CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,713 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 3 of 95
- CVE-2016-10593HIGHCVSS 8.1EG 8.12018-05-29
ibapi is an Interactive Brokers API addon for NodeJS. ibapi downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. Before 2.5.6, it may be possible to cause remote code execution (RCE) by swapping out the request…
- CVE-2016-10594HIGHCVSS 8.1EG 8.12018-06-01
ipip is a Node.js module to query geolocation information for an IP or domain, based on database by ipip.net. ipip downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
- CVE-2016-10597MEDIUMCVSS 5.9EG 5.92018-06-01
cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
- CVE-2016-10607HIGHCVSS 8.1EG 8.12018-06-01
openframe-glsviewer is a Openframe extension which adds support for shaders via glslViewer. openframe-glsviewer downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execu…
- CVE-2016-10613MEDIUMCVSS 5.9EG 5.92018-06-01
bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
- CVE-2016-10616HIGHCVSS 8.1EG 8.12018-06-01
openframe-image is an Openframe extension which adds support for images via fbi. openframe-image downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
- CVE-2016-10633HIGHCVSS 8.1EG 8.12018-06-01
dwebp-bin is a dwebp node.js wrapper that convert WebP into PNG. dwebp-bin downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the reques…
- CVE-2016-10641HIGHCVSS 8.1EG 8.12018-06-04
node-bsdiff-android downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
- CVE-2016-10642HIGHCVSS 8.1EG 8.12018-06-04
cmake installs the cmake x86 linux binaries. cmake downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attac…
- CVE-2016-10645HIGHCVSS 8.1EG 8.12018-06-04
grunt-images is a grunt plugin for processing images. grunt-images downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested bina…
- CVE-2016-10648HIGHCVSS 8.1EG 8.12018-06-04
marionette-socket-host is a marionette-js-runner host for sending actions over a socket. marionette-socket-host downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execu…
- CVE-2016-10686HIGHCVSS 8.1EG 8.12018-06-04
fis-sass-all is another libsass wrapper for node. fis-sass-all downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resource…
- CVE-2016-10968HIGHCVSS 8.8EG 8.82019-09-16
The peepso-core plugin before 1.6.1 for WordPress has PeepSoProfilePreferencesAjax->save() privilege escalation.
- CVE-2016-10971CRITICALCVSS 9.8EG 9.82019-09-16
The MemberSonic Lite plugin before 1.302 for WordPress has incorrect login access control because only knowlewdge of an e-mail address is required.
- CVE-2016-10972CRITICALCVSS 9.8EG 9.82019-09-16
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
- CVE-2016-11002HIGHCVSS 8.8EG 8.82019-09-20
The Elegant Themes Extra theme before 1.2.4 for WordPress has privilege escalation.
- CVE-2016-11003HIGHCVSS 8.8EG 8.82019-09-20
The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation.
- CVE-2016-11004HIGHCVSS 8.8EG 8.82019-09-20
The Elegant Themes Monarch plugin before 1.2.7 for WordPress has privilege escalation.
- CVE-2016-11011MEDIUMCVSS 6.5EG 6.52019-09-20
The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
- CVE-2016-15002HIGHCVSS 7.3EG 8.82022-06-09
A vulnerability, which was classified as critical, was found in MONyog Ultimate 6.63. This affects an unknown part of the component Cookie Handler. The manipulation of the argument HasServerEdit/IsAdmin leads to privilege escalation. It is…
- CVE-2016-15045HIGHCVSS 8.5EG 8.52025-07-23
A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Linux (developed by Wuhan Deepin Technology Co., Ltd.). In versions 0.9.53-1 (Deepin 15.5) and 0.9.66-1 (Deepin 15.7), th…
- CVE-2016-1572HIGHCVSS 8.4EG 8.42016-01-22
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.
- CVE-2016-1575HIGHCVSS 7.8EG 7.82016-05-02
The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.
- CVE-2016-2059HIGHCVSS 7.0EG 7.02016-05-05
The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core.c in the IPC router kernel module for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other produc…
- CVE-2016-2061HIGHCVSS 7.8EG 7.82016-06-13
Integer signedness error in the MSM V4L2 video driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of…
- CVE-2016-2066HIGHCVSS 7.8EG 7.82016-06-13
Integer signedness error in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial o…
- CVE-2016-2067HIGHCVSS 7.8EG 7.82016-07-11
drivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, mishandles the KGSL_MEMFLAGS_GPUREADONLY fl…
- CVE-2016-2192MEDIUMCVSS 6.5EG 6.52017-06-06
PostgreSQL PL/Java before 1.5.0 allows remote authenticated users to alter type mappings for types they do not own.
- CVE-2016-2853HIGHCVSS 7.8EG 7.82016-05-02
The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an aufs filesystem on top of a FUSE filesystem, and then executing a crafted setuid pr…
- CVE-2016-2854HIGHCVSS 7.8EG 7.82016-05-02
The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.
- CVE-2016-3376HIGHCVSS 7.8EG 7.82016-10-14
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileg…
- CVE-2016-6590HIGHCVSS 7.8EG 7.82020-01-08
A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpo…
- CVE-2016-8219MEDIUMCVSS 6.5EG 6.52017-06-13
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to 250 and CAPI-release versions prior to 1.12.0. A user with the SpaceAuditor role is over-privileged with the ability to restage applications. This could cause…
- CVE-2016-9489HIGHCVSS 8.8EG 8.82018-07-13
In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like "ADMIN". A user is als…
- CVE-2016-9928HIGHCVSS 7.4EG 7.42020-02-06
MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via…
- CVE-2017-0310MEDIUMCVSS 6.5EG 6.52017-02-15
All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivileged user to cause a denial of service.
- CVE-2017-0358HIGHCVSS 7.8EG 7.82018-04-13
Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root pri…
- CVE-2017-0360MEDIUMCVSS 5.3EG 5.32017-04-04
file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same root name but with a suffix" attack. NOTE: This vulnerability exists because of an incomplete fix …
- CVE-2017-0932HIGHCVSS 8.8EG 8.82018-03-22
Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of validation on the input of the Feature functionality. An attacker with access to an operator (read-only) accou…
- CVE-2017-0934HIGHCVSS 8.8EG 8.82018-03-22
Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file system leading to sensitive information being exposed. An attacker with access to an oper…
- CVE-2017-0935HIGHCVSS 8.8EG 8.82018-03-22
Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file system leading to sensitive information being exposed. An attacker with access to an op…
- CVE-2017-10000HIGHCVSS 7.7EG 7.72017-08-08
Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Reporting). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low p…
- CVE-2017-1000003CRITICALCVSS 9.8EG 9.82017-07-17
ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resulting in privilege escalation. ATutor versions 2.2.1 and earlier are vulnerable to an incorrect acc…
- CVE-2017-1000082CRITICALCVSS 9.8EG 9.82017-07-07
systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.
- CVE-2017-1000104MEDIUMCVSS 6.5EG 6.52017-10-05
The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read access to Jenkins were able to access URLs directly that allowed viewing these file…
- CVE-2017-1000156MEDIUMCVSS 6.5EG 6.52017-11-03
Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any group member even when they didn't have the admin role.
- CVE-2017-1000241HIGHCVSS 8.1EG 8.12017-11-17
The application OpenEMR version 5.0.0, 5.0.1-dev and prior is affected by vertical privilege escalation vulnerability. This vulnerability can allow an authenticated non-administrator users to view and modify information only accessible to …
- CVE-2017-10046MEDIUMCVSS 5.4EG 5.42017-08-08
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2 and 16.1. Easily exploitable v…
- CVE-2017-10094MEDIUMCVSS 5.4EG 5.42017-08-08
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows low privileged attacker with …
- CVE-2017-10098MEDIUMCVSS 5.4EG 5.42017-08-08
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and …
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →