The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control.
A vulnerability in Apigee-X allowed an attacker to gain unauthorized read and write access to Apigee Analytics (AX) data
A privilege escalation vulnerability exists in Google Cloud's Dialogflow CX. Dialogflow agent developers with Webhook e
An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completi
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at pet
An issue in the component Access64.sys of Wistron Corporation TBT Force Power Control v1.0.0.0 allows attackers to escal
A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Pla
An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system modu
An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a cra
An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API
An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/n
SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for P
An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers t
SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote a
An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate priv
An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to b
SQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote atta
An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.
Improper Privilege Management vulnerability in Jacques Malgrange Rencontre – Dating Site allows Privilege Escalation.Thi
Improper Privilege Management vulnerability in WhatArmy WatchTowerHQ allows Privilege Escalation.This issue affects Watc
Improper Privilege Management vulnerability in Favethemes Houzez Login Register allows Privilege Escalation.This issue a
Improper Privilege Management vulnerability in Favethemes Houzez allows Privilege Escalation.This issue affects Houzez:
Improper Privilege Management vulnerability in xtemos Woodmart Core allows Privilege Escalation.This issue affects Woodm
Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega:
Improper Privilege Management vulnerability in Saleswonder Team WebinarIgnition allows Privilege Escalation.This issue a
Improper Privilege Management vulnerability in IOSS WP MLM Unilevel allows Privilege Escalation.This issue affects WP ML
Improper Privilege Management vulnerability in powerfulwp Local Delivery Drivers for WooCommerce allows Privilege Escala
Improper Privilege Management vulnerability in Glowlogix WP Frontend Profile allows Privilege Escalation.This issue affe
Improper Privilege Management vulnerability in WebWizards SalesKing allows Privilege Escalation.This issue affects Sales
Improper Privilege Management vulnerability in Wholesale WholesaleX allows Privilege Escalation.This issue affects Whole
Improper Privilege Management vulnerability in CodeRevolution Demo My WordPress allows Privilege Escalation.This issue a
Improper Privilege Management vulnerability in Astoundify Simple Registration for WooCommerce allows Privilege Escalatio
Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore
Improper Privilege Management vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Privile
Aten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged telnet account. The user is not asked to cha
Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access th
Insecure Permissions vulnerability in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to e
An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile
The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3
SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via
Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Privilege Escalation
In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.
Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch
Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affec
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code executio
The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.
An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via
The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to
A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privil
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started