CWE-269: Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

813
Total CVEs
170
Critical
553
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
50
2025
213
2024
225
2023
118
2022
49

Top Affected Vendors

1 Microsoft 81
2 Google 46
3 Huawei 26
4 Apple 20
5 Oracle 19
6 Trendmicro 13
7 Dell 11
8 Fortinet 8
9 Apache 7
10 Citrix 7

All Improper Privilege Management CVEs (813)

CVE-2021-31168
7.8

This vulnerability allows local attackers to escalate privileges on Windows systems by exploiting a flaw in the Container Manager Service. Attackers c...

May 11, 2021
CVE-2020-27518
7.8

CVE-2020-27518 is a local privilege escalation vulnerability in Windscribe VPN's WindscribeService component. Attackers with low-privilege access can ...

May 4, 2021
CVE-2020-27519
7.8

CVE-2020-27519 is a local privilege escalation vulnerability in Pritunl Client's pritunl-service component. Attackers can exploit malicious OpenVPN co...

Apr 30, 2021
CVE-2021-31523
7.8

This vulnerability allows local users on Debian systems with xscreensaver 5.42+dfsg1-1 to escalate privileges due to improper capability assignment. T...

Apr 21, 2021
CVE-2021-21981
7.8

CVE-2021-21981 is a privilege escalation vulnerability in VMware NSX-T where local guest users can assign themselves higher RBAC privileges than autho...

Apr 19, 2021
CVE-2021-23887
7.8

This CVE describes a local privilege escalation vulnerability in McAfee DLP Endpoint for Windows. A low-privileged local attacker can write to arbitra...

Apr 15, 2021
CVE-2021-28313
7.8

CVE-2021-28313 is an elevation of privilege vulnerability in Microsoft's Diagnostics Hub Standard Collector Service. It allows authenticated attackers...

Apr 13, 2021
CVE-2021-1802
7.8

CVE-2021-1802 is a local privilege escalation vulnerability in macOS that allows an attacker with local access to gain elevated system privileges. Thi...

Apr 2, 2021
CVE-2021-1787
7.8

CVE-2021-1787 is a privilege escalation vulnerability in Apple operating systems that allows a local attacker to gain elevated privileges. This affect...

Apr 2, 2021
CVE-2020-29620
7.8

This macOS vulnerability allows malicious applications to bypass security restrictions and gain elevated privileges. It affects macOS systems running ...

Apr 2, 2021
CVE-2020-27938
7.8

CVE-2020-27938 is a privilege escalation vulnerability in macOS that allows malicious applications to gain elevated system privileges. This affects ma...

Apr 2, 2021
CVE-2021-28250
7.8

CVE-2021-28250 is a privilege escalation vulnerability in CA eHealth Performance Manager where the runpicEhealth executable improperly handles setuid/...

Mar 26, 2021
CVE-2021-27192
7.8

This CVE describes a local privilege escalation vulnerability in Netop Vision Pro Windows clients. It allows a local user with standard privileges to ...

Mar 25, 2021
CVE-2021-1640
7.8

CVE-2021-1640 is a privilege escalation vulnerability in the Windows Print Spooler service that allows authenticated attackers to execute arbitrary co...

Mar 11, 2021
CVE-2021-24102
7.8

CVE-2021-24102 is a Windows Event Tracing elevation of privilege vulnerability that allows authenticated attackers to execute arbitrary code with SYST...

Feb 25, 2021
CVE-2021-24092
7.8

This vulnerability in Microsoft Defender allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting improper hand...

Feb 25, 2021
CVE-2021-1698
7.8

This is a Windows Win32k elevation of privilege vulnerability that allows authenticated attackers to execute arbitrary code with SYSTEM privileges. It...

Feb 25, 2021
CVE-2021-26936
7.8

This vulnerability allows a local attacker to escalate privileges to root by manipulating video output paths in ReplaySorcery's default setuid-root co...

Feb 10, 2021
CVE-2021-0327
7.8

This vulnerability allows local attackers to bypass Android's permission system by exploiting a flaw in how binder identities are restored in the Acti...

Feb 10, 2021
CVE-2021-23876
7.8

This vulnerability allows a local user on a Windows system to bypass security controls in McAfee Total Protection, gaining SYSTEM-level privileges to ...

Feb 10, 2021
CVE-2021-1687
7.8

CVE-2021-1687 is an elevation of privilege vulnerability in Windows WalletService that allows authenticated attackers to execute arbitrary code with S...

Jan 12, 2021
CVE-2021-1689
7.8

CVE-2021-1689 is an elevation of privilege vulnerability in Windows Multipoint Management that allows authenticated attackers to execute arbitrary cod...

Jan 12, 2021
CVE-2021-1693
7.8

CVE-2021-1693 is an elevation of privilege vulnerability in the Windows Client Side Caching (CSC) service. It allows authenticated attackers to execut...

Jan 12, 2021
CVE-2021-1695
7.8

CVE-2021-1695 is an elevation of privilege vulnerability in the Windows Print Spooler service that allows authenticated attackers to execute arbitrary...

Jan 12, 2021
CVE-2021-1697
7.8

CVE-2021-1697 is an elevation of privilege vulnerability in Windows InstallService that allows authenticated attackers to execute arbitrary code with ...

Jan 12, 2021
CVE-2021-1702
7.8

CVE-2021-1702 is an elevation of privilege vulnerability in Windows Remote Procedure Call (RPC) Runtime that allows authenticated attackers to execute...

Jan 12, 2021
CVE-2021-1680
7.8

CVE-2021-1680 is an elevation of privilege vulnerability in Windows Diagnostics Hub Standard Collector. It allows authenticated attackers to execute a...

Jan 12, 2021
CVE-2021-1653
7.8

CVE-2021-1653 is an elevation of privilege vulnerability in the Windows Client Side Caching (CSC) service. It allows authenticated attackers to execut...

Jan 12, 2021
CVE-2021-1655
7.8

This vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges on Windows systems by exploiting the Client Side ...

Jan 12, 2021
CVE-2021-1657
7.8

CVE-2021-1657 is a remote code execution vulnerability in the Windows Fax Compose Form. An attacker could exploit this by tricking a user into opening...

Jan 12, 2021
CVE-2021-1659
7.8

This vulnerability allows a local authenticated attacker to execute arbitrary code with SYSTEM privileges on Windows systems. It affects Windows Clien...

Jan 12, 2021
CVE-2021-1642
7.8

This vulnerability in Windows AppX Deployment Extensions allows attackers to elevate privileges on affected systems. An authenticated attacker could e...

Jan 12, 2021
CVE-2021-1649
7.8

This vulnerability in Microsoft's Active Template Library allows attackers to execute arbitrary code with elevated privileges on affected systems. It ...

Jan 12, 2021
CVE-2021-1651
7.8

This vulnerability allows a local attacker to execute arbitrary code with SYSTEM privileges on Windows systems. It affects Windows 10, Windows Server ...

Jan 12, 2021
CVE-2021-0306
7.8

This vulnerability allows Android apps to bypass permission checks during major version upgrades, granting them the ACTIVITY_RECOGNITION permission wi...

Jan 11, 2021
CVE-2018-8724
7.8

CVE-2018-8724 is a local privilege escalation vulnerability in K7AntiVirus Premium where the K7TSMngr.exe component has incorrect access control. This...

Jan 11, 2021
CVE-2020-8290
7.8

This vulnerability allows local attackers to escalate privileges on systems running vulnerable Backblaze backup software. By exploiting improper permi...

Dec 27, 2020
CVE-2020-25106
7.8

CVE-2020-25106 is a privilege escalation vulnerability in Nanosystems SupRemo 4.1.3.2348 that allows attackers to rename the legitimate Supremo.exe fi...

Dec 22, 2020
CVE-2020-9114
7.8

This CVE-2020-9114 is a privilege escalation vulnerability in Huawei FusionCompute virtualization software. Attackers with common user privileges can ...

Dec 1, 2020
CVE-2020-16902
7.8

This Windows Installer vulnerability allows a local attacker to execute arbitrary code with SYSTEM privileges by exploiting improper input sanitizatio...

Oct 16, 2020
CVE-2019-1162
7.8

CVE-2019-1162 is a Windows privilege escalation vulnerability in the Advanced Local Procedure Call (ALPC) mechanism. An attacker with local access can...

Aug 14, 2019
CVE-2026-23477
7.7

This vulnerability allows any authenticated Rocket.Chat user to access OAuth application credentials (client_id and client_secret) by querying the /ap...

Jan 14, 2026
CVE-2025-67826
7.7

A Local Privilege Escalation vulnerability in K7 Ultimate Security allows unprivileged local users to edit any registry key via insecure named pipe ac...

Dec 22, 2025
CVE-2025-7044
7.7

An authenticated attacker can exploit improper input validation in MAAS's websocket handler to self-promote to administrator by injecting the is_super...

Dec 3, 2025
CVE-2025-50069
7.7

This vulnerability in Oracle Database Server's Java VM component allows attackers with low privileges (Create Session, Create Procedure) and network a...

Jul 15, 2025
CVE-2024-4545
7.7

This vulnerability in EnterpriseDB Postgres Advanced Server (EPAS) allows low-privilege users using the edbldr utility to bypass role permissions and ...

May 14, 2024
CVE-2024-3507
7.7

This CVE describes an improper privilege management vulnerability in Lunar software that allows attackers to perform secondary process injection. By e...

May 8, 2024
CVE-2023-36496
7.7

This vulnerability in PingDirectory's Delegated Admin Privilege virtual attribute provider plugin allows authenticated users to elevate their permissi...

Feb 1, 2024
CVE-2023-1326
7.7

This CVE describes a local privilege escalation vulnerability in apport-cli versions 2.26.0 and earlier. It allows unprivileged users to gain root pri...

Apr 13, 2023
CVE-2022-26113
7.7

This vulnerability in FortiClient for Windows allows a local attacker to write arbitrary files to the system due to unnecessary privileges. It affects...

Jul 19, 2022

About Improper Privilege Management (CWE-269)

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

Our database tracks 813 CVEs classified as CWE-269, with 170 rated critical and 553 rated high severity. The average CVSS score for Improper Privilege Management vulnerabilities is 8.1.

External reference: View CWE-269 on MITRE CWE →

Monitor Improper Privilege Management Vulnerabilities

Get alerted when new Improper Privilege Management CVEs affect your infrastructure.

Start Monitoring Free