CWE-269
Improper Privilege Management
Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-122 · CAPEC-233 · CAPEC-58
CVEs mapped to this weakness (3,267)
page 109 of 164| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-59705 | Med | 0.44 | 6.8 | 0.00 | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe insertion during system boot, aka "Unauthorized Reactivation of the USB interface"… | ||
| CVE-2025-64507 | Hig | 0.44 | 7.8 | 0.00 | Nov 10, 2025 | Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a container with an attached custom storage volume that has the `security.shifted`… | ||
| CVE-2025-43722 | Med | 0.44 | 6.7 | 0.00 | Sep 8, 2025 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | ||
| CVE-2025-8453 | Med | 0.44 | 6.7 | 0.00 | Aug 20, 2025 | CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code execution when a privileged engineer user with console access modifies a configuration file used by a root-level daemon to execute custom scripts. | ||
| CVE-2025-5028 | Med | 0.44 | — | 0.00 | Jul 11, 2025 | Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without having the permissions to do so. | ||
| CVE-2025-5687 | Hig | 0.44 | 7.8 | 0.00 | Jun 11, 2025 | A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects Mozilla VPN on macOS. Other operating systems are unaffected.*. This vulnerability was fixed in Mozilla VPN 2.28.0 (macOS). | ||
| CVE-2025-1732 | Med | 0.44 | 6.7 | 0.00 | Apr 22, 2025 | An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges… | ||
| CVE-2025-29999 | Med | 0.44 | 6.7 | 0.00 | Apr 8, 2025 | A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application searches for executable files in the application folder without proper validation. This could allow an attacker to execute arbitrary code with administrative… | ||
| CVE-2025-28401 | Med | 0.44 | 6.7 | 0.00 | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter | ||
| CVE-2025-28400 | Med | 0.44 | 6.7 | 0.00 | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method | ||
| CVE-2024-57062 | Med | 0.44 | 6.7 | 0.00 | Mar 13, 2025 | An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive information via the session handling component. | ||
| CVE-2025-21199 | Med | 0.44 | 6.7 | 0.00 | Mar 11, 2025 | Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-1121 | Med | 0.44 | 6.8 | 0.00 | Mar 7, 2025 | Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image. | ||
| CVE-2024-52336 | Hig | 0.44 | 7.8 | 0.00 | Nov 26, 2024 | A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw allows a local non-privileged user to execute a D-Bus call with `script_pre` or `script_post`… | ||
| CVE-2024-38818 | Med | 0.44 | 6.7 | 0.00 | Oct 9, 2024 | VMware NSX contains a local privilege escalation vulnerability. An authenticated malicious actor may exploit this vulnerability to obtain permissions from a separate group role than previously assigned. | ||
| CVE-2024-39574 | Med | 0.44 | 6.7 | 0.00 | Sep 10, 2024 | Dell PowerScale InsightIQ, version 5.1, contain an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service. | ||
| CVE-2024-37726 | Med | 0.44 | 6.8 | 0.01 | Jul 3, 2024 | Insecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to escalate privileges via the Export System Info function in MSI.CentralServer.exe | ||
| CVE-2024-37133 | Med | 0.44 | 6.7 | 0.00 | Jul 2, 2024 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain of root-level access. | ||
| CVE-2024-37126 | Med | 0.44 | 6.7 | 0.00 | Jul 2, 2024 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain of root-level access. | ||
| CVE-2024-32854 | Med | 0.44 | 6.7 | 0.00 | Jul 2, 2024 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to privilege escalation. |
- risk 0.44cvss 6.8epss 0.00
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe insertion during system boot, aka "Unauthorized Reactivation of the USB interface"…
- risk 0.44cvss 7.8epss 0.00
Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a container with an attached custom storage volume that has the `security.shifted`…
- risk 0.44cvss 6.7epss 0.00
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
- risk 0.44cvss 6.7epss 0.00
CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code execution when a privileged engineer user with console access modifies a configuration file used by a root-level daemon to execute custom scripts.
- risk 0.44cvss —epss 0.00
Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without having the permissions to do so.
- risk 0.44cvss 7.8epss 0.00
A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects Mozilla VPN on macOS. Other operating systems are unaffected.*. This vulnerability was fixed in Mozilla VPN 2.28.0 (macOS).
- risk 0.44cvss 6.7epss 0.00
An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges…
- risk 0.44cvss 6.7epss 0.00
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application searches for executable files in the application folder without proper validation. This could allow an attacker to execute arbitrary code with administrative…
- risk 0.44cvss 6.7epss 0.00
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter
- risk 0.44cvss 6.7epss 0.00
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method
- risk 0.44cvss 6.7epss 0.00
An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive information via the session handling component.
- risk 0.44cvss 6.7epss 0.00
Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.8epss 0.00
Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.
- risk 0.44cvss 7.8epss 0.00
A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw allows a local non-privileged user to execute a D-Bus call with `script_pre` or `script_post`…
- risk 0.44cvss 6.7epss 0.00
VMware NSX contains a local privilege escalation vulnerability. An authenticated malicious actor may exploit this vulnerability to obtain permissions from a separate group role than previously assigned.
- risk 0.44cvss 6.7epss 0.00
Dell PowerScale InsightIQ, version 5.1, contain an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.
- risk 0.44cvss 6.8epss 0.01
Insecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to escalate privileges via the Export System Info function in MSI.CentralServer.exe
- risk 0.44cvss 6.7epss 0.00
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain of root-level access.
- risk 0.44cvss 6.7epss 0.00
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain of root-level access.
- risk 0.44cvss 6.7epss 0.00
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to privilege escalation.