Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-269

MITRE ↗

Improper Privilege Management

131
CRITICAL
485
HIGH
140
MEDIUM
15
LOW
805 CVEs · Page 1/17
10.0
CVE-2026-31852

Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulner

10.0
CVE-2026-60366

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

9.9
CVE-2026-22039

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 hav

9.9
CVE-2026-30269

Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a

9.9
CVE-2026-46824

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level

9.9
CVE-2026-45632

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enfor

9.9
CVE-2026-47744

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings al

9.9
CVE-2026-50545

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic

9.9
CVE-2026-50563

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic

9.9
CVE-2026-50564

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic

9.9
CVE-2026-50566

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic

9.9
CVE-2026-46716

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to be

9.9
CVE-2026-46794

Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector).

9.9
CVE-2026-46852

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata P

9.9
CVE-2026-46893

Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation).

9.9
CVE-2026-46895

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). S

9.9
CVE-2026-46900

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). S

9.9
CVE-2026-46901

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). S

9.9
CVE-2026-46933

Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Internal Operations). S

9.9
CVE-2026-46964

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level

9.9
CVE-2026-58053

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docke

9.9
CVE-2026-60663

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).

9.9
CVE-2026-60719

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions t

9.9
CVE-2026-61076

Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job O

9.9
CVE-2026-61146

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

9.9
CVE-2026-61209

Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery).

9.9
CVE-2026-61237

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integra

9.9
CVE-2026-60369

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

9.9
CVE-2026-15630

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any

9.9
CVE-2026-7329

An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic

9.9
CVE-2026-8709

An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server bef

9.9
CVE-2026-9193

An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and

9.9
CVE-2026-48086

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

9.9
CVE-2026-64637

Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an

9.9
CVE-2026-72863

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app te

9.9
CVE-2026-72886

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.u

9.9
CVE-2026-73269

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a

9.9
CVE-2026-75843

ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransac

9.9
CVE-2026-75851

ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated princ

9.8
CVE-2026-22043

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed

9.8
CVE-2025-14736

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i

9.8
CVE-2026-22238

The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remot

9.8
CVE-2026-22708

Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode wi

9.8
CVE-2025-15403

The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6

9.8
CVE-2025-14533

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a

9.8
CVE-2026-0920

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versio

9.8
CVE-2025-15030

The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few u

9.8
CVE-2025-15027

The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including

9.8
CVE-2025-8572

The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7

9.8
CVE-2025-12882

The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0.

Frequently Asked Questions

What is CWE-269?

CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-269?

There are 813 CVE records associated with CWE-269 in our database. Of these, 131 are critical severity, 485 are high severity, and 140 are medium severity.

How can I protect against CWE-269 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.

Detect CWE-269 Vulnerabilities

CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.

Get Started