The Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creatio
there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privile
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An app may be able to gain root p
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentialit
An improper access control vulnerability in Trend Micro Deep Security Agent 20 could allow a local attacker to escalate
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Privilege Mana
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative
A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be call
A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected i
There is an improper privilege management vulnerability in Huawei smart phone product. A local, authenticated attacker c
An engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on af
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privilege
Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their
Improper privilege management vulnerability in Lunar software that affects versions 6.0.2 through 6.6.0. This vulnerabil
All versions of EnterpriseDB Postgres Advanced Server (EPAS) from 15.0 prior to 15.7.0 and from 16.0 prior to 16.3.0 ma
Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. A
Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specif
ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability whi
Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allow
The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side softwa
Improper Privilege Management vulnerability in Qube One Ltd. Redirection for Contact Form 7 wpcf7-redirect allows Privil
An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_us
A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to es
An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connecti
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected ve
Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerabilit
Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect
Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerabilit
The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect ava
An issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) mo
Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent (browser) and its
Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful ex
There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allo
NVIDIA ChatRTX for Windows contains a vulnerability in Chat RTX UI, where a user can cause an improper privilege managem
NVIDIA ChatRTX for Windows contains a vulnerability in ChatRTX UI, where a user can cause an improper privilege manageme
Improper Privilege Management vulnerability in WP Sharks s2Member Pro allows Privilege Escalation.This issue affects s2M
The mobile application (com.transsion.videocallenhancer) interface has improper permission control, which can lead to th
An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials
An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0,
OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqual
Nintendo Wii U OS 5.5.5 allows man-in-the-middle attackers to forge SSL certificates as though they came from a Root CA,
Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malici
Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and ma
Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability i
The GLPI Agent is a generic management agent. Prior to version 1.7.2, a local user can modify GLPI-Agent code or used DL
Improper Privilege Management vulnerability in wpForo wpForo Forum allows Privilege Escalation.This issue affects wpForo
A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileg
Local privilege escalation vulnerability allowed an attacker to misuse ESET's file operations during a restore operation
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started