CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,558 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 57 of 92
- CVE-2022-36443HIGHCVSS 7.8EG 7.82023-01-10
An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The device allows the administrator to lock some communication channels (wireless and SD card) but it is still possible to use a physical connection (Ethernet cable) without r…
- CVE-2022-36536CRITICALCVSS 9.8EG 9.82022-09-16
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.
- CVE-2022-36772MEDIUMCVSS 6.5EG 6.52022-10-07
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user.
- CVE-2022-36793CRITICALCVSS 6.5EG 9.12022-09-09
Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress.
- CVE-2022-36832MEDIUMCVSS 4.0EG 4.02022-08-05
Improper access control vulnerability in WebApp in Cameralyzer prior to versions 3.2.22, 3.3.22, 3.4.22 and 3.5.51 allows attackers to access external storage as Cameralyzer privilege.
- CVE-2022-36833HIGHCVSS 7.3EG 7.82022-08-05
Improper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5.04.8 in Android 11 and above allows local attacker to execute hidden function for developer by changing package name.
- CVE-2022-36861MEDIUMCVSS 5.9EG 5.92022-09-09
Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege.
- CVE-2022-37002CRITICALCVSS 9.8EG 9.82022-08-10
The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background.
- CVE-2022-3701HIGHCVSS 7.8EG 7.82023-10-27
A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local attacker to execute arbitrary code with elevated privileges.
- CVE-2022-37015CRITICALCVSS 9.8EG 9.82022-11-08
Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain …
- CVE-2022-37016CRITICALCVSS 9.8EG 9.82022-12-01
Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources t…
- CVE-2022-37019MEDIUMCVSS 6.8EG 6.82024-06-10
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
- CVE-2022-37025HIGHCVSS 7.8EG 7.82022-08-18
An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user ga…
- CVE-2022-37706HIGHCVSS 7.8EG 7.82022-12-25
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the system library function mishandles pathnames that begin with a /dev/.. substring.
- CVE-2022-37929MEDIUMCVSS 6.7EG 6.72022-12-12
Improper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.
- CVE-2022-37954HIGHCVSS 7.8EG 8.12022-09-13
DirectX Graphics Kernel Elevation of Privilege Vulnerability
- CVE-2022-37968CRITICALCVSS 10.0EG 10.02022-10-11
Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative…
- CVE-2022-37970HIGHCVSS 7.8EG 7.82022-10-11
Windows DWM Core Library Elevation of Privilege Vulnerability
- CVE-2022-37971HIGHCVSS 7.1EG 7.12022-10-11
Microsoft Windows Defender Elevation of Privilege Vulnerability
- CVE-2022-37975HIGHCVSS 8.8EG 8.82022-10-11
Windows Group Policy Elevation of Privilege Vulnerability
- CVE-2022-37976HIGHCVSS 8.8EG 8.82022-10-11
Active Directory Certificate Services Elevation of Privilege Vulnerability
- CVE-2022-37979HIGHCVSS 7.8EG 7.82022-10-11
Windows Hyper-V Elevation of Privilege Vulnerability
- CVE-2022-38007HIGHCVSS 7.8EG 7.82022-09-13
Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability
- CVE-2022-38058MEDIUMCVSS 4.3EG 4.32022-09-09
Authenticated (subscriber+) Plugin Setting change vulnerability in WP Shamsi plugin <= 4.1.1 at WordPress.
- CVE-2022-38060HIGHCVSS 8.8EG 8.82022-12-21
A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.
- CVE-2022-38065HIGHCVSS 8.8EG 8.82022-12-21
A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileg…
- CVE-2022-38070HIGHCVSS 5.4EG 8.82022-09-09
Privilege Escalation (subscriber+) vulnerability in Pop-up plugin <= 1.1.5 at WordPress.
- CVE-2022-38124MEDIUMCVSS 5.7EG 6.52022-12-13
Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.
- CVE-2022-38351HIGHCVSS 8.8EG 8.82022-09-19
A vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted PUT request to the update profile page.
- CVE-2022-38378MEDIUMCVSS 4.2EG 6.02023-02-16
An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has access to the admin profile section (System…
- CVE-2022-38757HIGHCVSS 7.2EG 7.22022-12-23
A vulnerability has been identified in Micro Focus ZENworks 2020 Update 3a and prior versions. This vulnerability allows administrators with rights to perform actions (e.g., install a bundle) on a set of managed devices, to be able to exer…
- CVE-2022-38774HIGHCVSS 7.8EG 7.82023-01-26
An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
- CVE-2022-38775HIGHCVSS 7.8EG 7.82023-01-26
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
- CVE-2022-38777HIGHCVSS 7.8EG 7.82023-02-08
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
- CVE-2022-39007CRITICALCVSS 9.8EG 9.82022-09-16
The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerability may cause privilege escalation.
- CVE-2022-39032HIGHCVSS 8.8EG 8.82022-09-28
Smart eVision has an improper privilege management vulnerability. A remote attacker with general user privilege can exploit this vulnerability to escalate to administrator privilege, and then perform arbitrary system command or disrupt ser…
- CVE-2022-3911HIGHCVSS 8.8EG 8.82023-01-02
The iubenda WordPress plugin before 3.3.3 does does not have authorisation and CSRF in an AJAX action, and does not ensure that the options to be updated belong to the plugin as long as they are arrays. As a result, any authenticated users…
- CVE-2022-39182HIGHCVSS 4.9EG 8.82023-01-12
H C Mingham-Smith Ltd - Tardis 2000 Privilege escalation.Version 1.6 is vulnerable to privilege escalation which may allow a malicious actor to gain system privileges.
- CVE-2022-39202MEDIUMCVSS 4.3EG 4.32022-09-13
matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. The Internet Relay Chat (IRC) protocol allows you to specify multiple modes in a single mode command. Due to a bug in the underlying matrix-org/node-irc library, affect…
- CVE-2022-39203HIGHCVSS 8.8EG 8.82022-09-13
matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. Attackers can specify a specific string of characters, which would confuse the bridge into combining an attacker-owned channel and an existing channel, allowing them to…
- CVE-2022-39286HIGHCVSS 8.8EG 8.82022-10-26
Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted f…
- CVE-2022-39395CRITICALCVSS 9.6EG 9.62022-11-10
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela Server and Vela Worker prior to version 0.16.0 and Vela UI prior to version 0.17.0, some default configurations for Vela allow e…
- CVE-2022-39422HIGHCVSS 7.5EG 7.52022-10-18
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.38. Difficult to exploit vulnerability allows high privileged attacker with logon to the in…
- CVE-2022-39877MEDIUMCVSS 4.0EG 5.32022-10-07
Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.
- CVE-2022-3990HIGHCVSS 7.8EG 7.82023-02-01
HPSFViewer might allow Escalation of Privilege. This potential vulnerability was remediated on July 29th, 2022. Customers who opted for automatic updates should have already received the remediation.
- CVE-2022-39953HIGHCVSS 7.8EG 7.82023-03-07
A improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6, FortiNAC version 9.1.0 through 9.1.8, FortiNAC all versions 8.8, FortiNAC all versions 8.7, FortiNAC all versions 8.6, …
- CVE-2022-40142HIGHCVSS 7.8EG 7.82022-09-19
A security link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service agents could allow a local attacker to create a writable folder in an arbitrary location and escalate privileg…
- CVE-2022-40297HIGHCVSS 7.8EG 7.82022-09-09
UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode is only four digits, far below typical length/complexity for a user account's password. NOTE: a third party states "The …
- CVE-2022-40299HIGHCVSS 7.8EG 7.82022-09-09
In Singular before 4.3.1, a predictable /tmp pathname is used (e.g., by sdb.cc), which allows local users to gain the privileges of other users via a procedure in a file under /tmp. NOTE: this CVE Record is about sdb.cc and similar files i…
- CVE-2022-4041HIGHCVSS 5.9EG 8.82023-01-31
Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.8.0 before 0…
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →