CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,558 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 56 of 92
- CVE-2022-32931MEDIUMCVSS 5.5EG 5.52024-01-10
This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to access private information.
- CVE-2022-32949HIGHCVSS 7.8EG 7.82023-02-27
This issue was addressed with improved checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-33640HIGHCVSS 7.8EG 7.82022-08-09
System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
- CVE-2022-33646HIGHCVSS 7.0EG 7.02022-08-09
Azure Batch Node Agent Elevation of Privilege Vulnerability
- CVE-2022-3368HIGHCVSS 7.3EG 8.82022-10-17
A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avira Security versi…
- CVE-2022-33680HIGHCVSS 8.3EG 8.32022-07-07
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2022-3369HIGHCVSS 8.6EG 8.62022-11-01
An Improper Access Control vulnerability in the bdservicehost.exe component, as used in Bitdefender Engines for Windows, allows an attacker to delete privileged registry keys by pointing a Registry symlink to a privileged key. This issue a…
- CVE-2022-33708HIGHCVSS 7.8EG 7.82022-07-12
Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
- CVE-2022-33709HIGHCVSS 7.8EG 7.82022-07-12
Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
- CVE-2022-33710HIGHCVSS 7.8EG 7.82022-07-12
Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
- CVE-2022-33757MEDIUMCVSS 6.5EG 6.52022-10-25
An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privileges to do so. This may lead to the disclosure of information on the scan target and/or the Nessus scan to unauthorized…
- CVE-2022-33962MEDIUMCVSS 6.7EG 6.72022-08-04
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, certain iRules commands may allow an attacker to bypass the access control restrictions for a se…
- CVE-2022-34006HIGHCVSS 7.8EG 7.82022-06-19
An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. When installing, Microsoft SQL Express 2019 installs by default with an SQL instance running as SYSTEM with BUILTIN\Users as sysadmin, thus enabling unprivileged …
- CVE-2022-34008HIGHCVSS 7.8EG 7.82022-06-21
Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privileged attacker can use an NTFS directory junction to restore a malicious DLL from quarantine into the System32 folder.
- CVE-2022-3405CRITICALCVSS 8.8EG 9.32023-05-03
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Window…
- CVE-2022-3419MEDIUMCVSS 6.5EG 6.52022-10-31
The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator
- CVE-2022-3421HIGHCVSS 5.6EG 7.32022-10-17
An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned by root to be owned by a non-root user. When the Drive for Desktop installer is run for the first time, it will place a…
- CVE-2022-3422HIGHCVSS 7.5EG 7.52022-10-07
Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the forgot_password_token the hacker can send the request and changed the pass
- CVE-2022-34338MEDIUMCVSS 6.5EG 6.52022-08-01
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provider types. IBM X-Force ID: 229962.
- CVE-2022-34382HIGHCVSS 7.8EG 7.82022-09-02
Dell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration. A local malicious user may potentially exploit this vulnerability in ord…
- CVE-2022-34384HIGHCVSS 7.8EG 7.82023-02-11
Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vuln…
- CVE-2022-34438MEDIUMCVSS 6.7EG 6.72022-10-21
Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges could potentially exploit this vulnerability, leading to full system compromise. This imp…
- CVE-2022-34691HIGHCVSS 8.8EG 8.82022-08-09
Active Directory Domain Services Elevation of Privilege Vulnerability
- CVE-2022-34699HIGHCVSS 7.8EG 7.82022-08-09
Windows Win32k Elevation of Privilege Vulnerability
- CVE-2022-34703HIGHCVSS 7.8EG 7.82022-08-09
Windows Partition Management Driver Elevation of Privilege Vulnerability
- CVE-2022-34706HIGHCVSS 7.8EG 7.82022-08-09
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
- CVE-2022-34754MEDIUMCVSS 6.8EG 6.82022-07-13
A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing credentials. Affected Products: Acti9 PowerTag Link C (A9XELC10-A) (V1.7.5 and prior), Acti9 PowerTag Link C (A9XELC10-B) (…
- CVE-2022-34858CRITICALCVSS 9.8EG 9.82022-08-22
Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.
- CVE-2022-35243CRITICALCVSS 8.7EG 9.12022-08-04
In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.5.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode r…
- CVE-2022-35257HIGHCVSS 7.8EG 7.82022-09-23
A local privilege escalation vulnerability in UI Desktop for Windows (Version 0.55.1.2 and earlier) allows a malicious actor with local access to a Windows device with UI Desktop to run arbitrary commands as SYSTEM.
- CVE-2022-35291HIGHCVSS 8.1EG 8.12022-07-27
Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin privileges over the network. These APIs were consumed in the SF Mobile application for Tim…
- CVE-2022-3569HIGHCVSS 7.8EG 7.82022-10-17
Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary co…
- CVE-2022-35761HIGHCVSS 7.8EG 8.42022-08-09
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2022-35762HIGHCVSS 7.8EG 7.82022-08-09
Storage Spaces Direct Elevation of Privilege Vulnerability
- CVE-2022-35763HIGHCVSS 7.8EG 7.82022-08-09
Storage Spaces Direct Elevation of Privilege Vulnerability
- CVE-2022-35764HIGHCVSS 7.8EG 7.82022-08-09
Storage Spaces Direct Elevation of Privilege Vulnerability
- CVE-2022-35765HIGHCVSS 7.8EG 7.82022-08-09
Storage Spaces Direct Elevation of Privilege Vulnerability
- CVE-2022-35768HIGHCVSS 7.8EG 7.82022-08-09
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2022-35771HIGHCVSS 7.8EG 7.82022-08-09
Windows Defender Credential Guard Elevation of Privilege Vulnerability
- CVE-2022-35774MEDIUMCVSS 4.9EG 4.92022-08-09
Azure Site Recovery Elevation of Privilege Vulnerability
- CVE-2022-35775MEDIUMCVSS 6.5EG 6.52022-08-09
Azure Site Recovery Elevation of Privilege Vulnerability
- CVE-2022-35780MEDIUMCVSS 6.5EG 6.52022-08-09
Azure Site Recovery Elevation of Privilege Vulnerability
- CVE-2022-35781MEDIUMCVSS 6.5EG 6.52022-08-09
Azure Site Recovery Elevation of Privilege Vulnerability
- CVE-2022-35782MEDIUMCVSS 6.5EG 6.52022-08-09
Azure Site Recovery Elevation of Privilege Vulnerability
- CVE-2022-35841HIGHCVSS 8.8EG 8.82022-09-13
Windows Enterprise App Management Service Remote Code Execution Vulnerability
- CVE-2022-35921LOWCVSS 3.5EG 3.52022-08-01
fof/byobu is a private discussions extension for Flarum forum. Affected versions were found to not respect private discussion disablement by users. Users of Byobu should update the extension to version 1.1.7, where this has been patched. U…
- CVE-2022-36075LOWCVSS 2.6EG 2.62022-09-15
Nextcloud files access control is a nextcloud app to manage access control for files. Users with limited access can see file names in certain cases where they do not have privilege to do so. This issue has been addressed and it is recommen…
- CVE-2022-36088MEDIUMCVSS 5.0EG 5.02022-09-07
GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately restrict permissions when installing outside of the default location. This could allow a malic…
- CVE-2022-36157HIGHCVSS 8.8EG 8.82022-08-19
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.
- CVE-2022-3641HIGHCVSS 8.8EG 8.82022-12-12
Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated user to spoof a privileged account.
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →