CWE-269: Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

816
Total CVEs
170
Critical
556
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
50
2025
213
2024
225
2023
118
2022
49

Top Affected Vendors

1 Microsoft 81
2 Google 46
3 Huawei 26
4 Apple 20
5 Oracle 19
6 Trendmicro 13
7 Dell 11
8 Cisco 9
9 Fortinet 8
10 Apache 7

All Improper Privilege Management CVEs (816)

CVE-2023-36496
7.7

This vulnerability in PingDirectory's Delegated Admin Privilege virtual attribute provider plugin allows authenticated users to elevate their permissi...

Feb 1, 2024
CVE-2023-1326
7.7

This CVE describes a local privilege escalation vulnerability in apport-cli versions 2.26.0 and earlier. It allows unprivileged users to gain root pri...

Apr 13, 2023
CVE-2022-26113
7.7

This vulnerability in FortiClient for Windows allows a local attacker to write arbitrary files to the system due to unnecessary privileges. It affects...

Jul 19, 2022
CVE-2022-29218
7.7

A cache poisoning vulnerability in RubyGems allowed malicious packages to temporarily replace legitimate gems in CDN caches when platform names ended ...

May 13, 2022
CVE-2026-26010
7.6

OpenMetadata versions before 1.11.8 leak JSON Web Tokens (JWTs) used by the ingestion-bot service through API calls from the UI. This allows any read-...

Feb 11, 2026
CVE-2025-64487
7.6

A privilege escalation vulnerability in Outline document management systems allows authenticated users to gain unauthorized administrative privileges ...

Feb 11, 2026
CVE-2024-56335
7.6

This vulnerability allows authenticated attackers with admin/owner permissions in one organization to modify or delete groups in other organizations i...

Dec 20, 2024
CVE-2024-42798
7.6

An incorrect access control vulnerability in Kashipara Music Management System v1.0 allows low-privileged attackers to access administrator functions ...

Sep 16, 2024
CVE-2023-23990
7.6

This vulnerability in the WordPress Redirection for Contact Form 7 plugin allows attackers to escalate privileges, potentially gaining administrative ...

May 17, 2024
CVE-2024-1764
7.6

This vulnerability allows users in Devolutions Server to retain elevated privileges beyond their intended expiration time. Attackers could exploit thi...

Mar 5, 2024
CVE-2024-21985
7.6

This vulnerability in NetApp ONTAP allows authenticated users with multiple remote accounts to perform REST API actions beyond their intended privileg...

Jan 26, 2024
CVE-2021-28702
7.6

This vulnerability allows PCI devices with Reserved Memory Region Reporting (RMRR) to be improperly deassigned when passed through to virtual machine ...

Oct 6, 2021
CVE-2020-7467
7.6

This vulnerability in FreeBSD's bhyve hypervisor allows guest virtual machines to execute certain AMD virtualization instructions that bypass nested p...

Mar 26, 2021
CVE-2026-24894
7.5

This vulnerability in FrankenPHP worker mode allows session data from one user's request to be accessible to another user's request processed by the s...

Feb 12, 2026
CVE-2026-21983
7.5

This vulnerability in Oracle VM VirtualBox allows a high-privileged attacker with local access to the host system to potentially compromise the Virtua...

Jan 20, 2026
CVE-2025-66314
7.5

This vulnerability in ZTE ElasticNet UME R32 allows attackers to bypass access controls and access functionality they shouldn't have permission to use...

Nov 27, 2025
CVE-2025-12726
7.5

This vulnerability allows a remote attacker who has already compromised Chrome's renderer process to escalate privileges via a crafted HTML page. It a...

Nov 10, 2025
CVE-2025-53105
7.5

In GLPI versions 10.0.0 through 10.0.18, authenticated non-admin users can manipulate business rule execution order, potentially altering system behav...

Aug 27, 2025
CVE-2025-29924
7.5

XWiki Platform subwikis with 'Prevent unregistered users to view pages' or similar privacy settings are vulnerable to unauthorized access through REST...

Mar 19, 2025
CVE-2021-3978
7.5

CVE-2021-3978 is a local privilege escalation vulnerability in Cloudflare's octorpki RPKI validator. When combined with another vulnerability that all...

Jan 29, 2025
CVE-2025-21343
7.5

This vulnerability in Windows Web Threat Defense User Service allows attackers to read sensitive information from system memory. It affects Windows sy...

Jan 14, 2025
CVE-2024-39206
7.5

MSP360 Backup Agent versions 7.8.5.15 and 7.9.4.84 store network share credentials in an encrypted file (enginesettings.list) using a hard-coded encry...

Jul 2, 2024
CVE-2024-0096
7.5

NVIDIA ChatRTX for Windows has a privilege management vulnerability where attackers can manipulate execution flow through user inputs. This could allo...

May 14, 2024
CVE-2024-25842
7.5

This vulnerability in the Presta World 'Account Manager - Sales Representative & Dealers - CRM' module for PrestaShop allows remote attackers to escal...

Mar 3, 2024
CVE-2023-52105
7.5

CVE-2023-52105 is a privilege escalation vulnerability in Huawei's nearby module that allows attackers to gain elevated privileges on affected devices...

Jan 16, 2024
CVE-2023-52116
7.5

This CVE describes a permission management vulnerability in Huawei's multi-screen interaction module that could allow unauthorized access or privilege...

Jan 16, 2024
CVE-2023-52114
7.5

This CVE describes a data confidentiality vulnerability in Huawei's ScreenReader module that could allow unauthorized access to sensitive information....

Jan 16, 2024
CVE-2023-52107
7.5

This CVE describes a permission verification vulnerability in Huawei's WMS (Window Manager Service) module on HarmonyOS devices. Attackers could explo...

Jan 16, 2024
CVE-2023-41309
7.5

A permission control vulnerability in Huawei's MediaPlaybackController module allows attackers to bypass intended restrictions, potentially disrupting...

Sep 27, 2023
CVE-2023-41301
7.5

This CVE describes an unauthorized API access vulnerability in Huawei's PMS (Package Management Service) module that allows attackers to bypass intend...

Sep 25, 2023
CVE-2023-1694
7.5

CVE-2023-1694 is a file privilege escalation vulnerability in the Settings module of Huawei HarmonyOS and EMUI systems. Successful exploitation could ...

May 20, 2023
CVE-2023-29350
7.5

This vulnerability in Microsoft Edge allows attackers to gain elevated privileges on affected systems. It affects users running vulnerable versions of...

May 5, 2023
CVE-2022-22390
7.5

This vulnerability in IBM Db2 allows unauthorized information disclosure through improper privilege management when using table functions. Attackers c...

Jun 24, 2022
CVE-2022-29179
7.5

This CVE allows an attacker who has already escaped a container running as root to escalate privileges to Kubernetes cluster admin using Cilium's serv...

May 20, 2022
CVE-2022-22257
7.5

CVE-2022-22257 is an improper permission control vulnerability in Huawei's customization framework that allows unauthorized access to modify system se...

Apr 11, 2022
CVE-2022-23921
7.5

CVE-2022-23921 is a local privilege escalation vulnerability in GE CIMPLICITY software that allows authenticated attackers to execute arbitrary code w...

Feb 25, 2022
CVE-2021-42291
7.5

This vulnerability allows authenticated attackers to elevate privileges in Active Directory Domain Services by exploiting improper access control. It ...

Nov 10, 2021
CVE-2021-42282
7.5

CVE-2021-42282 is an Active Directory Domain Services privilege escalation vulnerability that allows authenticated attackers to gain domain administra...

Nov 10, 2021
CVE-2021-25442
7.5

This vulnerability allows Mobile Device Management (MDM) users to bypass Knox Manage authentication in Samsung devices. It affects Samsung devices usi...

Jul 8, 2021
CVE-2020-7335
7.5

This vulnerability allows local users on Windows systems running McAfee Total Protection to escalate privileges by exploiting a timing issue through j...

Dec 1, 2020
CVE-2025-53942
7.4

This vulnerability allows deactivated users who registered via OAuth/SAML to retain partial system access in authentik. They can authorize application...

Jul 23, 2025
CVE-2025-6177
7.4

This vulnerability allows a local attacker with physical access to gain root code execution on enrolled ChromeOS devices by exploiting a debug shell a...

Jun 16, 2025
CVE-2024-53350
7.4

Insecure permissions in kubeslice v1.3.1 allow attackers to access service account tokens, enabling privilege escalation within Kubernetes clusters. T...

Mar 21, 2025
CVE-2024-53349
7.4

This vulnerability in Kuadrant v0.11.3 allows attackers to access service account tokens due to insecure permissions in the secrets component. Attacke...

Mar 21, 2025
CVE-2023-40375
7.4

This CVE describes a local privilege escalation vulnerability in IBM i's integrated application server. An attacker with command-line access to the ho...

Sep 28, 2023
CVE-2025-67246
7.3

This vulnerability allows unprivileged local users to read arbitrary physical memory through the Ludashi driver's IOCTL handler, exposing sensitive ke...

Jan 15, 2026
CVE-2025-55581
7.3

This vulnerability allows attackers with filesystem access to replace critical binaries on D-Link DCS-825L cameras, leading to persistent root-level c...

Aug 22, 2025
CVE-2025-22165
7.3

This CVE-2025-22165 is a Medium severity Arbitrary Code Execution vulnerability in Sourcetree for Mac that allows a locally authenticated attacker to ...

Jul 24, 2025
CVE-2025-39202
7.3

An authenticated low-privilege user in MicroSCADA X SYS600's Monitor Pro interface can view and overwrite files, leading to information disclosure and...

Jun 24, 2025
CVE-2023-41076
7.3

This macOS privilege escalation vulnerability allows malicious applications to gain elevated system privileges without proper authorization. It affect...

Apr 11, 2025

About Improper Privilege Management (CWE-269)

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

Our database tracks 816 CVEs classified as CWE-269, with 170 rated critical and 556 rated high severity. The average CVSS score for Improper Privilege Management vulnerabilities is 8.1.

External reference: View CWE-269 on MITRE CWE →

Monitor Improper Privilege Management Vulnerabilities

Get alerted when new Improper Privilege Management CVEs affect your infrastructure.

Start Monitoring Free