CWE-269 · 3,258 records
Improper privilege management
Why does it happen?
To simplify setup, a service account is granted broad, cluster-wide permissions. The principle of least privilege is skipped during installation.
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
kind: ClusterRolerules: - apiGroups: ["*"] resources: ["*"] verbs: ["*"]Fixed
kind: Rolemetadata: namespace: lodos-systemrules: - apiGroups: ["apps"] resources: ["deployments"] verbs: ["get", "list", "update"]How to prevent it
- 01Grant service accounts permissions only within their own namespace.
- 02Avoid wildcard (*) resources and verbs.
- 03Audit role bindings automatically on a regular basis.
CVEs in this class
3,264 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
97Now | CVE-2017-5689Weaponized | An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (Aintel · active management technology firmware · CWE-269 | Critical9.8 | KEV | 92.2% | May 2, 2017 |
96Now | CVE-2021-20021Weaponized | A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a craftedsonicwall · email security · CWE-269 | Critical9.8 | KEV | 88.7% | Apr 9, 2021 |
80Now | CVE-2016-0151Weaponized | The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold microsoft · windows 10 1507 · CWE-269 | High7.8 | KEV | 62.9% | Apr 12, 2016 |
79This week | CVE-2020-8655Weaponized | An issue was discovered in EyesOfNetwork 5.3.eyesofnetwork · eyesofnetwork · CWE-269 | High7.8 | KEV | 60.1% | Feb 6, 2020 |
70This week | CVE-2019-1405Weaponized | An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creationmicrosoft · windows 10 1507 · CWE-269 | High7.8 | KEV | 30.0% | Nov 12, 2019 |
69This week | CVE-2017-12635Weaponized | Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x bapache · couchdb · CWE-269 | Critical9.8 | — | 99.8% | Nov 14, 2017 |
69This week | CVE-2022-24637Weaponized | Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gopenwebanalytics · open web analytics · CWE-269 | Critical9.8 | — | 99.1% | Mar 18, 2022 |
69This week | CVE-2024-49035Weaponized | Partner.Microsoft.Com Elevation of Privilege Vulnerabilitymicrosoft · partner center · CWE-269 | Critical9.8 | KEV | 1.3% | Nov 26, 2024 |
69This week | CVE-2026-84869Weaponized | ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actionsconnectwise · screenconnect · CWE-269 | Critical9.9 | KEV | 0.9% | Sep 8, 2026 |
69This week | CVE-2026-46817Weaponized | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission).oracle · e-business suite · CWE-269 | Critical9.8 | KEV | 0.8% | May 28, 2026 |
68This week | CVE-2013-0643Weaponized | The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 anadobe · flash player · CWE-269 | High8.8 | KEV | 10.5% | Feb 26, 2013 |
67This week | CVE-2019-1215Weaponized | An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Prmicrosoft · windows 10 1507 · CWE-269 | High7.8 | KEV | 19.3% | Sep 11, 2019 |
67This week | CVE-2023-28434Weaponized | MinIO is vulnerable to privilege escalation on Linux/MacOSminio · minio · CWE-269 | High8.8 | KEV | 7.9% | Mar 22, 2023 |
65This week | CVE-2022-0441Weaponized | MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creationstylemixthemes · masterstudy lms · CWE-269 | Critical9.8 | — | 85.3% | Mar 7, 2022 |
64This week | CVE-2014-1511Weaponized | Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypamozilla · firefox · CWE-269 | Critical9.8 | — | 83.6% | Mar 19, 2014 |
64This week | CVE-2014-1510Weaponized | The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 mozilla · firefox · CWE-269 | Critical9.8 | — | 82.3% | Mar 19, 2014 |
64This week | CVE-2019-1388Weaponized | An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Winmicrosoft · windows 10 1507 · CWE-269 | High7.8 | KEV | 8.6% | Nov 12, 2019 |
63This week | CVE-2021-38540Proof of concept | Apache Airflow: Variable Import endpoint missed authentication checkapache · airflow · CWE-269 | Critical9.8 | — | 80.9% | Sep 9, 2021 |
63This week | CVE-2020-3950Weaponized | VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior bvmware · fusion · CWE-269 | High7.8 | KEV | 7.3% | Mar 17, 2020 |
63This week | CVE-2024-38014Weaponized | Windows Installer Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-269 | High7.8 | KEV | 6.3% | Sep 10, 2024 |
62This week | CVE-2020-13638Proof of concept | lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation.rconfig · rconfig · CWE-269 | Critical9.8 | — | 76.6% | Nov 13, 2020 |
62This week | CVE-2002-0367Weaponized | smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which almicrosoft · windows 2000 · CWE-269 | High7.8 | KEV | 4.9% | Jun 25, 2002 |
62This week | CVE-2026-21533Weaponized | Windows Remote Desktop Services Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-269 | High7.8 | KEV | 4.1% | Feb 10, 2026 |
62This week | CVE-2024-26169Weaponized | Windows Error Reporting Service Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-269 | High7.8 | KEV | 4.0% | Mar 12, 2024 |
62This week | CVE-2023-35674Weaponized | In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code.google · android · CWE-269 | High7.8 | KEV | 2.6% | Sep 11, 2023 |
- CVE-2017-568997Now
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (A
CriticalCVSS 9.8KEVWeaponizedEPSS 92%intel · active management technology firmwareMay 2, 2017
- CVE-2021-2002196Now
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted
CriticalCVSS 9.8KEVWeaponizedEPSS 89%sonicwall · email securityApr 9, 2021
- CVE-2016-015180Now
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold
HighCVSS 7.8KEVWeaponizedEPSS 63%microsoft · windows 10 1507Apr 12, 2016
- CVE-2020-865579This week
An issue was discovered in EyesOfNetwork 5.3.
HighCVSS 7.8KEVWeaponizedEPSS 60%eyesofnetwork · eyesofnetworkFeb 6, 2020
- CVE-2019-140570This week
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation
HighCVSS 7.8KEVWeaponizedEPSS 30%microsoft · windows 10 1507Nov 12, 2019
- CVE-2017-1263569This week
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x b
CriticalCVSS 9.8WeaponizedEPSS 100%apache · couchdbNov 14, 2017
- CVE-2022-2463769This week
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to g
CriticalCVSS 9.8WeaponizedEPSS 99%openwebanalytics · open web analyticsMar 18, 2022
- CVE-2024-4903569This week
Partner.Microsoft.Com Elevation of Privilege Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 1%microsoft · partner centerNov 26, 2024
- CVE-2026-8486969This week
ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
CriticalCVSS 9.9KEVWeaponizedEPSS 1%connectwise · screenconnectSep 8, 2026
- CVE-2026-4681769This week
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission).
CriticalCVSS 9.8KEVWeaponizedEPSS 1%oracle · e-business suiteMay 28, 2026
- CVE-2013-064368This week
The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 an
HighCVSS 8.8KEVWeaponizedEPSS 11%adobe · flash playerFeb 26, 2013
- CVE-2019-121567This week
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Pr
HighCVSS 7.8KEVWeaponizedEPSS 19%microsoft · windows 10 1507Sep 11, 2019
- CVE-2023-2843467This week
MinIO is vulnerable to privilege escalation on Linux/MacOS
HighCVSS 8.8KEVWeaponizedEPSS 8%minio · minioMar 22, 2023
- CVE-2022-044165This week
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
CriticalCVSS 9.8WeaponizedEPSS 85%stylemixthemes · masterstudy lmsMar 7, 2022
- CVE-2014-151164This week
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypa
CriticalCVSS 9.8WeaponizedEPSS 84%mozilla · firefoxMar 19, 2014
- CVE-2014-151064This week
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25
CriticalCVSS 9.8WeaponizedEPSS 82%mozilla · firefoxMar 19, 2014
- CVE-2019-138864This week
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Win
HighCVSS 7.8KEVWeaponizedEPSS 9%microsoft · windows 10 1507Nov 12, 2019
- CVE-2021-3854063This week
Apache Airflow: Variable Import endpoint missed authentication check
CriticalCVSS 9.8Proof of conceptEPSS 81%apache · airflowSep 9, 2021
- CVE-2020-395063This week
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior b
HighCVSS 7.8KEVWeaponizedEPSS 7%vmware · fusionMar 17, 2020
- CVE-2024-3801463This week
Windows Installer Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 6%microsoft · windows 10 1507Sep 10, 2024
- CVE-2020-1363862This week
lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation.
CriticalCVSS 9.8Proof of conceptEPSS 77%rconfig · rconfigNov 13, 2020
- CVE-2002-036762This week
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which al
HighCVSS 7.8KEVWeaponizedEPSS 5%microsoft · windows 2000Jun 25, 2002
- CVE-2026-2153362This week
Windows Remote Desktop Services Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 4%microsoft · windows 10 1607Feb 10, 2026
- CVE-2024-2616962This week
Windows Error Reporting Service Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 4%microsoft · windows 10 1507Mar 12, 2024
- CVE-2023-3567462This week
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code.
HighCVSS 7.8KEVWeaponizedEPSS 3%google · androidSep 11, 2023