Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally
An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modificati
An issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the applicat
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXE
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE com
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE c
Due to excessive privileges granted to the web user running the airpointer web platform, a malicious actor that gains co
The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escal
A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a lo
Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privi
A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects M
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Win
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalat
A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges
A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to esc
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious a
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7.
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7
An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaV
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disa
In AccessibilityServiceConnection.java, there is a possible background activity launch due to a logic error in the code.
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disa
The eudskacs.sys driver version 20250328 shipped with EaseUs Todo Backup 1.2.0.1 fails to properly validate privileges f
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be abl
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.47.41.0. The
A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers wi
A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair function
Local Privilege Escalation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator
Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incu
Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally
Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, P
The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26. An app
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15.
An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary me
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.27 a
An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged
An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ul
Windows Web Threat Defense User Service Information Disclosure Vulnerability
When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set
XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it's possible for an user to get
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that
Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started