VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on th
IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed ser
The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious act
Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privi
The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability.
Microsoft Office Elevation of Privilege Vulnerability
IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple pl
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token a
The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send
The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the cha
The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token an
Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability causes
GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide
The OpenFeature Operator allows users to expose feature flags to applications. Assuming the pre-existence of a vulnerabi
An Improper Privilege Management vulnerability in SUSE kubewarden allows attackers to read arbitrary secrets if they get
Privilege Escalation to root administrator (nsroot)
Improper privilege management in all versions of GitHub Enterprise Server allows users with authorized access to the man
A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their u
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their us
A vulnerability in the ClearPass OnGuard Windows agent could allow malicious users on a Windows instance to elevate thei
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
Windows GDI Elevation of Privilege Vulnerability
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
Symantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnera
An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which co
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged
Incorrect access control in Aternity agent in Riverbed Aternity before 12.1.4.27 allows for local privilege escalation.
HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being re
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which mi
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which mi
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege
HPSFViewer might allow Escalation of Privilege. This potential vulnerability was remediated on July 29th, 2022. Customer
An issue in mRemoteNG v1.76.20 allows attackers to escalate privileges via a crafted executable file. NOTE: third partie
The components wfshbr64.sys and wfshbr32.sys in Another Eden before v3.0.20 and before v2.14.200 allows attackers to per
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged
Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior),
PC settings tool Ver10.1.26.0 and earlier, PC settings tool Ver11.0.22.0 and earlier allows a attacker to write to the r
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started