CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,558 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 54 of 92
- CVE-2022-26789HIGHCVSS 7.8EG 7.82022-04-15
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-26790HIGHCVSS 7.8EG 7.82022-04-15
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-26791HIGHCVSS 7.8EG 7.82022-04-15
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-26792HIGHCVSS 7.8EG 7.82022-04-15
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-26793HIGHCVSS 7.8EG 7.82022-04-15
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-26794HIGHCVSS 7.8EG 7.82022-04-15
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-26795HIGHCVSS 7.8EG 7.82022-04-15
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-26796HIGHCVSS 7.8EG 7.82022-04-15
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-26797HIGHCVSS 7.8EG 7.82022-04-15
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-26798HIGHCVSS 7.8EG 7.82022-04-15
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-26801HIGHCVSS 7.8EG 7.82022-04-15
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-26802HIGHCVSS 7.8EG 7.82022-04-15
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-26803HIGHCVSS 7.8EG 7.82022-04-15
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-26891HIGHCVSS 8.3EG 8.32022-04-05
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2022-26894HIGHCVSS 8.3EG 8.32022-04-05
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2022-26895HIGHCVSS 8.3EG 8.32022-04-05
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2022-26900HIGHCVSS 8.3EG 8.32022-04-05
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2022-26908HIGHCVSS 8.3EG 8.32022-04-05
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2022-26909HIGHCVSS 8.3EG 8.32022-04-05
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2022-26912HIGHCVSS 8.3EG 8.32022-04-05
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2022-26914HIGHCVSS 7.8EG 7.82022-04-15
Win32k Elevation of Privilege Vulnerability
- CVE-2022-26938HIGHCVSS 7.0EG 7.02022-05-10
Storage Spaces Direct Elevation of Privilege Vulnerability
- CVE-2022-26939HIGHCVSS 7.0EG 7.02022-05-10
Storage Spaces Direct Elevation of Privilege Vulnerability
- CVE-2022-2732HIGHCVSS 8.3EG 8.32022-08-09
Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1.
- CVE-2022-27421HIGHCVSS 7.2EG 7.22022-04-15
Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin.
- CVE-2022-27487HIGHCVSS 8.8EG 8.82023-04-11
A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version 4.1.0, 4.0.0 through 4.0.2 and before 3.3.3 allows a remote authenticated attacker to perf…
- CVE-2022-27659MEDIUMCVSS 4.3EG 4.32022-05-05
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, an authenticated attacker can modify or delete Dashboards created by other BIG-IP users in the Traffic Management Use…
- CVE-2022-27677HIGHCVSS 7.8EG 7.82023-03-01
Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentially leading to privilege escalation and code execution by the lower privileged user.
- CVE-2022-27773CRITICALCVSS 9.8EG 9.82022-12-05
A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated privileges.
- CVE-2022-27840MEDIUMCVSS 4.4EG 4.42022-04-11
Improper access control vulnerability in SamsungRecovery prior to version 8.1.43.0 allows local attckers to delete arbitrary files as SamsungRecovery permission.
- CVE-2022-28169HIGHCVSS 8.8EG 8.82022-10-25
Brocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allow a low privilege webtools, user, to gain elevated admin rights, or privileges, beyond what is intended or entitled for…
- CVE-2022-28666MEDIUMCVSS 5.3EG 5.32022-07-21
Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.
- CVE-2022-29125HIGHCVSS 7.0EG 7.02022-05-10
Windows Push Notifications Apps Elevation of Privilege Vulnerability
- CVE-2022-29164HIGHCVSS 7.1EG 7.12022-05-06
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. In affected versions an attacker can create a workflow which produces a HTML artifact containing an HTML file that contains a …
- CVE-2022-29179HIGHCVSS 7.5EG 7.52022-05-20
Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Prior to versions 1.9.16, 1.10.11, and 1.11.15, if an attacker is able to perform a container escape of a conta…
- CVE-2022-29218HIGHCVSS 7.7EG 7.72022-05-13
RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allowed some gems (with platforms ending in numbers, like `arm64-darwin-21`) to be temporarily…
- CVE-2022-29333HIGHCVSS 7.8EG 7.82022-05-24
A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.
- CVE-2022-29526MEDIUMCVSS 5.3EG 5.32022-06-23
Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.
- CVE-2022-29587MEDIUMCVSS 4.0EG 4.02022-05-16
Konica Minolta bizhub MFP devices before 2022-04-14 have an internal Chromium browser that executes with root (aka superuser) access privileges.
- CVE-2022-29614MEDIUMCVSS 5.0EG 5.02022-06-14
SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.2…
- CVE-2022-2975HIGHCVSS 7.7EG 7.72022-10-06
A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative user to modify accounts leading to execution of arbitrary code as the root user. This issue …
- CVE-2022-29849HIGHCVSS 7.8EG 7.82022-05-02
In Progress OpenEdge before 11.7.14 and 12.x before 12.2.9, certain SUID binaries within the OpenEdge application were susceptible to privilege escalation. If exploited, a local attacker could elevate their privileges and compromise the af…
- CVE-2022-29908HIGHCVSS 7.8EG 7.82022-09-19
The folioupdate service in Fabasoft Cloud Enterprise Client 22.4.0043 allows Local Privilege Escalation.
- CVE-2022-30121HIGHCVSS 6.7EG 8.82022-09-23
The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their …
- CVE-2022-30150HIGHCVSS 7.5EG 7.52022-06-15
Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability
- CVE-2022-30151HIGHCVSS 7.0EG 7.02022-06-15
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- CVE-2022-30154MEDIUMCVSS 5.3EG 5.32022-06-15
Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability
- CVE-2022-30181MEDIUMCVSS 6.5EG 6.52022-07-12
Azure Site Recovery Elevation of Privilege Vulnerability
- CVE-2022-30224HIGHCVSS 7.0EG 7.02022-07-12
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
- CVE-2022-30225HIGHCVSS 7.1EG 7.12022-07-12
Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →