In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the cod
In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity la
Microsoft Office Elevation of Privilege Vulnerability
Certain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure
A local privilege escalation vulnerability in SonicWall Net Extender MSI client for Windows 10.2.336 and earlier versio
An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGu
An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to th
An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an I
A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a sta
An issue discovered in IXP Data Easy Install v.6.6.14884.0 allows local attackers to gain escalated privileges via weak
An issue found in IXP Data Easy Install v.6.6.14884.0 allows a local attacker to gain privileges via a static XOR key.
please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOC
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their us
HP Print and Scan Doctor for Windows may potentially be vulnerable to escalation of privilege. HP is releasing software
VMware Tools contains a local privilege escalation vulnerability. A malicious actor with local user access to a guest vi
A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earli
A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlie
In ActivityStarter, there is a possible background activity launch due to an unsafe PendingIntent. This could lead to lo
In System UI, there is a possible factory reset protection bypass due to a logic error in the code. This could lead to l
In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to
In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to loc
The installer (aka openvpn-client-installer) in Securepoint SSL VPN Client before 2.0.40 allows local privilege escalati
Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege.
Macvim is a text editor for MacOS. Prior to version 178, Macvim makes use of an insecure interprocess communication (IPC
A CWE-269: Improper Privilege Management vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit C
Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of
Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of
An issue was discovered in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, allows attackers
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to
Sandbox Accounts for Events provides multiple, temporary AWS accounts to a number of authenticated users simultaneously
A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system
Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated u
Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthentic
The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerab
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may af
The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may af
NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause execution with unnecessary privi
Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnerability may affect se
An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges vi
A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x
Dell PowerScale OneFS, versions 8.2.2.x-9.5.0.x, contains an improper privilege management vulnerability. A remote atta
Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause feat
SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges
Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability ma
An authenticated XCC user can change permissions for any user through a crafted API command.
Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confi
In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service inc
Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerabilit
The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissio
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started