CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,558 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 58 of 92
- CVE-2022-40772MEDIUMCVSS 6.5EG 6.52022-11-23
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module.
- CVE-2022-41032HIGHCVSS 7.8EG 7.82022-10-11
NuGet Client Elevation of Privilege Vulnerability
- CVE-2022-41040CRITICALCVSS 8.8EG 9.0⚠ KEV2022-10-03
Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2022-41115MEDIUMCVSS 6.6EG 6.62022-12-13
Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
- CVE-2022-41268HIGHCVSS 8.5EG 8.52022-12-13
In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By implementing such tran…
- CVE-2022-41290HIGHCVSS 8.4EG 8.42022-12-23
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache_file command to obtain root privileges. IBM X-Force ID: 236690.
- CVE-2022-41339HIGHCVSS 7.8EG 7.82022-11-12
In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation.
- CVE-2022-41604HIGHCVSS 8.8EG 8.82022-09-27
Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissions for the %PROGRAMDATA%\CheckPoint\ZoneAlarm\Data\Updates directory, and a self-protection driver…
- CVE-2022-41700MEDIUMCVSS 6.7EG 6.72023-11-14
Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-4173HIGHCVSS 7.3EG 8.82022-12-06
A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus …
- CVE-2022-41835HIGHCVSS 7.3EG 8.82022-10-19
In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute limited set of commands in a container and impact the F5OS controller.
- CVE-2022-41923CRITICALCVSS 9.1EG 9.12022-11-23
Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to one endpoint (i.e. the targeted endpoint) using the authorization requirements of a different endpoint (i.e. the donor…
- CVE-2022-41948MEDIUMCVSS 6.7EG 6.72022-12-08
DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Affected versions are subject to a privilege escalation vulnerability. A DHIS2 user with authority to manage users can assig…
- CVE-2022-41974HIGHCVSS 7.8EG 7.82022-10-29
multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate…
- CVE-2022-41975HIGHCVSS 7.8EG 7.82022-09-30
RealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI installer Repair mode.
- CVE-2022-42046HIGHCVSS 7.8EG 7.82022-12-20
wfshbr64.sys and wfshbr32.sys specially crafted IOCTL allows arbitrary user to perform local privilege escalation
- CVE-2022-42197MEDIUMCVSS 6.5EG 6.52022-10-20
In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges.
- CVE-2022-42238HIGHCVSS 8.8EG 8.82022-10-11
A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard.
- CVE-2022-42438HIGHCVSS 7.5EG 8.82023-02-08
IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin functions by specifying direct URL paths. IBM X-Force ID: 238210.
- CVE-2022-42455HIGHCVSS 7.8EG 7.82023-02-15
ASUS EC Tool driver (aka d.sys) 1beb15c90dcf7a5234ed077833a0a3e900969b60be1d04fcebce0a9f8994bdbb, as signed by ASUS and shipped with multiple ASUS software products, contains multiple IOCTL handlers that provide raw read and write access t…
- CVE-2022-42459HIGHCVSS 7.2EG 7.22022-11-18
Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress.
- CVE-2022-4264MEDIUMCVSS 6.5EG 6.52022-12-09
Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.
- CVE-2022-4270LOWCVSS 2.0EG 2.62022-12-02
Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permissions accidentally.
- CVE-2022-42717HIGHCVSS 7.8EG 7.82022-10-11
An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverag…
- CVE-2022-42735HIGHCVSS 8.8EG 8.82023-02-15
Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privilege low-level administrators create users with higher privileges than their own. This issue affects Apache ShenYu: 2.…
- CVE-2022-42796HIGHCVSS 7.8EG 7.82022-11-01
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.7 and iPadOS 15.7, macOS Ventura 13. An app may be able to gain elevated privileges.
- CVE-2022-4281HIGHCVSS 6.3EG 8.82022-12-05
A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /face-recognition-php/facepay-master/camera.php. The manipulation of the argument userId leads…
- CVE-2022-42849HIGHCVSS 7.8EG 7.82022-12-15
An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2, watchOS 9.2. A user may be able to elevate privileges.
- CVE-2022-42855HIGHCVSS 7.1EG 7.12022-12-15
A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlemen…
- CVE-2022-42888CRITICALCVSS 9.8EG 9.82022-12-06
Unauth. Privilege Escalation vulnerability in ARMember premium plugin <= 5.5.1 on WordPress.
- CVE-2022-4294HIGHCVSS 7.1EG 7.82023-01-10
Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resou…
- CVE-2022-4305CRITICALCVSS 9.8EG 9.82023-01-23
The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.
- CVE-2022-43138CRITICALCVSS 9.8EG 9.82022-11-17
Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.
- CVE-2022-4314CRITICALCVSS 9.8EG 9.82022-12-12
Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2.
- CVE-2022-43308HIGHCVSS 7.8EG 7.82022-11-18
INTELBRAS SG 2404 MR 20180928-rel64938 allows authenticated attackers to arbitrarily create Administrator accounts via crafted user cookies.
- CVE-2022-43533HIGHCVSS 7.8EG 7.82023-01-05
A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with root level privileges on th…
- CVE-2022-43534HIGHCVSS 7.8EG 7.82023-01-05
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with root level privileges on the…
- CVE-2022-43535HIGHCVSS 7.8EG 7.82023-01-05
A vulnerability in the ClearPass OnGuard Windows agent could allow malicious users on a Windows instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with NT AUTHORITY\SYSTEM leve…
- CVE-2022-43749HIGHCVSS 4.3EG 8.82022-10-26
Improper privilege management vulnerability in summary report management in Synology Presto File Server before 2.1.2-1601 allows remote authenticated users to bypass security constraint via unspecified vectors.
- CVE-2022-43759HIGHCVSS 7.2EG 7.22023-02-07
A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any -promoted resource in any cluster. This issue affects: SUSE Rancher Rancher versions prio…
- CVE-2022-43863HIGHCVSS 6.7EG 7.22023-03-22
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities. IBM X-Force ID: 239425.
- CVE-2022-43927HIGHCVSS 5.9EG 7.52023-02-17
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a specially crafted table access is used. IBM X-Force ID: 241671.
- CVE-2022-43997HIGHCVSS 7.8EG 7.82023-01-26
Incorrect access control in Aternity agent in Riverbed Aternity before 12.1.4.27 allows for local privilege escalation. There is an insufficiently protected handle to the A180AG.exe SYSTEM process with PROCESS_ALL_ACCESS rights.
- CVE-2022-4441HIGHCVSS 7.6EG 8.82023-01-31
Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.9.0 before 0…
- CVE-2022-44562CRITICALCVSS 9.8EG 9.82022-11-09
The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
- CVE-2022-44689HIGHCVSS 7.8EG 7.82022-12-13
Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
- CVE-2022-44708HIGHCVSS 8.3EG 8.32022-12-13
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2022-44710HIGHCVSS 7.8EG 7.82022-12-13
DirectX Graphics Kernel Elevation of Privilege Vulnerability
- CVE-2022-44732HIGHCVSS 7.8EG 7.82022-11-07
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39900.
- CVE-2022-44733HIGHCVSS 7.8EG 7.82022-11-07
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39900.
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →