Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correc
Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has
A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can ex
Microsoft Defender for IoT Elevation of Privilege Vulnerability
VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious actor with admin privileges on VMwar
Improper Privilege Management vulnerability in Crocoblock JetFormBuilder allows Privilege Escalation.This issue affects
Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP
Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shi
Improper Privilege Management vulnerability in Darren Cooney Instant Images allows Privilege Escalation.This issue affec
Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affe
Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0.
Improper Privilege Management vulnerability in WebAppick CTX Feed allows Privilege Escalation.This issue affects CTX Fee
The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.
A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matt
This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user
Improper Privilege Management in uvdesk/community-skeleton
There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissi
Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privi
A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local
In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a race co
In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. Thi
The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during
Dell Repository Manager version 3.4.2 and earlier, contain a Local Privilege Escalation Vulnerability in Installation mo
Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrar
There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on speci
Improper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.Thi
Ariane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attac
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation
Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerabili
Insecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to
There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can cre
Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, With
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access
In pt_sysctl_command of pt.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead
In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Cal
In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to
An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and exec
Uncontrolled search path for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to pote
Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authent
** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel N
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local h
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local h
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local h
Dell PowerScale InsightIQ, version 5.1, contain an Improper Privilege Management vulnerability. A high privileged attack
VMware NSX contains a local privilege escalation vulnerability. An authenticated malicious actor may exploit this vuln
Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected a
Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier use
Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command s
A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobject
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started