Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Proper
Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escal
Insecure permissions in kubeslice v1.3.1 allow attackers to gain access to the service account's token, leading to escal
Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local
authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set o
zot is a production-ready vendor-neutral OCI image registry. The group data stored for users in the boltdb database (met
A DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation,
A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker
An issue in BambooHR Build v.25.0210.170831-83b08dd allows a remote attacker to escalate privileges via the /saml/index.
An app may be able to elevate privileges. This issue is fixed in macOS 14. This issue was addressed by removing the vuln
A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with lo
This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac.
Pearcleaner is a free, source-available and fair-code licensed mac app cleaner. The PearcleanerHelper is a privileged he
D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-w
The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable
The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, a
An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash functi
An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privile
A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi
A non-primary administrator user with admin rights to the web interface but without shell access permissions can display
K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCT
Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The
Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administra
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (
Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low sys
The Bricks theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.6.1. This
An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive
An issue in ETSI Open-Source MANO (OSM) 14.0.x before 14.0.3, 15.0.x before 15.0.2, 16.0.0, and 17.0.0 allows a remote a
n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code
Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privil
The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when succ
Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (
Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.
An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive info
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application sear
An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware vers
CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code exe
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privi
theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to versi
A Improper Privilege Management vulnerability in SUSE rancher in RoleTemplateobjects when external=true is set can lead
An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS
D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly
Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by
Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resou
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege e
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started