The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i
According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the applica
A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation.
The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to ins
Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the dev
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate
Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azu
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at pet
Exported broadcast receivers allowing malicious apps to bypass broadcast protection.
Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords.
An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to escalate pr
Microsoft Defender for IoT Elevation of Privilege Vulnerability
Improper Privilege Management vulnerability in realmag777 HUSKY allows Privilege Escalation.This issue affects HUSKY: fr
The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive informati
A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an
In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation.
VRCX is an assistant/companion application for VRChat. In versions prior to 2024.03.23, a CefSharp browser with over-per
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without
An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 an
Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escal
Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user t
A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Fi
An issue in Coign CRM Portal v.06.06 allows a remote attacker to escalate privileges via the userPermissionsList paramet
An improper privilege management vulnerability exists in IBM Merge Healthcare eFilm Workstation. A local, authenticated
A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x
MinIO is a High Performance Object Storage. When someone creates an access key, it inherits the permissions of the paren
The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism v
An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and befo
Local privilege escalation vulnerability affects OpenText Operations Agent product versions 12.15 and 12.20-12.25 when i
As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience fo
The FTL Server component of TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a
The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege esc
An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file param
Yubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation b
wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin
Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (filesystem modules) al
Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api mo
An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a cr
An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones throu
The Spectra Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.5.
Microsoft Brokering File System Elevation of Privilege Vulnerability
Improper Privilege Management vulnerability in Teplitsa of social technologies Leyka allows Privilege Escalation.This is
Improper Privilege Management vulnerability in SAASPROJECT Booking Package Booking Package allows Privilege Escalation.T
Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.Thi
Improper Privilege Management vulnerability in GiveWP allows Privilege Escalation.This issue affects GiveWP: from n/a th
Improper Privilege Management vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation.Th
Improper Privilege Management vulnerability in Themify Themify Ultra allows Privilege Escalation.This issue affects Them
Improper Privilege Management vulnerability in Thrive Themes Thrive Theme Builder allows Privilege Escalation.This issue
Improper Privilege Management vulnerability in Crocoblock JetEngine allows Privilege Escalation.This issue affects JetEn
Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalatio
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started