← Back
CWE-269

3,323 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,323)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Redhat
Samba
2Linux
Rsync
Apr 16, 2026
Mar 15, 2002
N/A· v4
N/A· v3
2.1 LOW· v2
rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be...Show more
rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.Show less
1Microsoft
1Exchange Server
Apr 16, 2026
Mar 8, 2002
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.
1Sun
1Nfs
Apr 16, 2026
May 1, 1990
N/A· v4
8.4 HIGH· v3
7.2 HIGH· v2
Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.