CWE-269: Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

818
Total CVEs
171
Critical
557
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
50
2025
213
2024
225
2023
118
2022
49

Top Affected Vendors

1 Microsoft 81
2 Google 46
3 Huawei 26
4 Apple 20
5 Oracle 19
6 Trendmicro 13
7 Dell 11
8 Cisco 9
9 Fortinet 8
10 Mcafee 7

All Improper Privilege Management CVEs (818)

CVE-2025-0651
7.1

A privilege escalation vulnerability in Cloudflare WARP for Windows allows low-privileged users to create symbolic links that cause the WARP service (...

Jan 22, 2025
CVE-2024-22069
7.1

This vulnerability allows authenticated users with common permissions to intercept password change requests and modify administrator credentials on ZT...

Aug 8, 2024
CVE-2024-3137
7.1

CVE-2024-3137 is an improper privilege management vulnerability in uvdesk/community-skeleton that allows authenticated users to escalate privileges an...

Apr 2, 2024
CVE-2023-47629
7.1

This vulnerability in DataHub allows users with email sign-up links to create admin accounts when the default 'datahub' user has been removed but its ...

Nov 14, 2023
CVE-2023-5622
7.1

This vulnerability allows low-privileged Windows users to escalate privileges to SYSTEM level by replacing a specially crafted file in Nessus Network ...

Oct 26, 2023
CVE-2020-23362
7.1

This CVE describes an insecure permissions vulnerability in Shop_CMS YerShop that allows remote attackers to escalate privileges via the cover_id para...

May 9, 2023
CVE-2023-28758
7.1

This vulnerability in Veritas NetBackup's BPCD component allows unprivileged users to specify arbitrary log file paths when executing commands, enabli...

Mar 23, 2023
CVE-2022-29164
7.1

This vulnerability in Argo Workflows allows authenticated attackers to create malicious workflows that generate HTML artifacts containing scripts. Whe...

May 6, 2022
CVE-2022-0144
7.1

CVE-2022-0144 is a privilege management vulnerability in shelljs where the 'exec' function could be tricked into executing commands with elevated priv...

Jan 11, 2022
CVE-2021-39944
7.1

This vulnerability allows GitLab users with developer role permissions to elevate their privileges to maintainer level when importing projects. It aff...

Dec 13, 2021
CVE-2021-22326
7.1

This vulnerability in HarmonyOS allows local attackers to bypass privilege restrictions and gain kernel-level read/write access. It affects devices ru...

Jun 30, 2021
CVE-2025-26513
7.0

A local privilege escalation vulnerability exists in the SAN Host Utilities for Windows installer versions before 8.0. This allows authenticated local...

Aug 7, 2025
CVE-2025-27468
7.0

This vulnerability allows an authorized attacker with local access to a Windows system to escalate privileges by exploiting improper privilege managem...

May 13, 2025
CVE-2020-9222
7.0

This is a local privilege escalation vulnerability in Huawei FusionCompute products. Attackers with local access can exploit insufficient deserializat...

Dec 27, 2024
CVE-2023-22576
7.0

CVE-2023-22576 is a local privilege escalation vulnerability in Dell Repository Manager versions 3.4.2 and earlier. A local low-privileged attacker ca...

Aug 21, 2024
CVE-2024-5907
7.0

A local privilege escalation vulnerability in Palo Alto Networks Cortex XDR agent on Windows allows authenticated local users to execute programs with...

Jun 12, 2024
CVE-2021-37942
7.0

This vulnerability allows a local user to escalate privileges by attaching a malicious plugin to an application running the Elastic APM Java agent. At...

Nov 22, 2023
CVE-2023-36721
7.0

This vulnerability in Windows Error Reporting Service allows authenticated local attackers to execute arbitrary code with SYSTEM privileges. It affect...

Oct 10, 2023
CVE-2023-37907
7.0

This vulnerability allows local privilege escalation (LPE) in Cryptomator's MSI installer repair function. Low-privileged users can exploit administra...

Jul 25, 2023
CVE-2023-21896
7.0

This vulnerability in Oracle Solaris's NSSwitch component allows a low-privileged attacker with local access to potentially gain full control of the s...

Apr 18, 2023
CVE-2021-41334
7.0

CVE-2021-41334 is an elevation of privilege vulnerability in Windows Desktop Bridge that allows authenticated attackers to execute arbitrary code with...

Oct 13, 2021
CVE-2021-24095
7.0

This is a DirectX Elevation of Privilege vulnerability that allows an authenticated attacker to execute arbitrary code with SYSTEM privileges on a vul...

Mar 11, 2021
CVE-2021-1709
7.0

CVE-2021-1709 is a privilege escalation vulnerability in the Windows Win32k kernel driver that allows authenticated attackers to gain SYSTEM-level pri...

Jan 12, 2021
CVE-2021-1682
7.0

CVE-2021-1682 is a Windows kernel elevation of privilege vulnerability that allows authenticated attackers to execute arbitrary code with SYSTEM privi...

Jan 12, 2021
CVE-2020-26181
7.0

This CVE describes a privilege escalation vulnerability in Dell EMC Isilon OneFS and PowerScale OneFS systems. It allows a compadmin user with specifi...

Jan 5, 2021
CVE-2020-1488
7.0

This Windows vulnerability allows authenticated attackers to elevate privileges by exploiting improper privilege management in AppX Deployment Extensi...

Aug 17, 2020
CVE-2019-1175
7.0

CVE-2019-1175 is a local privilege escalation vulnerability in Microsoft's psmsrv.dll component. An authenticated attacker could exploit this to execu...

Aug 14, 2019
CVE-2019-1177
7.0

CVE-2019-1177 is a local privilege escalation vulnerability in Windows' rpcss.dll component. An authenticated attacker could exploit this to execute a...

Aug 14, 2019
CVE-2025-59705
6.8

This vulnerability allows a physically proximate attacker to escalate privileges on Entrust nShield hardware security modules by inserting a chassis p...

Dec 2, 2025
CVE-2025-1121
6.8

This vulnerability allows an attacker with physical access to a ChromeOS device to escalate privileges to root and potentially unenroll enterprise-man...

Mar 7, 2025
CVE-2024-36499
6.8

This vulnerability allows unauthorized screenshot capturing in Huawei's WMS module, potentially exposing sensitive information displayed on affected d...

Jun 14, 2024
CVE-2023-48319
6.8

This vulnerability allows attackers with editor-level access in WordPress to escalate their privileges to administrator level in the Salon Booking Sys...

May 17, 2024
CVE-2025-69257
6.7

CVE-2025-69257 is a local privilege escalation vulnerability in theshit command-line utility. When executed with elevated privileges (sudo/root), the ...

Dec 30, 2025
CVE-2025-43722
6.7

Dell PowerScale OneFS versions before 9.12.0.0 have a privilege escalation vulnerability where a high-privileged local attacker can gain additional sy...

Sep 8, 2025
CVE-2025-8453
6.7

A privilege escalation vulnerability allows privileged engineer users with console access to modify configuration files used by a root-level daemon, p...

Aug 20, 2025
CVE-2025-28401
6.7

A privilege escalation vulnerability in RUoYi v.4.8.0 allows remote attackers to gain elevated privileges by manipulating the menuId parameter. This a...

Apr 7, 2025
CVE-2024-57062
6.7

A privilege escalation vulnerability in SoundCloud's iOS app v7.65.2 allows local attackers to gain elevated privileges and access sensitive informati...

Mar 13, 2025
CVE-2025-21199
6.7

This vulnerability in Azure Agent Installer allows authenticated attackers to escalate privileges on local systems. Attackers with standard user acces...

Mar 11, 2025
CVE-2024-39574
6.7

Dell PowerScale InsightIQ version 5.1 contains an improper privilege management vulnerability that allows a high-privileged attacker with local access...

Sep 10, 2024
CVE-2024-32854
6.7

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability that allows a local high-privilege attac...

Jul 2, 2024
CVE-2024-31953
6.7

This vulnerability allows local attackers with existing user privileges to escalate to administrator privileges through arbitrary code execution durin...

May 14, 2024
CVE-2024-20021
6.7

This vulnerability in ATF SPM allows attackers to remap physical memory to virtual memory due to a logic error, enabling local privilege escalation. I...

May 6, 2024
CVE-2025-22254
6.6

This CVE describes an improper privilege management vulnerability in multiple Fortinet products where authenticated users with read-only admin permiss...

Jun 10, 2025
CVE-2023-32196
6.6

This vulnerability allows attackers to escalate privileges in Rancher when RoleTemplate objects have external=true. Attackers could gain higher permis...

Oct 16, 2024
CVE-2024-44540
6.6

CVE-2024-44540 allows attackers with physical access to Ubiquiti AirMax devices to gain privileged command shell access via the UART debugging port. T...

Sep 23, 2024
CVE-2024-39342
6.6

This vulnerability in Entrust Instant Financial Issuance (formerly Cardwizard) allows attackers to decrypt passwords using static hard-coded AES keys,...

Sep 23, 2024
CVE-2025-52599
6.5

This vulnerability involves inadequate permission management for camera guest accounts in Hanwha Vision cameras, allowing unauthorized access to sensi...

Dec 26, 2025
CVE-2023-53908
6.5

This vulnerability allows authenticated users of HiSecOS 04.0.01 to escalate their privileges to administrative level by sending crafted XML payloads ...

Dec 17, 2025
CVE-2025-24863
6.5

This vulnerability in Intel CIP software allows unprivileged authenticated users to potentially access sensitive information they shouldn't have acces...

Nov 11, 2025
CVE-2025-61759
6.5

A local privilege escalation vulnerability in Oracle VM VirtualBox allows authenticated attackers with low privileges on the host system to access sen...

Oct 21, 2025

About Improper Privilege Management (CWE-269)

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

Our database tracks 818 CVEs classified as CWE-269, with 171 rated critical and 557 rated high severity. The average CVSS score for Improper Privilege Management vulnerabilities is 8.1.

External reference: View CWE-269 on MITRE CWE →

Monitor Improper Privilege Management Vulnerabilities

Get alerted when new Improper Privilege Management CVEs affect your infrastructure.

Start Monitoring Free