CWE-269
3,308 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (3,308)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dell 2Supportassist For Business Pcs Supportassist For Home PcsJun 17, 2026 Jun 20, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management Vulnerability. A malic...Show more |
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158882. |
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158879. |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Jun 12, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a...Show more |
An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admins have the inherent ability to reset passwords for all of their organization's users). This, however...Show more |
1Enttec 4Datagate Mk2 Firmware E Streamer Mk2 FirmwarePixelator Firmware+1 moreJun 17, 2026 Jun 7, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They allow high-privileged root access by www-data via sudo without requiring appropria...Show more |
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 159227. |
1Ibm 10Control Desk Maximo Asset ManagementMaximo For Aviation+7 moreJun 17, 2026 Jun 6, 2019 N/A· v4 2.1 LOW· v3 2.1 LOW· v2 IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311. |
Privilege escalation in the "HTC Account Service" and "ViveportDesktopService" in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges to SYSTEM via reconfiguration of either service. |
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given all capabilities during stage 2 (the actual environment in which the application...Show more |
1Bosch 1Smart Home Controller Firmware Jun 17, 2026 May 29, 2019 N/A· v4 7.1 HIGH· v3 6.8 MEDIUM· v2 A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permiss...Show more |
1Bosch 1Smart Home Controller Firmware Jun 17, 2026 May 29, 2019 N/A· v4 8.0 HIGH· v3 4.9 MEDIUM· v2 A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a restricted app obtaining default app permissio...Show more |
1Bosch 1Smart Home Controller Firmware Jun 17, 2026 May 29, 2019 N/A· v4 8.0 HIGH· v3 5.4 MEDIUM· v2 A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in elevated privileges of the adversary's choosing. In...Show more |
1Ca 2Risk Authentication Strong AuthenticationJun 17, 2026 May 28, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x allows...Show more |
1Microsoft 1Azure Active Directory Connect Jun 17, 2026 May 16, 2019 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 An elevation of privilege vulnerability exists in Microsoft Azure Active Directory Connect build 1.3.20.0, which allows an attacker to execute two PowerShell cmdlets in context of a privileged account, and perform privil...Show more |
Under certain conditions, it is possible to request the modification of role or privilege assignments through SAP Identity Management REST Interface Version 2, which would otherwise be restricted only for viewing. |
Go through 1.12.5 on Windows mishandles process creation with a nil environment in conjunction with a non-nil token, which allows attackers to obtain sensitive information or gain privileges. |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreJun 17, 2026 May 3, 2019 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, a user with the Resource Administrator role is able to overwrite sensitive low-level files (such as /etc/passwd) using SFTP t...Show more |
1Redhat 2Jboss Enterprise Application Platform WildflyJun 17, 2026 May 3, 2019 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying...Show more |
1Octopus 2Octopus Deploy Octopus ServerJun 17, 2026 May 1, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 In Octopus Deploy 2019.1.0 through 2019.3.1 and 2019.4.0 through 2019.4.5, an authenticated user with the VariableViewUnscoped or VariableEditUnscoped permission scoped to a specific project could view or edit unscoped v...Show more |