Improper privilege management vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows a loca
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affect
VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migr
External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secr
NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause improper privilege management
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use o
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Managemen
ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x are susceptible to a vulnerability
An issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted
In ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks whil
i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators
Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work corre
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i
Improper Privilege Management vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter,
Improper Privilege Management vulnerability in IqbalRony WP User Switch allows Privilege Escalation.This issue affects W
Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows Privilege Escalation.This
Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated u
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability.
Privilege Escalation in WRSA.EXE in Webroot Antivirus 8.0.1X- 9.0.35.12 on Windows64 bit and 32 bit allows malicious s
Exposure of resource to wrong sphere in some Intel(R) DTT software installers may allow an authenticated user to potenti
A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacke
An exposed dangerous function vulnerability in the Trend Micro Apex One agent could allow a local attacker to escalate p
An improper access control vulnerability in Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Work
In Telerik JustDecompile versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the appli
In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applicati
In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the
Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Ope
Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete file
In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due
On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the pro
A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker
A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYST
A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate the
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS
In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a lo
In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local e
In config_gov_time_windows of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could l
In policy_check of fvp.c, there is a possible out of bounds write due to a missing bounds check. This could lead to loca
In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due t
In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local
In ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to
Windows Error Reporting Service Elevation of Privilege Vulnerability
As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported
In the Windows installer in Atos Eviden CardOS API before 5.5.5.2811, Local Privilege Escalation can occur.(from a regul
In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to
Microsoft Brokering File System Elevation of Privilege Vulnerability
Microsoft Brokering File System Elevation of Privilege Vulnerability
Windows Storage Elevation of Privilege Vulnerability
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affe
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started