Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control
Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management
Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may
A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an u
Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Privileged Proc
Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escal
Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.
Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identi
Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the t
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibil
Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Suppor
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th
Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Suppor
Vulnerability in the Oracle Project Costing product of Oracle E-Business Suite (component: Enterprise Command Center).
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers
Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Su
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).
Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementat
Vulnerability in the Oracle Shipping Execution product of Oracle E-Business Suite (component: Internal Operations). Sup
Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Oper
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Suppo
Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operati
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve
An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account c
The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorizat
A Project Resource Manager may gain broader administrative privileges under specific conditions.
Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. Th
The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionalit
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high pri
The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the target
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable
The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of it
The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its lo
Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feat
Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability m
Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify the
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write perm
In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is a
Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/
FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege esc
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started