Skip to content
Noroxi

CWE-269 · 3,258 records

Improper privilege management

Why does it happen?

To simplify setup, a service account is granted broad, cluster-wide permissions. The principle of least privilege is skipped during installation.

Vulnerable and fixed code

A representative teaching example. Highlighted lines mark where the bug and the fix are.

Vulnerable

yaml
kind: ClusterRolerules:  - apiGroups: ["*"]    resources: ["*"]    verbs: ["*"]

Fixed

yaml
kind: Rolemetadata:  namespace: lodos-systemrules:  - apiGroups: ["apps"]    resources: ["deployments"]    verbs: ["get", "list", "update"]

How to prevent it

  1. 01Grant service accounts permissions only within their own namespace.
  2. 02Avoid wildcard (*) resources and verbs.
  3. 03Audit role bindings automatically on a regular basis.

CVEs in this class

3,264 records

  • An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (A

    CriticalCVSS 9.8KEVWeaponizedEPSS 92%

    intel · active management technology firmwareMay 2, 2017

  • A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted

    CriticalCVSS 9.8KEVWeaponizedEPSS 89%

    sonicwall · email securityApr 9, 2021

  • The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold

    HighCVSS 7.8KEVWeaponizedEPSS 63%

    microsoft · windows 10 1507Apr 12, 2016

  • CVE-2020-8655
    79This week

    An issue was discovered in EyesOfNetwork 5.3.

    HighCVSS 7.8KEVWeaponizedEPSS 60%

    eyesofnetwork · eyesofnetworkFeb 6, 2020

  • CVE-2019-1405
    70This week

    An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation

    HighCVSS 7.8KEVWeaponizedEPSS 30%

    microsoft · windows 10 1507Nov 12, 2019

  • CVE-2017-12635
    69This week

    Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x b

    CriticalCVSS 9.8WeaponizedEPSS 100%

    apache · couchdbNov 14, 2017

  • CVE-2022-24637
    69This week

    Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to g

    CriticalCVSS 9.8WeaponizedEPSS 99%

    openwebanalytics · open web analyticsMar 18, 2022

  • CVE-2024-49035
    69This week

    Partner.Microsoft.Com Elevation of Privilege Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 1%

    microsoft · partner centerNov 26, 2024

  • CVE-2026-84869
    69This week

    ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions

    CriticalCVSS 9.9KEVWeaponizedEPSS 1%

    connectwise · screenconnectSep 8, 2026

  • CVE-2026-46817
    69This week

    Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission).

    CriticalCVSS 9.8KEVWeaponizedEPSS 1%

    oracle · e-business suiteMay 28, 2026

  • CVE-2013-0643
    68This week

    The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 an

    HighCVSS 8.8KEVWeaponizedEPSS 11%

    adobe · flash playerFeb 26, 2013

  • CVE-2019-1215
    67This week

    An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Pr

    HighCVSS 7.8KEVWeaponizedEPSS 19%

    microsoft · windows 10 1507Sep 11, 2019

  • CVE-2023-28434
    67This week

    MinIO is vulnerable to privilege escalation on Linux/MacOS

    HighCVSS 8.8KEVWeaponizedEPSS 8%

    minio · minioMar 22, 2023

  • CVE-2022-0441
    65This week

    MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation

    CriticalCVSS 9.8WeaponizedEPSS 85%

    stylemixthemes · masterstudy lmsMar 7, 2022

  • CVE-2014-1511
    64This week

    Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypa

    CriticalCVSS 9.8WeaponizedEPSS 84%

    mozilla · firefoxMar 19, 2014

  • CVE-2014-1510
    64This week

    The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25

    CriticalCVSS 9.8WeaponizedEPSS 82%

    mozilla · firefoxMar 19, 2014

  • CVE-2019-1388
    64This week

    An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Win

    HighCVSS 7.8KEVWeaponizedEPSS 9%

    microsoft · windows 10 1507Nov 12, 2019

  • CVE-2021-38540
    63This week

    Apache Airflow: Variable Import endpoint missed authentication check

    CriticalCVSS 9.8Proof of conceptEPSS 81%

    apache · airflowSep 9, 2021

  • CVE-2020-3950
    63This week

    VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior b

    HighCVSS 7.8KEVWeaponizedEPSS 7%

    vmware · fusionMar 17, 2020

  • CVE-2024-38014
    63This week

    Windows Installer Elevation of Privilege Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 6%

    microsoft · windows 10 1507Sep 10, 2024

  • CVE-2020-13638
    62This week

    lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation.

    CriticalCVSS 9.8Proof of conceptEPSS 77%

    rconfig · rconfigNov 13, 2020

  • CVE-2002-0367
    62This week

    smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which al

    HighCVSS 7.8KEVWeaponizedEPSS 5%

    microsoft · windows 2000Jun 25, 2002

  • CVE-2026-21533
    62This week

    Windows Remote Desktop Services Elevation of Privilege Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 4%

    microsoft · windows 10 1607Feb 10, 2026

  • CVE-2024-26169
    62This week

    Windows Error Reporting Service Elevation of Privilege Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 4%

    microsoft · windows 10 1507Mar 12, 2024

  • CVE-2023-35674
    62This week

    In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code.

    HighCVSS 7.8KEVWeaponizedEPSS 3%

    google · androidSep 11, 2023

All vulnerability classes