Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True
A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems.
Azure PlayFab Elevation of Privilege Vulnerability
An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request
Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handli
Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated
The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.5
Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Appl
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalati
The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This
HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access rol
OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/use
On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used
A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability cou
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 a
A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the fir
Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite
An issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified acti
In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrit
Input verification vulnerability in the compression and decompression module. Impact: Successful exploitation of this vu
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthe
Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payro
There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, S
Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical sys
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege e
A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileg
An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.
NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware contro
Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vul
A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to e
A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic
Windows Installer Elevation of Privilege Vulnerability
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictio
In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification ac
Privilege escalation vulnerability has been found in Wondershare Dr.Fone version 13.5.21. This vulnerability could allow
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successf
CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and
Symantec Diagnostic Tool (SymDiag), prior to 3.0.79, may be susceptible to a Privilege Escalation vulnerability.
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Local Privilege
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative
Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Clie
A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-pr
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma
A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 1
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started