Kruise provides automated management of large-scale applications on Kubernetes. Starting in version 0.8.0 and prior to v
A vulnerability in the Secure Copy Protocol (SCP) and SFTP feature of Cisco IOS XR Software could allow an authenticated
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git re
** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyx
The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versi
The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/e
Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application En
The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions
A security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By ma
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerl
A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from a
Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.
Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients
In pktproc_perftest_gen_rx_packet_sktbuf_mode of link_rx_pktproc.c, there is a possible out of bounds write due to a rac
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows
Incorrect user permission validation in Harbor <v2.9.5 and Harbor <v2.10.3 allows authenticated users to modify configur
Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.
Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local
An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to us
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security V
Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will a
An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted c
Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV
Permission Bypass allowing attackers to disable HDCP 2.2 encryption by not completing the HDCP Key Exchange initializat
A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doin
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. A local
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials
Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 6
An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to us
A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.11.0), Mendix Application
An issue in Shanghai Zhouma Network Technology CO., Ltd IMS Intelligent Manufacturing Collaborative Internet of Things S
An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate
An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through
Input parameter verification vulnerability in the background service module Impact: Successful exploitation of this vuln
This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privil
An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in c
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privile
An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A mali
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An app may gain
Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerabi
Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory
An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker
A vulnerability in the API endpoints of Cisco Integrated Management Controller could allow an authenticated, remote
Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Ope
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Sup
Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the l
Dell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privile
Dell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authentic
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started