Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-269

MITRE ↗

Improper Privilege Management

401
CRITICAL
1,938
HIGH
752
MEDIUM
71
LOW
3,229 CVEs · Page 10/65
7.8
CVE-2026-12217

A security vulnerability has been detected in DVDFab Virtual Drive 2.0.0.5. Impacted is an unknown function in the libra

7.8
CVE-2026-36213

An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.e

7.8
CVE-2026-0019

In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead t

7.8
CVE-2026-0063

In setAllowedCarriers of PhoneInterfaceManager.java, there is a possible way to disable carrier restrictions due to a lo

7.8
CVE-2025-7406

Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administr

7.8
CVE-2026-14124

Inappropriate implementation in CredentialProvider in Google Chrome on Windows prior to 150.0.7871.47 allowed a local at

7.8
CVE-2026-46680

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched

7.8
CVE-2026-0276

A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to

7.8
CVE-2026-49176

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50343

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50391

Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-47868

VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be

7.8
CVE-2026-47047

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

7.8
CVE-2026-47054

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

7.8
CVE-2026-60150

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

7.8
CVE-2026-60271

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar

7.8
CVE-2026-60454

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that

7.8
CVE-2026-60530

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_http2.so). The supported v

7.8
CVE-2026-60625

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Studio). Supported versions

7.8
CVE-2026-60661

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is

7.8
CVE-2026-60973

Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). Support

7.8
CVE-2026-61053

Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Di

7.8
CVE-2026-61055

Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). Th

7.8
CVE-2026-61090

Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Miscellaneous). Supported

7.8
CVE-2026-61091

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: B

7.8
CVE-2026-61126

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: P

7.8
CVE-2026-62561

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve

7.8
CVE-2026-16607

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allow

7.8
CVE-2026-38765

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne

7.8
CVE-2026-38766

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_1

7.8
CVE-2026-38764

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne

7.8
CVE-2026-18107

A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process insid

7.8
CVE-2026-17863

Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to p

7.8
CVE-2026-17864

Inappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perfo

7.8
CVE-2026-18606

A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown function

7.8
CVE-2026-19189

A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functional

7.8
CVE-2026-19381

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unkn

7.8
CVE-2026-18071

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege manageme

7.8
CVE-2026-63700

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A l

7.8
CVE-2026-69414

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicl

7.8
CVE-2026-16703

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper p

7.8
CVE-2026-16874

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain root privileges due to improper enf

7.8
CVE-2026-16937

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper p

7.8
CVE-2026-16991

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper h

7.8
CVE-2026-16997

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper

7.7
CVE-2026-23477

Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0,

7.7
CVE-2026-33821

Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privi

7.7
CVE-2026-73122

A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vuln

7.7
CVE-2026-70828

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

7.7
CVE-2026-70942

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

Frequently Asked Questions

What is CWE-269?

CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-269?

There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.

How can I protect against CWE-269 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.

Detect CWE-269 Vulnerabilities

CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.

Get Started