CWE-269: Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

802
Total CVEs
166
Critical
546
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
50
2025
213
2024
225
2023
118
2022
49

Top Affected Vendors

1 Microsoft 81
2 Google 46
3 Huawei 26
4 Apple 20
5 Oracle 19
6 Trendmicro 13
7 Dell 11
8 Fortinet 8
9 Apache 7
10 Citrix 7

All Improper Privilege Management CVEs (802)

CVE-2023-32696
8.8

This vulnerability in CKAN's Docker container allows the 'ckan' user (equivalent to www-data) to execute arbitrary code with elevated privileges via s...

May 30, 2023
CVE-2022-3405
8.8

CVE-2022-3405 is a privilege escalation vulnerability in Acronis Agent that allows local attackers to execute arbitrary code and access sensitive info...

May 3, 2023
CVE-2023-2240
8.8

This vulnerability allows improper privilege management in Microweber CMS, enabling attackers to escalate privileges or perform unauthorized actions. ...

Apr 22, 2023
CVE-2022-27487
8.8

This vulnerability allows authenticated remote attackers to make unauthorized API calls on Fortinet FortiSandbox and FortiDeceptor systems. Attackers ...

Apr 11, 2023
CVE-2023-1762
8.8

This CVE describes an improper privilege management vulnerability in phpMyFAQ versions prior to 3.1.12. It allows authenticated users to escalate priv...

Mar 31, 2023
CVE-2023-27094
8.8

This vulnerability in OpenGoofy Hippo4j allows attackers to escalate privileges through the ThreadPoolController in the tenant Management module. Atta...

Mar 23, 2023
CVE-2023-28434
8.8

This vulnerability allows authenticated attackers with S3 permissions to bypass bucket name validation and write objects to any bucket in Minio object...

Mar 22, 2023
CVE-2022-45608
8.8

This vulnerability in ThingsBoard 3.4.1 allows low-privileged CUSTOMER_USER accounts to escalate privileges to TENANT_ADMIN or SYS_ADMIN roles by expl...

Mar 1, 2023
CVE-2022-48341
8.8

CVE-2022-48341 is a privilege escalation vulnerability in ThingsBoard where authenticated tenant administrators can modify the scopes parameter to gai...

Feb 23, 2023
CVE-2022-42735
8.8

Apache ShenYu Admin allows low-privilege administrators to create users with higher privileges than their own due to improper privilege management. Th...

Feb 15, 2023
CVE-2022-32536
8.8

CVE-2022-32536 is an authentication bypass vulnerability in Bosch Ethernet switch PRA-ES8P2S web servers that allows non-administrator users to gain a...

Jun 23, 2022
CVE-2020-36549
8.8

This critical vulnerability in GE Voluson S8 ultrasound systems stems from the underlying Windows XP operating system missing security patches, creati...

Jun 17, 2022
CVE-2022-1654
8.8

This vulnerability allows any authenticated user, even with low privileges like subscribers or customers, to escalate their permissions to administrat...

Jun 13, 2022
CVE-2019-9971
8.8

This vulnerability allows local attackers to gain root privileges on 3CX Phone System installations by exploiting insecure sudo permissions for tcpdum...

Jun 7, 2022
CVE-2022-1770
8.8

CVE-2022-1770 is an improper privilege management vulnerability in the trudesk helpdesk software that allows authenticated users to escalate their pri...

May 20, 2022
CVE-2021-36207
8.8

CVE-2021-36207 is a privilege escalation vulnerability in Johnson Controls Metasys ADS/ADX/OAS servers that allows authenticated users to elevate thei...

Apr 29, 2022
CVE-2021-43858
8.8

CVE-2021-43858 is a privilege escalation vulnerability in MinIO cloud storage software where a malicious client can craft HTTP API calls to update use...

Dec 27, 2021
CVE-2021-28710
8.8

This vulnerability in Xen's VT-d IOMMU implementation allows a guest virtual machine to write to leaf page table entries when sharing page tables with...

Nov 21, 2021
CVE-2021-37911
8.8

This vulnerability allows attackers on the same local network to bypass privilege controls in BenQ smart wireless conference projector management inte...

Aug 30, 2021
CVE-2021-24602
8.8

The HM Multiple Roles WordPress plugin before version 1.3 contains a privilege escalation vulnerability that allows authenticated users with any role ...

Aug 23, 2021
CVE-2020-24576
8.8

This vulnerability in Netskope Client allows low-privileged users to escalate their privileges to SYSTEM level on Windows systems. It affects Netskope...

Aug 12, 2021
CVE-2021-34802
8.8

This vulnerability in Neo4j Graph Database allows authenticated users to execute commands with elevated privileges due to a failure in resetting secur...

Jul 30, 2021
CVE-2021-34481
8.8

This CVE describes a remote code execution vulnerability in the Windows Print Spooler service that allows attackers to execute arbitrary code with SYS...

Jul 16, 2021
CVE-2021-27661
8.8

This vulnerability allows authenticated users of Johnson Controls Facility Explorer SNC Series Supervisory Controllers to gain unintended file system ...

Jul 1, 2021
CVE-2021-33538
8.8

This vulnerability in Weidmueller Industrial WLAN devices allows authenticated low-privilege users to overwrite other user account passwords by crafti...

Jun 25, 2021
CVE-2021-23999
8.8

This vulnerability in Mozilla Firefox, Firefox ESR, and Thunderbird allows malicious web content to gain elevated system privileges through Blob URL m...

Jun 24, 2021
CVE-2021-1400
8.8

This vulnerability in Cisco Small Business Wireless Access Points allows authenticated remote attackers to access sensitive information or execute arb...

May 6, 2021
CVE-2021-27394
8.8

This vulnerability allows authenticated non-administrative users in Mendix applications to manipulate their user roles and gain administrative privile...

Apr 16, 2021
CVE-2021-26758
8.8

CVE-2021-26758 is a privilege escalation vulnerability in OpenLiteSpeed web server version 1.7.8 that allows attackers to gain root terminal access an...

Apr 7, 2021
CVE-2021-1728
8.8

CVE-2021-1728 is an elevation of privilege vulnerability in Microsoft System Center Operations Manager (SCOM). It allows authenticated attackers to ex...

Feb 25, 2021
CVE-2021-26594
8.8

This vulnerability allows attackers to escalate privileges to administrator role in Directus 8.x through 8.8.1 by exploiting insufficient backend vali...

Feb 23, 2021
CVE-2025-37101
8.7

This vulnerability in HPE OneView for VMware vCenter allows attackers with read-only privileges to perform administrative actions through vertical pri...

Jun 26, 2025
CVE-2024-8100
8.7

This vulnerability allows attackers to use time-bound device onboarding tokens to gain administrative privileges on Arista CloudVision Portal (CVP) on...

May 8, 2025
CVE-2024-55954
8.7

This vulnerability in OpenObserve allows users with 'Admin' role privileges to delete 'Root' user accounts, bypassing intended privilege hierarchy. Th...

Jan 16, 2025
CVE-2024-49035
8.7

An improper access control vulnerability in Partner.Microsoft.com allows unauthenticated attackers to elevate privileges over a network. This affects ...

Nov 26, 2024
CVE-2020-11846
8.7

This vulnerability in OpenText Privileged Access Manager allows attackers to gain unrestricted access to all application resources after obtaining a t...

Aug 21, 2024
CVE-2023-3699
8.7

An Improper Privilege Management vulnerability in ASUSTOR Data Master (ADM) allows unprivileged local users to modify storage device configurations. T...

Aug 22, 2023
CVE-2024-11218
8.6

This vulnerability in Podman and Buildah allows container breakout through a race condition when building malicious Containerfiles with --jobs=2. Atta...

Jan 22, 2025
CVE-2023-41957
8.6

CVE-2023-41957 is an unauthenticated privilege escalation vulnerability in the WordPress Simple Membership plugin. Attackers can exploit this flaw to ...

May 17, 2024
CVE-2021-30355
8.6

This vulnerability allows a local attacker with framework user privileges on Amazon Kindle e-readers to escalate to root access. It affects Kindle dev...

Sep 1, 2021
CVE-2025-5689
8.5

This vulnerability in Ubuntu's authd service incorrectly assigns root group membership to first-time SSH users during pre-authentication. This allows ...

Jun 16, 2025
CVE-2024-45752
8.5

CVE-2024-45752 allows any unprivileged user to configure the logid daemon via an unrestricted D-Bus service in logiops, enabling malicious keyboard ma...

Sep 19, 2024
CVE-2024-34082
8.5

This vulnerability in Grav CMS allows low-privileged users with page edit permissions to read arbitrary server files using Twig syntax, including sens...

May 15, 2024
CVE-2024-1973
8.5

This vulnerability allows lower-privileged users of Micro Focus Content Manager to manipulate client applications and escalate their privileges, enabl...

Mar 25, 2024
CVE-2023-7080
8.5

This vulnerability in Cloudflare Wrangler's development server allowed arbitrary code execution within Workers sandbox via the V8 inspector. Attackers...

Dec 29, 2023
CVE-2025-66324
8.4

This CVE describes an input verification vulnerability in Huawei's compression/decompression module that could allow attackers to manipulate or corrup...

Dec 8, 2025
CVE-2025-36631
8.4

In Tenable Agent versions before 10.8.5 on Windows, a non-administrative user can overwrite arbitrary local system files with log content using SYSTEM...

Jun 13, 2025
CVE-2024-5009
8.4

This vulnerability allows local attackers to modify the administrator password in WhatsUp Gold through improper access control in the SetAdminPassword...

Jun 25, 2024
CVE-2024-33224
8.4

This vulnerability in Realtek's IO Driver allows attackers to escalate privileges and execute arbitrary code by sending crafted IOCTL requests to the ...

May 22, 2024
CVE-2023-47145
8.4

This vulnerability in IBM Db2 for Windows allows a local user to escalate privileges to SYSTEM level using the MSI repair functionality. It affects Db...

Jan 7, 2024

About Improper Privilege Management (CWE-269)

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

Our database tracks 802 CVEs classified as CWE-269, with 166 rated critical and 546 rated high severity. The average CVSS score for Improper Privilege Management vulnerabilities is 8.1.

External reference: View CWE-269 on MITRE CWE →

Monitor Improper Privilege Management Vulnerabilities

Get alerted when new Improper Privilege Management CVEs affect your infrastructure.

Start Monitoring Free