A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastr
In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.
The application suffers from a privilege escalation vulnerability. A user with read permissions can elevate privileg
An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privile
Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exp
Apiman is a flexible and open source API Management platform. Due to a missing permissions check, an attacker with an au
In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting
Metabase is an open source data analytics platform. Affected versions are subject to Improper Privilege Management. As i
PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled
A vulnerability in the installer script of Cisco AppDynamics PHP Agent could allow an authenticated, local attacker to e
Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows
Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attack
Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to mani
Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when request
An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and d
A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read,
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause i
Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated u
Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privile
IBM CICS TX Standard 11.1 and Advanced 10.1, 11.1 performs an operation at a privilege level that is higher than the min
An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with
Tailscale is software for using Wireguard and multi-factor authentication (MFA). A vulnerability identified in the imple
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to perform a denial of serv
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to b
Cryptomator encrypts data being stored on cloud infrastructure. The MSI installer provided on the homepage for Cryptomat
In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read th
It is possible to sideload a compromised DLL during the installation at elevated privilege.
In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local i
The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could all
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 t
An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37,
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 t
An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.5
Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This i
The Funnel Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a
JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a
It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT to
A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information d
The com.cutestudio.colordialer application through 2.1.8-2 for Android allows a remote attacker to initiate phone calls
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several ap
Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may caus
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) remo
H C Mingham-Smith Ltd - Tardis 2000 Privilege escalation.Version 1.6 is vulnerable to privilege escalation which may all
A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide
IBM Directory Server for IBM i contains a local privilege escalation vulnerability. A malicious actor with command line
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started