MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A re
KubePi is an opensource kubernetes management panel. A normal user has permission to create/update users, they can becom
Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows
TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate fi
Windows SMB Witness Service Elevation of Privilege Vulnerability
Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: Admin C
Rapid7 Velociraptor allows users to be created with different privileges on the server. Administrators are generally all
A privilege escalation vulnerability was identified in Nessus versions 8.10.1 through 8.15.8 and 10.0.0 through 10.4.1.
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary
As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This co
TimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through
Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privi
ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Adminis
An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileg
OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the or
An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserContr
Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requ
An issue found in OpenGoofy Hippo4j v.1.4.3 allows attackers to escalate privileges via the ThreadPoolController of the
Improper Privilege Management in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2
Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following
CKAN is an open-source data management system for powering data hubs and data portals. Prior to versions 2.9.9 and 2.10.
The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to i
A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. Th
Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an
Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an a
The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2
The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in vers
The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.
An Execution with Unnecessary Privileges vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Con
Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.
KnowStreaming 3.3.0 is vulnerable to Escalation of Privileges. Unauthorized users can create a new user with an admin ro
A logic issue was addressed with improved state management. This issue is fixed in Pro Video Formats 2.2.5. A user may b
SearchBlox before Version 9.2.1 is vulnerable to Privileged Escalation-Lower user is able to access Admin functionality.
A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access
An issue in DLINK DPH-400SE FRU 2.2.15.8 allows a remote attacker to escalate privileges via the User Modify function in
SnapCenter versions 4.8 through 4.9 are susceptible to a vulnerability which may allow an authenticated SnapCenter Serv
An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attac
SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to el
Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to pote
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users
Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made us
Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows
The V8 inspector intentionally allows arbitrary code execution within the Workers sandbox for debugging. wrangler dev wo
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started