CWE-269
Improper Privilege Management
Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-122 · CAPEC-233 · CAPEC-58
CVEs mapped to this weakness (3,702)
page 168 of 186| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-3388 | Med | 0.27 | 4.1 | 0.00 | Apr 10, 2024 | A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive response packets from… | ||
| CVE-2023-45083 | Med | 0.27 | 4.2 | 0.00 | Dec 5, 2023 | An Improper Privilege Management vulnerability exists in HyperCloud that will impact the ability for a user to authenticate against the management plane. An authenticated admin-level user may be able to delete the "admin" or "serveradmin" users, which prevents authentication… | ||
| CVE-2023-38058 | Med | 0.27 | 4.1 | 0.00 | Jul 24, 2023 | An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated attacker to to perform a move of an ticket without the needed permission. This issue affects OTRS: from 8.0.X before 8.0.35. | ||
| CVE-2023-2679 | Med | 0.27 | 4.1 | 0.00 | May 17, 2023 | Data leakage in Adobe connector in Snow Software SPE 9.27.0 on Windows allows privileged user to observe other users data. | ||
| CVE-2022-38378 | Med | 0.27 | 4.2 | 0.00 | Feb 16, 2023 | An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has access to the admin profile section (System subsection Administrator Users) to… | ||
| CVE-2023-25173 | Med | 0.27 | 5.3 | 0.01 | Feb 16, 2023 | containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group… | ||
| CVE-2022-24927 | Med | 0.27 | 4.2 | 0.00 | Feb 11, 2022 | Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission. | ||
| CVE-2020-26080 | Med | 0.27 | 4.1 | 0.01 | Nov 18, 2020 | A vulnerability in the user management functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to manage user information for users in different domains on an affected system. The vulnerability is due to improper domain access… | ||
| CVE-2020-8179 | Med | 0.27 | 4.1 | 0.01 | Jul 2, 2020 | Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks. | ||
| CVE-2026-20607 | Med | 0.26 | 4.0 | 0.00 | Mar 25, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access protected user data. | ||
| CVE-2025-24353 | Med | 0.26 | 5.0 | 0.00 | Jan 23, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.2.0, when sharing an item, a typical user can specify an arbitrary role. It allows the user to use a higher-privileged role to see fields that otherwise the user should not be… | ||
| CVE-2023-23438 | Med | 0.26 | 4.0 | 0.00 | Dec 29, 2023 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions | ||
| CVE-2023-23429 | Med | 0.26 | 4.0 | 0.00 | Dec 29, 2023 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | ||
| CVE-2023-23427 | Med | 0.26 | 4.0 | 0.00 | Dec 29, 2023 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | ||
| CVE-2022-30739 | Med | 0.26 | 4.0 | 0.00 | Jun 7, 2022 | Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number with a normal level permission. | ||
| CVE-2022-29587 | Med | 0.26 | 4.0 | 0.00 | May 16, 2022 | Konica Minolta bizhub MFP devices before 2022-04-14 have an internal Chromium browser that executes with root (aka superuser) access privileges. | ||
| CVE-2022-22266 | Med | 0.26 | 4.0 | 0.00 | Jan 10, 2022 | (Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission. | ||
| CVE-2022-22263 | Med | 0.26 | 4.0 | 0.00 | Jan 10, 2022 | Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity. | ||
| CVE-2021-25515 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2021 | An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID. | ||
| CVE-2021-36943 | Med | 0.26 | 4.0 | 0.01 | Aug 12, 2021 | Azure CycleCloud Elevation of Privilege Vulnerability |
- risk 0.27cvss 4.1epss 0.00
A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive response packets from…
- risk 0.27cvss 4.2epss 0.00
An Improper Privilege Management vulnerability exists in HyperCloud that will impact the ability for a user to authenticate against the management plane. An authenticated admin-level user may be able to delete the "admin" or "serveradmin" users, which prevents authentication…
- risk 0.27cvss 4.1epss 0.00
An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated attacker to to perform a move of an ticket without the needed permission. This issue affects OTRS: from 8.0.X before 8.0.35.
- risk 0.27cvss 4.1epss 0.00
Data leakage in Adobe connector in Snow Software SPE 9.27.0 on Windows allows privileged user to observe other users data.
- risk 0.27cvss 4.2epss 0.00
An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has access to the admin profile section (System subsection Administrator Users) to…
- risk 0.27cvss 5.3epss 0.01
containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group…
- risk 0.27cvss 4.2epss 0.00
Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission.
- risk 0.27cvss 4.1epss 0.01
A vulnerability in the user management functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to manage user information for users in different domains on an affected system. The vulnerability is due to improper domain access…
- risk 0.27cvss 4.1epss 0.01
Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.
- risk 0.26cvss 4.0epss 0.00
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access protected user data.
- risk 0.26cvss 5.0epss 0.00
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.2.0, when sharing an item, a typical user can specify an arbitrary role. It allows the user to use a higher-privileged role to see fields that otherwise the user should not be…
- risk 0.26cvss 4.0epss 0.00
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions
- risk 0.26cvss 4.0epss 0.00
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
- risk 0.26cvss 4.0epss 0.00
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
- risk 0.26cvss 4.0epss 0.00
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number with a normal level permission.
- risk 0.26cvss 4.0epss 0.00
Konica Minolta bizhub MFP devices before 2022-04-14 have an internal Chromium browser that executes with root (aka superuser) access privileges.
- risk 0.26cvss 4.0epss 0.00
(Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.
- risk 0.26cvss 4.0epss 0.00
Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity.
- risk 0.26cvss 4.0epss 0.00
An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.
- risk 0.26cvss 4.0epss 0.01
Azure CycleCloud Elevation of Privilege Vulnerability