Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-269

MITRE ↗

Improper Privilege Management

401
CRITICAL
1,938
HIGH
752
MEDIUM
71
LOW
3,229 CVEs · Page 12/65
7.4
CVE-2026-70823

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

7.3
CVE-2025-67246

A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control

7.3
CVE-2026-23772

Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management

7.3
CVE-2026-32323

Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may

7.3
CVE-2026-14719

A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an u

7.3
CVE-2026-20890

Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Privileged Proc

7.3
CVE-2026-68821

Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.

7.2
CVE-2026-23896

immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escal

7.2
CVE-2025-63909

Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.

7.2
CVE-2026-31834

Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identi

7.2
CVE-2026-33906

Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup

7.2
CVE-2026-45395

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the t

7.2
CVE-2026-46867

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibil

7.2
CVE-2026-46922

Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Suppor

7.2
CVE-2026-46953

Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th

7.2
CVE-2026-46970

Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Suppor

7.2
CVE-2026-60340

Vulnerability in the Oracle Project Costing product of Oracle E-Business Suite (component: Enterprise Command Center).

7.2
CVE-2026-60418

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers

7.2
CVE-2026-60546

Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Su

7.2
CVE-2026-60576

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).

7.2
CVE-2026-60836

Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Internal Operations).

7.2
CVE-2026-60900

Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementat

7.2
CVE-2026-60918

Vulnerability in the Oracle Shipping Execution product of Oracle E-Business Suite (component: Internal Operations). Sup

7.2
CVE-2026-60925

Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).

7.2
CVE-2026-61006

Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Oper

7.2
CVE-2026-61094

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve

7.2
CVE-2026-61107

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Suppo

7.2
CVE-2026-61336

Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operati

7.2
CVE-2026-62548

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve

7.2
CVE-2026-66015

An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account c

7.2
CVE-2026-14237

The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorizat

7.2
CVE-2026-68752

A Project Resource Manager may gain broader administrative privileges under specific conditions.

7.2
CVE-2026-72828

Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. Th

7.2
CVE-2026-17533

The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionalit

7.2
CVE-2026-70834

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

7.2
CVE-2026-70939

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

7.2
CVE-2026-70950

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

7.2
CVE-2026-70421

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high pri

7.2
CVE-2026-75796

The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the target

7.2
CVE-2026-75971

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable

7.2
CVE-2026-13415

The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of it

7.2
CVE-2026-79996

The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its lo

7.1
CVE-2026-21223

Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feat

7.1
CVE-2026-28548

Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability m

7.1
CVE-2026-33706

Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify the

7.1
CVE-2026-41359

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write perm

7.1
CVE-2026-46333

In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The

7.1
CVE-2026-46914

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is a

7.1
CVE-2026-52808

Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/

7.1
CVE-2026-58583

FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege esc

Frequently Asked Questions

What is CWE-269?

CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-269?

There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.

How can I protect against CWE-269 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.

Detect CWE-269 Vulnerabilities

CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.

Get Started