Backup, Recovery, and Media Services (BRMS) for IBM i 7.2, 7.3, and 7.4 contains a local privilege escalation vulnerabil
Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer handler, where improper privileg
There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, app
Product security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrat
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authentica
Zscaler Client Connector Installer on Windows before version 3.4.0.124 improperly handled directory junctions during uni
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause i
A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privilege
PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list a
In Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an
MeterSphere is a one-stop open source continuous testing platform. Prior to 2.10.10-lts, the authenticated attackers can
An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiPro
An Improper Privilege Management vulnerability exists in HyperCloud that will impact the ability for a user to authentic
Data leakage in Adobe connector in Snow Software SPE 9.27.0 on Windows allows privileged user to observe other users dat
An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated at
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause d
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause d
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause d
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault
Redis is an in-memory database that persists on disk. Redis does not correctly identify keys accessed by `SORT_RO` and a
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a par
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause d
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause d
The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-admini
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause i
An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only
Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to re
Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are
LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operati
All Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability. A re
The www-data (Apache web server) account is configured to run sudo with no password for many commands (including /bin/sh
A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the s
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account,
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to uplo
Gitblit 1.9.2 allows privilege escalation via the Config User Service: a control character can be placed in a profile da
OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5
A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component
Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.
The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due
remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm
In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakn
The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause ma
The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerabili
Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation
Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.
Unauth. Privilege Escalation vulnerability in ARMember premium plugin <= 5.5.1 on WordPress.
A potential security vulnerability has been identified in OMEN Gaming Hub and in HP Command Center which may allow escal
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started