CWE-269: Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

802
Total CVEs
166
Critical
546
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
50
2025
213
2024
225
2023
118
2022
49

Top Affected Vendors

1 Microsoft 81
2 Google 46
3 Huawei 26
4 Apple 20
5 Oracle 19
6 Trendmicro 13
7 Dell 11
8 Fortinet 8
9 Apache 7
10 Citrix 7

All Improper Privilege Management CVEs (802)

CVE-2023-38280
8.4

This vulnerability allows a local user with restricted shell access on IBM Hardware Management Console (HMC) to escalate privileges to root. It affect...

Oct 16, 2023
CVE-2023-30989
8.4

This CVE describes a local privilege escalation vulnerability in IBM Performance Tools for i. An attacker with command-line access to the host operati...

Jul 16, 2023
CVE-2023-27558
8.4

This vulnerability allows local attackers to escalate privileges on IBM Db2 for Windows systems by exploiting unquoted service paths. Attackers can pl...

Jul 10, 2023
CVE-2023-20854
8.4

CVE-2023-20854 is an arbitrary file deletion vulnerability in VMware Workstation that allows local authenticated users to delete any files on the syst...

Feb 3, 2023
CVE-2026-27802
8.3

This vulnerability allows managers in Vaultwarden to escalate their privileges by modifying permissions for collections they shouldn't have access to....

Mar 4, 2026
CVE-2025-64489
8.3

SuiteCRM versions 7.14.7 and prior, and 8.0.0-beta.1 through 8.9.0 contain a privilege escalation vulnerability where user sessions remain active afte...

Nov 8, 2025
CVE-2024-45041
8.3

External Secrets Operator versions before 0.10.2 have an overly permissive ClusterRole that allows the default-external-secrets-cert-controller deploy...

Sep 9, 2024
CVE-2024-42995
8.3

This vulnerability allows low-privileged users in VTiger CRM to bypass authorization checks and disable arbitrary modules via the Migration administra...

Aug 16, 2024
CVE-2023-47837
8.3

This vulnerability in the ARMember WordPress plugin allows attackers to bypass membership restrictions and access premium content without proper autho...

Jun 4, 2024
CVE-2024-5525
8.3

A privilege management vulnerability in Astrotalks allows local users to gain administrator access without credentials. This affects systems running A...

May 31, 2024
CVE-2025-53024
8.2

This vulnerability in Oracle VM VirtualBox allows a high-privileged attacker with local access to the host system to completely compromise the Virtual...

Jul 15, 2025
CVE-2025-53027
8.2

A local privilege escalation vulnerability in Oracle VM VirtualBox 7.1.10 allows attackers with high privileges on the host system to compromise the V...

Jul 15, 2025
CVE-2024-21141
8.2

This vulnerability in Oracle VM VirtualBox allows a high-privileged attacker with local access to the host system to completely compromise the Virtual...

Jul 16, 2024
CVE-2024-0082
8.2

NVIDIA ChatRTX for Windows has a privilege management vulnerability where attackers can send open file requests to escalate privileges locally. This c...

Apr 8, 2024
CVE-2023-41806
8.2

CVE-2023-41806 is an improper privilege management vulnerability in Pandora FMS that allows authenticated users to escalate privileges, potentially le...

Nov 23, 2023
CVE-2023-39732
8.2

This vulnerability in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the client secret, which can then be used to acquire channel access to...

Oct 25, 2023
CVE-2023-39734
8.2

CVE-2023-39734 is a client secret leakage vulnerability in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 that allows attackers to obtain channel a...

Oct 25, 2023
CVE-2023-21990
8.2

This vulnerability in Oracle VM VirtualBox allows a high-privileged attacker with local access to the host system to compromise VirtualBox and potenti...

Apr 18, 2023
CVE-2021-43860
8.2

This vulnerability in Flatpak allows malicious applications to grant themselves hidden permissions without user consent by exploiting a null byte in m...

Jan 12, 2022
CVE-2021-23882
8.2

This vulnerability allows local administrators on Windows systems to prevent proper installation of McAfee Endpoint Security (ENS) files during clean ...

Feb 10, 2021
CVE-2020-35517
8.2

This vulnerability allows a privileged guest user in a QEMU virtual machine with virtio-fs shared directories to create device special files that prov...

Jan 28, 2021
CVE-2026-2144
8.1

The Magic Login Mail or QR Code WordPress plugin has a privilege escalation vulnerability that allows unauthenticated attackers to gain access to any ...

Feb 14, 2026
CVE-2025-14975
8.1

This vulnerability in the Custom Login Page Customizer WordPress plugin allows unauthenticated attackers to reset any user's password by knowing their...

Jan 29, 2026
CVE-2025-11086
8.1

This vulnerability allows unauthenticated attackers to register as administrators on WordPress sites using the Academy LMS plugin with Social Login ad...

Oct 22, 2025
CVE-2024-46916
8.1

This vulnerability in Diebold Nixdorf Vynamic Security Suite allows attackers to delete critical system files before filesystem mounting, potentially ...

Aug 29, 2025
CVE-2025-50062
8.1

This vulnerability in Oracle PeopleSoft Enterprise HCM Global Payroll Core allows authenticated attackers with low privileges to access and modify sen...

Jul 15, 2025
CVE-2024-35430
8.1

This vulnerability allows authenticated users in ZKTeco ZKBio CVSecurity to bypass password verification when exporting data. Attackers with valid cre...

May 30, 2024
CVE-2024-21989
8.1

This vulnerability in ONTAP Select Deploy administration utility allows read-only users to escalate their privileges to higher administrative levels. ...

Apr 17, 2024
CVE-2024-22752
8.1

CVE-2024-22752 is an insecure permissions vulnerability in EaseUS MobiMover that allows attackers to escalate privileges by placing a malicious execut...

Mar 7, 2024
CVE-2023-41324
8.1

This vulnerability in GLPI allows API users with read-only access to user resources to steal other users' accounts by exploiting improper privilege ma...

Sep 27, 2023
CVE-2023-28632
8.1

This vulnerability allows authenticated GLPI users to modify any user's email address, enabling account takeover through password reset functionality ...

Apr 5, 2023
CVE-2022-35291
8.1

This vulnerability in SAP SuccessFactors allows authenticated users with standard privileges to perform administrative actions on attachments via misc...

Jul 27, 2022
CVE-2014-125001
8.1

This critical vulnerability in Cardo Systems Scala Rider Q3 allows unauthenticated attackers to execute arbitrary code with root privileges via the /c...

May 24, 2022
CVE-2025-33188
8.0

This vulnerability in NVIDIA DGX Spark GB10 hardware allows attackers to tamper with hardware controls, potentially leading to information disclosure,...

Nov 25, 2025
CVE-2025-52289
8.0

A privilege escalation vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to bypass the pending approval process and activate their...

Jul 31, 2025
CVE-2024-8068
8.0

This vulnerability allows authenticated Windows Active Directory users in the same domain as a Citrix Session Recording server to escalate privileges ...

Nov 12, 2024
CVE-2023-52209
8.0

This vulnerability in WPForms User Registration plugin allows authenticated users to escalate their privileges, potentially gaining administrative acc...

Aug 1, 2024
CVE-2024-37560
8.0

This vulnerability in the WP User Switch WordPress plugin allows attackers to escalate privileges due to improper privilege management. It affects all...

Jul 12, 2024
CVE-2023-46647
8.0

This vulnerability allows users with authorized access to the management console with an editor role in GitHub Enterprise Server to escalate their pri...

Dec 21, 2023
CVE-2023-22645
8.0

This vulnerability allows attackers with access to the kubewarden-controller ServiceAccount to read arbitrary Kubernetes secrets. It affects SUSE kube...

Apr 19, 2023
CVE-2022-24812
8.0

This vulnerability in Grafana Enterprise allows privilege escalation when fine-grained access control is enabled. An attacker can use a lower-privileg...

Apr 12, 2022
CVE-2021-36967
8.0

This vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting a flaw in the Windows WLAN AutoConf...

Sep 15, 2021
CVE-2023-7241
7.9

This vulnerability in Webroot Antivirus allows malicious software to abuse the WRSA.EXE process to delete arbitrary and protected files, potentially l...

May 1, 2024
CVE-2022-1823
7.9

A local privilege escalation vulnerability in McAfee Consumer Product Removal Tool allows authenticated local users to modify configuration files and ...

Jun 20, 2022
CVE-2022-24931
7.9

This vulnerability allows unauthorized attackers to execute arbitrary activities through Samsung's ApkInstaller dynamic receiver without proper permis...

Mar 10, 2022
CVE-2021-25502
7.9

This vulnerability allows attackers to read the ESN (Electronic Serial Number) value without proper privileges on affected Samsung devices. The ESN is...

Nov 5, 2021
CVE-2021-31581
7.9

This vulnerability allows authenticated users to escape the restricted shell in Akkadian Provisioning Manager Engine by exploiting the 'Edit MySQL Con...

Jul 22, 2021
CVE-2025-15561
7.8

This vulnerability allows local attackers to achieve privilege escalation to SYSTEM level by placing a malicious executable in a world-writable direct...

Feb 19, 2026
CVE-2026-21533
KEV 7.8

This vulnerability allows an authorized attacker with valid Remote Desktop credentials to elevate privileges on a Windows system. It affects Windows s...

Feb 10, 2026
CVE-2025-69875
7.8

A local privilege escalation vulnerability in Quick Heal Total Security allows low-privileged users to restore quarantined files into protected system...

Feb 3, 2026

About Improper Privilege Management (CWE-269)

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control.

Our database tracks 802 CVEs classified as CWE-269, with 166 rated critical and 546 rated high severity. The average CVSS score for Improper Privilege Management vulnerabilities is 8.1.

External reference: View CWE-269 on MITRE CWE →

Monitor Improper Privilege Management Vulnerabilities

Get alerted when new Improper Privilege Management CVEs affect your infrastructure.

Start Monitoring Free