14.1-0ubuntu3.29+esm3.Show less
1Webtoffee
1Import Export Wordpress Users
Jun 17, 2026
Apr 23, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
1Netgear
2Wac505 Firmware
Wac510 Firmware
Nov 21, 2024
Apr 22, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
NETGEAR WAC510 devices before 5.0.0.17 are affected by privilege escalation.