Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-269

MITRE ↗

Improper Privilege Management

401
CRITICAL
1,938
HIGH
752
MEDIUM
71
LOW
3,229 CVEs · Page 19/65
8.8
CVE-2025-7779

Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True

8.8
CVE-2025-11561

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems.

8.8
CVE-2025-59247

Azure PlayFab Elevation of Privilege Vulnerability

8.8
CVE-2025-61429

An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request

8.8
CVE-2024-14004

Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handli

8.8
CVE-2025-12485

Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated

8.8
CVE-2025-11168

The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.5

8.8
CVE-2025-24838

Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Appl

8.8
CVE-2025-11923

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalati

8.8
CVE-2025-13680

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This

8.8
CVE-2023-53908

HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access rol

8.7
CVE-2024-55954

OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/use

8.7
CVE-2024-8100

On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used

8.7
CVE-2025-37101

A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability cou

8.6
CVE-2024-11218

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 a

8.5
CVE-2025-5689

A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the fir

8.4
CVE-2025-33067

Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

8.4
CVE-2025-36631

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite

8.4
CVE-2023-50450

An issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified acti

8.4
CVE-2025-36630

In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrit

8.4
CVE-2025-66324

Input verification vulnerability in the compression and decompression module. Impact: Successful exploitation of this vu

8.3
CVE-2025-64489

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.

8.2
CVE-2025-53024

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

8.2
CVE-2025-53027

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

8.1
CVE-2025-30475

Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthe

8.1
CVE-2025-50062

Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payro

8.1
CVE-2025-8309

There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, S

8.1
CVE-2024-46916

Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical sys

8.1
CVE-2025-11086

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege e

8.0
CVE-2025-52289

A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileg

8.0
CVE-2025-54761

An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.

8.0
CVE-2025-33188

NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware contro

7.8
CVE-2024-56447

Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vul

7.8
CVE-2024-53706

A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to e

7.8
CVE-2024-11128

A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic

7.8
CVE-2025-21287

Windows Installer Elevation of Privilege Vulnerability

7.8
CVE-2025-21360

Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability

7.8
CVE-2018-9375

In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictio

7.8
CVE-2024-49742

In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification ac

7.8
CVE-2025-0834

Privilege escalation vulnerability has been found in Wondershare Dr.Fone version 13.5.21. This vulnerability could allow

7.8
CVE-2024-11467

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successf

7.8
CVE-2025-0327

CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and

7.8
CVE-2025-0893

Symantec Diagnostic Tool (SymDiag), prior to 3.0.79, may be susceptible to a Privilege Escalation vulnerability.

7.8
CVE-2025-27644

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Local Privilege

7.8
CVE-2025-22231

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative

7.8
CVE-2025-29800

Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-25230

Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Clie

7.8
CVE-2025-3224

A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-pr

7.8
CVE-2025-24258

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma

7.8
CVE-2025-31222

A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 1

Frequently Asked Questions

What is CWE-269?

CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-269?

There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.

How can I protect against CWE-269 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.

Detect CWE-269 Vulnerabilities

CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.

Get Started