A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allo
A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed
A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allow
An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute
VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative
Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: fro
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonom
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.1), SCALANCE XC316-8 (6GK53
The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0. Anyone with authenticated us
In ESPEC North America Web Controller 3 before 3.3.8, an attacker with physical access can gain elevated privileges beca
In ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout.
Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, b
A vulnerability in Cisco Catalyst Center could allow an authenticated, remote attacker to execute operations that should
ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This
An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via ex
Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator
Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Native Image). The supported version
An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even
Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype
ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected b
Vulnerability in the Oracle Database Materialized View component of Oracle Database Server. Supported versions that are
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
ADB(Android Debug Bridge) is affected by type privilege bypass, successful exploitation of this vulnerability may affect
Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Appl
An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS
A privilege escalation vulnerability in PocketBook InkPad Color 3 allows attackers to escalate to root privileges if the
A Sudo privilege misconfiguration vulnerability in PocketBook InkPad Color 3 on Linux, ARM allows attackers to read file
266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.2153
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Abu
The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config
Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without
A CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation when the server
An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login
A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Li
A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0,
Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege esc
ZPanel includes a helper binary named zsudo, intended to allow restricted privilege escalation for administrative tasks.
The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could
Excessive Privileges vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows Privilege Abuse.This issue aff
Excessive Privileges vulnerability in Calix GigaCenter ONT (Broadcom SoC modules) allows Privilege Abuse.This issue affe
The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hij
SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys und
Improper Privilege Management vulnerability in GE Vernova S1 Agile Configuration Software on Windows allows Privilege Es
Improper privilege management vulnerability in Novakon P series allows attackers to gain root privileges if one service
In a hardened Docker environment, with Enhanced Container Isolation ( ECI https://docs.docker.com/enterprise/security/ha
Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass vulnerability. The TCU
By making minor configuration changes to the TropOS 4th Gen device, an authenticated user with the ability to run user l
The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named
An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC-based connectors. A Loo
CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all a
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started