Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD has a Web-based terminal that allows u
A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated
A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local
The issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.3, mac
An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only admin
IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to a
A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to
The Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive Met
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be
spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for custom
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be
biscuit-rust is the Rust implementation of Biscuit, an authentication and authorization token for microservices architec
Nextcloud Server is a self hosted personal cloud system. When a server is configured to only allow sharing with users th
A local privilege escalation (LPE) vulnerability has been identified in Phish Alert Button for Outlook (PAB), specifical
An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PA
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are a
A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an un
Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin
Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe modu
MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a pr
An issue exists in SoftIron HyperCloud where authenticated, but non-admin users can create data pools, which could pote
Protection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentia
XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execut
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic o
XWiki Platform is a generic wiki platform. Starting in version 11.8-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.2
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authent
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful explo
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful explo
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause kernel privilege esc
An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges v
An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a escalation of privileges via the TTMulti
Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLo
An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by
Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel
An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi v
The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and inclu
An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Built-in features of Windows (desktop shortcuts, narrat
Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion. This issue
An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in
A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the trans
API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may caus
Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this
D-Link device DIR-820L 1.05B03 is vulnerable to Insecure Permissions.
A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated
An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and W
Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perfo
On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundan
Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 a
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started