Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-269

MITRE ↗

Improper Privilege Management

401
CRITICAL
1,938
HIGH
752
MEDIUM
71
LOW
3,229 CVEs · Page 16/65
4.3
CVE-2026-19996

A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin

4.3
CVE-2026-79276

Improper privilege management in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging

4.2
CVE-2026-46424

Budibase is an open-source low-code platform. Prior to 3.38.2, the public API role unassignment endpoint (POST /api/publ

4.2
CVE-2026-54319

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1

4.1
CVE-2026-60938

Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Sup

4.0
CVE-2026-20607

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonom

3.8
CVE-2026-44987

SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with "User Admin" permissi

3.8
CVE-2026-56212

Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization secur

3.7
CVE-2026-33552

Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.

3.7
CVE-2026-70848

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

3.7
CVE-2026-19220

The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network be

3.4
CVE-2026-60847

Vulnerability in the Oracle Order Entry product of Oracle E-Business Suite (component: Internal Operations). Supported

3.3
CVE-2026-0016

In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings acro

3.3
CVE-2026-0050

In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissi

3.3
CVE-2026-28586

In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. T

3.3
CVE-2026-43657

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5. A malic

3.2
CVE-2026-31369

PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availab

3.1
CVE-2026-17074

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper

3.0
CVE-2026-44218

ciguard is a static security auditor for CI/CD pipelines. From 0.1.0 to 0.8.1, the published ghcr.io/jo-jo98/ciguard con

2.7
CVE-2026-77003

The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being c

2.2
CVE-2026-30888

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 allow a mod

CVE-2026-22536

The absence of permissions control for the user XXX allows the current configuration in the sudoers file to escalate pri

CVE-2025-59094

A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sy

CVE-2025-13176

Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL.

CVE-2025-6723

Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access con

CVE-2026-30960

rssn is a scientific computing library for Rust, combining a high-performance symbolic computation engine with numerical

0.0
CVE-2026-30892

crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option

CVE-2025-62625

Improper privilege management in the KVM key download component could allow an attacker to swap tokens and download sens

CVE-2026-9489

NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Na

CVE-2026-9789

A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulne

CVE-2026-8980

The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-priv

CVE-2026-45043

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rust

CVE-2026-10868

A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplie

CVE-2026-11423

A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of

CVE-2026-46617

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic

CVE-2026-46618

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic

CVE-2026-53645

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow a low-privileged

CVE-2026-53565

Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis

CVE-2026-53444

Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/o

CVE-2026-6423

A local privilege escalation vulnerability in ESET Inspect Connector.  The vulnerability was caused by improper authenti

CVE-2026-15379

The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents

CVE-2026-15380

A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — n

CVE-2026-16337

Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-

CVE-2026-47407

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platfor

CVE-2026-34496

Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before

CVE-2026-7483

Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a

CVE-2026-10610

Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.

CVE-2026-12502

Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI,

CVE-2026-18759

The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication

CVE-2026-64634

A vulnerability allowing local privilege escalation to the Reporter service context.

Frequently Asked Questions

What is CWE-269?

CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-269?

There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.

How can I protect against CWE-269 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.

Detect CWE-269 Vulnerabilities

CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.

Get Started