CWE-269
Improper Privilege Management
Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-122 · CAPEC-233 · CAPEC-58
CVEs mapped to this weakness (3,267)
page 137 of 164| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-43663 | Med | 0.34 | 6.3 | 0.00 | Sep 28, 2023 | PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit `ce1f6708` addresses this… | ||
| CVE-2023-41312 | Med | 0.34 | 5.3 | 0.00 | Sep 27, 2023 | Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatically. | ||
| CVE-2023-29056 | Med | 0.34 | 5.3 | 0.00 | Apr 28, 2023 | A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined. | ||
| CVE-2021-4314 | Med | 0.34 | 5.3 | 0.00 | Jan 18, 2023 | It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue affects: 1.16 versions to 1.19. What… | ||
| CVE-2022-1901 | Med | 0.34 | 5.3 | 0.00 | Aug 19, 2022 | In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview. | ||
| CVE-2017-20107 | Med | 0.34 | 5.3 | 0.00 | Jun 28, 2022 | A vulnerability, which was classified as problematic, was found in ShadeYouVPN.com Client 2.0.1.11. Affected is an unknown function. The manipulation leads to improper privilege management. Local access is required to approach this attack. The exploit has been disclosed to the… | ||
| CVE-2022-30743 | Med | 0.34 | 5.3 | 0.00 | Jun 7, 2022 | Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission. | ||
| CVE-2022-30736 | Med | 0.34 | 5.3 | 0.00 | Jun 7, 2022 | Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission. | ||
| CVE-2022-0611 | Med | 0.34 | 6.3 | 0.01 | Feb 16, 2022 | Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11. | ||
| CVE-2017-13165 | Med | 0.34 | 5.3 | 0.00 | Dec 6, 2017 | An elevation of privilege vulnerability in the kernel file system. Product: Android. Versions: Android kernel. Android ID A-31269937. | ||
| CVE-2017-9662 | Med | 0.34 | 5.3 | 0.00 | Aug 14, 2017 | An Improper Privilege Management issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. Monitouch V-SFT is installed in a directory with weak access controls by default, which could allow an authenticated attacker with local access to escalate… | ||
| CVE-2026-11276 | Med | 0.33 | 5.1 | 0.00 | Jun 5, 2026 | Inappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to bypass discretionary access control via malicious network traffic. (Chromium security severity: Low) | ||
| CVE-2026-7778 | Med | 0.33 | 5.0 | 0.00 | May 5, 2026 | An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N… | ||
| CVE-2026-6386 | Med | 0.33 | 6.2 | 0.00 | Apr 22, 2026 | In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled this failed to take into account the presence of 1GB largepage mappings created using the shm_create_largepage(3)… | ||
| CVE-2026-40002 | Med | 0.33 | 5.0 | 0.00 | Apr 17, 2026 | Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting this vulnerability, an attacker can write… | ||
| CVE-2025-57443 | Med | 0.33 | 5.1 | 0.00 | Oct 2, 2025 | FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library-validation) that allow unprivileged local attackers to inject code into the FrostWire process via the DYLD_INSERT_LIBRARIES environment variable. This allows… | ||
| CVE-2024-23454 | Med | 0.33 | 6.2 | 0.00 | Sep 25, 2024 | Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the other local users may be able to view the content. This is because, on unix-like systems, the system temporary directory is… | ||
| CVE-2023-38496 | Med | 0.33 | 6.1 | 0.00 | Jul 25, 2023 | Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when requesting container network setup, therefore subsequent functions are called with root privileges, the attack surface is rather limited for users but an attacker… | ||
| CVE-2023-25188 | Med | 0.33 | 5.1 | 0.00 | Jun 16, 2023 | An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from the Nokia Single RAN BTS baseband unit, the BTS baseband unit diagnostic tool AaShell (which is by default disabled) allows… | ||
| CVE-2022-29614 | Med | 0.33 | 5.0 | 0.00 | Jun 14, 2022 | SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, SAPHOSTAGENT 7.22, -… |
- risk 0.34cvss 6.3epss 0.00
PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit `ce1f6708` addresses this…
- risk 0.34cvss 5.3epss 0.00
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatically.
- risk 0.34cvss 5.3epss 0.00
A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined.
- risk 0.34cvss 5.3epss 0.00
It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue affects: 1.16 versions to 1.19. What…
- risk 0.34cvss 5.3epss 0.00
In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.
- risk 0.34cvss 5.3epss 0.00
A vulnerability, which was classified as problematic, was found in ShadeYouVPN.com Client 2.0.1.11. Affected is an unknown function. The manipulation leads to improper privilege management. Local access is required to approach this attack. The exploit has been disclosed to the…
- risk 0.34cvss 5.3epss 0.00
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.
- risk 0.34cvss 5.3epss 0.00
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.
- risk 0.34cvss 6.3epss 0.01
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.
- risk 0.34cvss 5.3epss 0.00
An elevation of privilege vulnerability in the kernel file system. Product: Android. Versions: Android kernel. Android ID A-31269937.
- risk 0.34cvss 5.3epss 0.00
An Improper Privilege Management issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. Monitouch V-SFT is installed in a directory with weak access controls by default, which could allow an authenticated attacker with local access to escalate…
- risk 0.33cvss 5.1epss 0.00
Inappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to bypass discretionary access control via malicious network traffic. (Chromium security severity: Low)
- risk 0.33cvss 5.0epss 0.00
An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N…
- risk 0.33cvss 6.2epss 0.00
In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled this failed to take into account the presence of 1GB largepage mappings created using the shm_create_largepage(3)…
- risk 0.33cvss 5.0epss 0.00
Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting this vulnerability, an attacker can write…
- risk 0.33cvss 5.1epss 0.00
FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library-validation) that allow unprivileged local attackers to inject code into the FrostWire process via the DYLD_INSERT_LIBRARIES environment variable. This allows…
- risk 0.33cvss 6.2epss 0.00
Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the other local users may be able to view the content. This is because, on unix-like systems, the system temporary directory is…
- risk 0.33cvss 6.1epss 0.00
Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when requesting container network setup, therefore subsequent functions are called with root privileges, the attack surface is rather limited for users but an attacker…
- risk 0.33cvss 5.1epss 0.00
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from the Nokia Single RAN BTS baseband unit, the BTS baseband unit diagnostic tool AaShell (which is by default disabled) allows…
- risk 0.33cvss 5.0epss 0.00
SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, SAPHOSTAGENT 7.22, -…