CWE-269: Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

830
Total CVEs
177
Critical
563
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
50
2025
213
2024
225
2023
118
2022
49

Top Affected Vendors

1 Microsoft 81
2 Google 47
3 Huawei 27
4 Apple 20
5 Oracle 19
6 Trendmicro 13
7 Dell 11
8 Fortinet 9
9 Cisco 9
10 Mcafee 8

All Improper Privilege Management CVEs (830)

CVE-2024-39574
6.7

Dell PowerScale InsightIQ version 5.1 contains an improper privilege management vulnerability that allows a high-privileged attacker with local access...

Sep 10, 2024
CVE-2024-32854
6.7

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability that allows a local high-privilege attac...

Jul 2, 2024
CVE-2024-31953
6.7

This vulnerability allows local attackers with existing user privileges to escalate to administrator privileges through arbitrary code execution durin...

May 14, 2024
CVE-2024-20021
6.7

This vulnerability in ATF SPM allows attackers to remap physical memory to virtual memory due to a logic error, enabling local privilege escalation. I...

May 6, 2024
CVE-2025-22254
6.6

This CVE describes an improper privilege management vulnerability in multiple Fortinet products where authenticated users with read-only admin permiss...

Jun 10, 2025
CVE-2023-32196
6.6

This vulnerability allows attackers to escalate privileges in Rancher when RoleTemplate objects have external=true. Attackers could gain higher permis...

Oct 16, 2024
CVE-2024-44540
6.6

CVE-2024-44540 allows attackers with physical access to Ubiquiti AirMax devices to gain privileged command shell access via the UART debugging port. T...

Sep 23, 2024
CVE-2024-39342
6.6

This vulnerability in Entrust Instant Financial Issuance (formerly Cardwizard) allows attackers to decrypt passwords using static hard-coded AES keys,...

Sep 23, 2024
CVE-2025-52599
6.5

This vulnerability involves inadequate permission management for camera guest accounts in Hanwha Vision cameras, allowing unauthorized access to sensi...

Dec 26, 2025
CVE-2023-53908
6.5

This vulnerability allows authenticated users of HiSecOS 04.0.01 to escalate their privileges to administrative level by sending crafted XML payloads ...

Dec 17, 2025
CVE-2025-24863
6.5

This vulnerability in Intel CIP software allows unprivileged authenticated users to potentially access sensitive information they shouldn't have acces...

Nov 11, 2025
CVE-2025-61759
6.5

A local privilege escalation vulnerability in Oracle VM VirtualBox allows authenticated attackers with low privileges on the host system to access sen...

Oct 21, 2025
CVE-2025-56747
6.5

Creativeitem Academy LMS versions up to 5.13 contain a privilege escalation vulnerability where authenticated users can access instructor-only functio...

Oct 14, 2025
CVE-2025-61152
6.5

CVE-2025-61152 is a JWT authentication bypass vulnerability in python-jose that allows attackers to forge tokens with 'alg=none' and bypass signature ...

Oct 10, 2025
CVE-2025-57396
6.5

CVE-2025-57396 is a privilege escalation vulnerability in Tandoor Recipes where any authenticated user can modify their profile to gain administrative...

Sep 19, 2025
CVE-2025-7784
6.5

A privilege escalation vulnerability in Keycloak allows administrative users with the manage-users role to elevate their privileges to realm-admin whe...

Jul 18, 2025
CVE-2025-45737
6.5

This vulnerability allows attackers to escalate privileges by sending crafted IOCTL commands to the NeacSafe64.sys driver component. It affects system...

Jun 27, 2025
CVE-2025-3438
6.5

The MStore API WordPress plugin allows unauthenticated attackers to register accounts with 'wcfm_vendor' privileges when the WCFM Marketplace plugin i...

May 2, 2025
CVE-2024-8810
6.5

A GitHub App installed in organizations could escalate permissions from read to write access without administrator approval. This vulnerability affect...

Nov 7, 2024
CVE-2024-20374
6.5

This vulnerability allows authenticated administrators in Cisco Secure Firewall Management Center to execute arbitrary commands as root via crafted HT...

Oct 23, 2024
CVE-2024-45919
6.5

A privilege escalation vulnerability in Solvait version 24.4.2 allows attackers to bypass approval workflows by manipulating Request ID and Action Typ...

Oct 7, 2024
CVE-2024-24970
6.5

This vulnerability in HP Display Control software allows local attackers to escalate privileges on affected systems. It affects HP computers with the ...

Jul 19, 2024
CVE-2024-6325
6.5

This CVE appears to reference a vulnerability in Rockwell Automation FactoryTalk Policy Manager where improper privilege management (CWE-269) could al...

Jul 16, 2024
CVE-2024-4390
6.5

The Depicter WordPress plugin allows authenticated attackers with contributor-level access or higher to generate valid nonces for any WordPress action...

Jun 20, 2024
CVE-2024-29976
6.5

This vulnerability allows authenticated attackers on Zyxel NAS devices to view administrator session information including cookies via the 'show_allse...

Jun 4, 2024
CVE-2024-34146
6.5

The Jenkins Git server Plugin vulnerability allows attackers with a previously configured SSH public key but lacking Overall/Read permission to access...

May 2, 2024
CVE-2022-4264
6.5

CVE-2022-4264 is an incorrect privilege assignment vulnerability in M-Files Web (Classic) that allows low-privilege users to modify certain system con...

Dec 9, 2022
CVE-2025-26704
6.4

A privilege management vulnerability in ZTE GoldenDB allows authenticated users to escalate their privileges beyond intended levels. This affects Gold...

Mar 11, 2025
CVE-2025-22621
6.4

CVE-2025-22621 is an improper access control vulnerability in Splunk App for SOAR where following the official documentation's recommendation to add t...

Jan 7, 2025
CVE-2024-22278
6.4

This vulnerability in Harbor container registry allows authenticated users to modify system configurations due to incorrect permission validation. It ...

Aug 2, 2024
CVE-2025-13534
6.3

The ELEX WordPress HelpDesk plugin has a privilege escalation vulnerability that allows authenticated users with Contributor-level access or higher to...

Dec 2, 2025
CVE-2025-66173
6.2

A privilege escalation vulnerability in Hikvision DVR/NVR devices allows attackers with physical access to gain unrestricted shell access via the seri...

Dec 19, 2025
CVE-2025-55076
6.2

This vulnerability allows local users on macOS systems to escalate privileges to root by exploiting an unauthenticated XPC service in Plugin Alliance ...

Dec 3, 2025
CVE-2025-62686
6.2

A local privilege escalation vulnerability in Plugin Alliance InstallationHelper service allows local users to inject malicious dynamic libraries via ...

Dec 3, 2025
CVE-2025-46310
6.0

A macOS privilege escalation vulnerability allows attackers with root access to delete protected system files, potentially causing system instability ...

Feb 11, 2026
CVE-2025-62592
6.0

This vulnerability in Oracle VM VirtualBox allows a high-privileged attacker with local access to the host system to access sensitive data from the vi...

Oct 21, 2025
CVE-2025-53030
6.0

This vulnerability in Oracle VM VirtualBox 7.1.10 allows a high-privileged attacker with local access to the host system to access sensitive data from...

Jul 15, 2025
CVE-2025-53026
6.0

This vulnerability in Oracle VM VirtualBox allows a high-privileged attacker with local access to the host system to access sensitive data from the vi...

Jul 15, 2025
CVE-2024-51521
5.7

This CVE describes an input parameter verification vulnerability in Huawei background service modules. Attackers could exploit insufficient input vali...

Nov 5, 2024
CVE-2022-1804
5.5

CVE-2022-1804 is a privilege escalation vulnerability in accountsservice where the service fails to drop elevated permissions when writing to .pam_env...

Mar 25, 2025
CVE-2024-48828
5.5

Dell SmartFabric OS10 Software contains an improper privilege management vulnerability (CWE-269) where a low-privileged attacker with local access cou...

Mar 17, 2025
CVE-2025-25872
5.5

A privilege escalation vulnerability in Open Panel v0.3.4 allows remote attackers to gain elevated privileges through the Fix Permissions function. Th...

Mar 14, 2025
CVE-2024-54560
5.5

This vulnerability allows a malicious app to modify other applications without proper App Management permission on Apple devices. It affects iOS, iPad...

Mar 10, 2025
CVE-2025-24805
5.5

CVE-2025-24805 is an improper privilege management vulnerability in Mobile Security Framework (MobSF) where local users with minimal privileges can mi...

Feb 5, 2025
CVE-2025-23007
5.5

A vulnerability in the NetExtender Windows client's log export function allows unauthorized access to sensitive Windows system files. This could enabl...

Jan 30, 2025
CVE-2024-5909
5.5

A privilege escalation vulnerability in Palo Alto Networks Cortex XDR agent on Windows allows low-privileged local users to disable the endpoint prote...

Jun 12, 2024
CVE-2025-59790
5.4

CVE-2025-59790 is an improper privilege management vulnerability in Apache Kvrocks that could allow authenticated users to escalate privileges beyond ...

Nov 28, 2025
CVE-2025-50061
5.4

This vulnerability in Oracle Primavera P6 Enterprise Project Portfolio Management allows authenticated attackers with low privileges to perform unauth...

Jul 15, 2025
CVE-2025-46576
5.4

This vulnerability in GoldenDB database allows attackers to bypass privilege restrictions through request manipulation, enabling unauthorized content ...

Apr 27, 2025
CVE-2025-26706
5.4

An improper privilege management vulnerability in ZTE GoldenDB allows authenticated users to escalate their privileges beyond intended levels. This af...

Mar 11, 2025

About Improper Privilege Management (CWE-269)

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

Our database tracks 830 CVEs classified as CWE-269, with 177 rated critical and 563 rated high severity. The average CVSS score for Improper Privilege Management vulnerabilities is 8.1.

External reference: View CWE-269 on MITRE CWE →

Monitor Improper Privilege Management Vulnerabilities

Get alerted when new Improper Privilege Management CVEs affect your infrastructure.

Start Monitoring Free