Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unaut
Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A m
Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS.
A vulnerability classified as critical has been found in Shenzhen Youkate Industrial Facial Love Cloud Payment System up
A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges.
In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with proje
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privilege
Scylladb is a NoSQL data store using the seastar framework, compatible with Apache Cassandra. Authenticated users who ar
A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift
In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privi
Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is
An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path
Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges
Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORI
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restr
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause i
Azure Service Fabric Container Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affect
A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated,
Cryptomator is data encryption software for users who store their files in the cloud. Prior to version 1.9.2, the MSI in
Windows Error Reporting Service Elevation of Privilege Vulnerability
A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a maliciou
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain
In adsp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation o
Clusternet is a general-purpose system for controlling Kubernetes clusters across different environments. An issue in cl
The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmwar
Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attack
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access
Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with se
Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade
Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may
Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module.
Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module.
there is a possible permanent DoS or way for the modem to boot unverified firmware due to a logic error in the code. Thi
The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing u
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including
IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege a
VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs during installation f
A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated
GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper
ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and
Minio is a Multi-Cloud Object Storage framework. Starting with RELEASE.2020-12-23T02-24-12Z and prior to RELEASE.2023-03
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to versions 1.13.1 and 1.20.4,
Bhima version 1.27.0 allows a remote attacker to update the privileges of any account registered in the application via
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communica
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started