A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to e
An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible f
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid
During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a
systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.
Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorize
STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCT
People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0,
A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a we
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to r
When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine whether the operation
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locall
A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfa
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Rea
Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Install / Upgrade Issues). Supp
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external direc
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
The Flux Operator is a Kubernetes CRD controller that manages the lifecycle of CNCF Flux CD and the ControlPlane enterpr
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privilege
There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which
Inappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network se
Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operatio
An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has b
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthori
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the REST API crea
util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vuln
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Fi
A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunctio
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper
There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper director
Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass
Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation
Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allow
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote atta
Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials looku
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started