CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,558 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 55 of 92
- CVE-2022-30226HIGHCVSS 7.1EG 7.12022-07-12
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-30298HIGHCVSS 7.0EG 7.82022-09-06
An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python …
- CVE-2022-30526HIGHCVSS 7.8EG 7.82022-07-19
A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FL…
- CVE-2022-30610MEDIUMCVSS 4.5EG 4.52022-06-10
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it. An administrator could enter a link to a mali…
- CVE-2022-30616HIGHCVSS 7.2EG 7.22022-08-01
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to elevate their privilege to platform administrator through manipulation of APIs. IBM X-Force ID: 227978.
- CVE-2022-30620HIGHCVSS 8.2EG 8.82022-07-18
On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows ch…
- CVE-2022-3068HIGHCVSS 8.8EG 8.82022-09-21
Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.
- CVE-2022-30688HIGHCVSS 7.8EG 7.82022-05-17
needrestart 0.8 through 3.5 before 3.6 is prone to local privilege escalation. Regexes to detect the Perl, Python, and Ruby interpreters are not anchored, allowing a local user to escalate privileges when needrestart tries to detect if int…
- CVE-2022-30695HIGHCVSS 7.8EG 7.82022-05-16
Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Snap Deploy (Windows) before build 3640
- CVE-2022-30735HIGHCVSS 5.9EG 7.52022-06-07
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permission.
- CVE-2022-30736MEDIUMCVSS 5.3EG 5.32022-06-07
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.
- CVE-2022-30739MEDIUMCVSS 4.0EG 4.32022-06-07
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number with a normal level permission.
- CVE-2022-30743MEDIUMCVSS 5.3EG 5.32022-06-07
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.
- CVE-2022-3079HIGHCVSS 7.5EG 7.52022-09-20
Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpage functions which may cause a denial of service.
- CVE-2022-30804MEDIUMCVSS 6.5EG 6.52022-06-02
elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=.
- CVE-2022-3088HIGHCVSS 7.8EG 7.82022-11-28
UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image: Versions v1.0 to v 1.12, UC-3100 System Image: Versions v1.0 to v1.6, UC-5100 System Image: Versions v1.0 to…
- CVE-2022-31039MEDIUMCVSS 4.3EG 4.32022-06-27
Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to v…
- CVE-2022-31166HIGHCVSS 8.1EG 8.12022-09-07
XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Starting in versions 11.3.7, 11.0.3, and 12.0RC1, it is possible to exploit a bug in XWikiRights resolution of groups to obtain privilege escalation. Mo…
- CVE-2022-31214HIGHCVSS 7.8EG 7.82022-06-09
A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container that is accepted by the Firejail setuid-root program as a join target, a local attacker can enter an environment in whi…
- CVE-2022-31216HIGHCVSS 7.8EG 7.82022-06-15
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file …
- CVE-2022-31217HIGHCVSS 7.8EG 7.82022-06-15
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file …
- CVE-2022-31218HIGHCVSS 7.8EG 7.82022-06-15
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file …
- CVE-2022-31219HIGHCVSS 7.3EG 7.82022-06-15
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file …
- CVE-2022-31257HIGHCVSS 7.5EG 7.52022-07-12
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All versions < V8.18.18), Mendix Applications using Mendix 9 (All versions < V9.14.0), Mendix Applicat…
- CVE-2022-31267CRITICALCVSS 9.8EG 9.82022-05-21
Gitblit 1.9.2 allows privilege escalation via the Config User Service: a control character can be placed in a profile data field, such as an emailAddress%3Atext 'attacker@example.com\n\trole = "#admin"' value.
- CVE-2022-31464HIGHCVSS 7.8EG 7.82022-06-16
Insecure permissions configuration in Adaware Protect v1.2.439.4251 allows attackers to escalate privileges via changing the service binary path.
- CVE-2022-31496HIGHCVSS 8.8EG 8.82022-06-09
LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access.
- CVE-2022-31594MEDIUMCVSS 6.7EG 6.72022-06-14
A highly privileged user can exploit SUID-root program to escalate his privileges to root on a local Unix system.
- CVE-2022-31660HIGHCVSS 7.8EG 7.82022-08-05
VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
- CVE-2022-31661HIGHCVSS 7.8EG 7.82022-08-05
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can escalate privileges to 'root'.
- CVE-2022-31664HIGHCVSS 7.8EG 7.82022-08-05
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
- CVE-2022-31672HIGHCVSS 7.2EG 7.22022-08-10
VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root.
- CVE-2022-31676HIGHCVSS 7.8EG 7.82022-08-23
VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.
- CVE-2022-31707HIGHCVSS 7.2EG 7.22022-12-16
vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.
- CVE-2022-31884MEDIUMCVSS 6.5EG 6.52022-06-28
Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrator users API Keys.
- CVE-2022-32272CRITICALCVSS 9.8EG 9.82022-06-09
OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation.
- CVE-2022-32481HIGHCVSS 7.8EG 7.82022-07-07
Dell PowerProtect Cyber Recovery, versions prior to 19.11, contain a privilege escalation vulnerability on virtual appliance deployments. A lower-privileged authenticated user can chain docker commands to escalate privileges to root leadin…
- CVE-2022-32535CRITICALCVSS 4.8EG 9.82022-06-23
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combination with CVE-2022-23534 this could give an attacker root access to the switch.
- CVE-2022-32536HIGHCVSS 8.8EG 8.82022-06-23
The user access rights validation in the web server of the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 was insufficient. This would allow a non-administrator user to obtain administrator user access rights.
- CVE-2022-32633MEDIUMCVSS 6.7EG 6.72022-12-05
In Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441637; …
- CVE-2022-32781MEDIUMCVSS 4.4EG 4.42022-09-23
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5, Security Update 2022-005 Catalina, macOS Big Sur 11.6.8. An app with root privileges may be able to access private…
- CVE-2022-32782MEDIUMCVSS 4.4EG 4.42022-09-23
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information.
- CVE-2022-32794HIGHCVSS 7.8EG 7.82022-11-01
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. An app may be able to gain elevated privileges.
- CVE-2022-32801HIGHCVSS 7.8EG 7.82022-09-23
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5. An app may be able to gain root privileges.
- CVE-2022-32819HIGHCVSS 7.8EG 7.82022-09-23
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to gain r…
- CVE-2022-32826HIGHCVSS 7.8EG 7.82022-09-23
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able …
- CVE-2022-32829HIGHCVSS 7.8EG 7.82022-09-23
This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-32840HIGHCVSS 7.8EG 7.82022-08-24
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-32900HIGHCVSS 7.8EG 7.82023-02-27
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6, macOS Big Sur 11.7. An app may be able to gain elevated privileges.
- CVE-2022-32907HIGHCVSS 7.8EG 7.82022-11-01
This issue was addressed with improved checks. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →