Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-269

MITRE ↗

Improper Privilege Management

401
CRITICAL
1,938
HIGH
752
MEDIUM
71
LOW
3,229 CVEs · Page 13/65
7.1
CVE-2026-53515

Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/ss

7.1
CVE-2026-47870

VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network acce

7.1
CVE-2026-55550

NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide

7.1
CVE-2026-60492

Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: OW HR PR Foundatio

7.1
CVE-2026-62565

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End). Supported ve

7.1
CVE-2026-17744

Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to

7.1
CVE-2026-70936

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

7.0
CVE-2025-13917

WSS Agent, prior to 9.8.5, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereb

7.0
CVE-2026-4824

A vulnerability has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this issue is some unknown func

7.0
CVE-2026-41163

bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is i

7.0
CVE-2024-38487

api-gateway container running with root privilege would allow an attacker to escape the container and access host system

7.0
CVE-2026-60833

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affe

7.0
CVE-2026-61061

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported v

7.0
CVE-2026-61120

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve

7.0
CVE-2026-75857

CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool,

7.0
CVE-2026-16923

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper p

6.8
CVE-2026-39961

Aiven Operator allows you to provision and manage Aiven Services from your Kubernetes cluster. From 0.31.0 to before 0.3

6.8
CVE-2026-0048

In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/ov

6.8
CVE-2026-0086

In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null c

6.8
CVE-2026-70843

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

6.7
CVE-2025-13918

Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevatio

6.7
CVE-2026-24510

Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Privilege Management vulnerabilit

6.7
CVE-2026-26946

Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege

6.7
CVE-2026-0275

A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administ

6.7
CVE-2026-49501

Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Pri

6.7
CVE-2026-60406

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Op

6.7
CVE-2026-61176

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).

6.7
CVE-2026-61182

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Da

6.7
CVE-2026-16742

systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed

6.7
CVE-2026-71109

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

6.6
CVE-2026-35291

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that

6.6
CVE-2026-61013

Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support

6.6
CVE-2026-57599

There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the d

6.6
CVE-2026-65835

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE

6.6
CVE-2026-19222

The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to

6.5
CVE-2026-2375

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalat

6.5
CVE-2026-29647

In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state

6.5
CVE-2026-5193

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privile

6.5
CVE-2026-45254

In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key

6.5
CVE-2026-12450

Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain poten

6.5
CVE-2026-50201

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati

6.5
CVE-2026-40009

Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate t

6.5
CVE-2026-55843

Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission

6.5
CVE-2026-36425

An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user

6.5
CVE-2026-48010

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framewo

6.5
CVE-2026-47411

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an aut

6.5
CVE-2026-66399

phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows admi

6.5
CVE-2026-24059

The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creat

6.5
CVE-2026-72631

Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC

6.5
CVE-2026-70824

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

Frequently Asked Questions

What is CWE-269?

CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-269?

There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.

How can I protect against CWE-269 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.

Detect CWE-269 Vulnerabilities

CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.

Get Started