Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2.
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation
h3c firewall <= 3.10 ESS6703 has a privilege bypass vulnerability.
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela Server an
Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerabilit
Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to
An issue was discovered in COINS Construction Cloud 11.12. Due to logical flaws in the human ressources interface, it is
In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user
x26-Cogs is a repository of cogs made by Twentysix for the Red Discord bot. Among these cogs is the Defender cog, a tool
UltraVNC is a free and open source remote pc access software. A vulnerability has been found in versions prior to 1.3.8.
In Bluetooth, there is a possible way to access the a2dp audio control switch due to a missing permission check. This co
MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. A security issue was f
The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM be
Hotdog, prior to v1.0.1, did not mimic the capabilities or the SELinux label of the target JVM process. This would allow
Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 w
Incomplete fix for CVE-2021-3101. Hotdog, prior to v1.0.2, did not mimic the resource limits, device restrictions, or sy
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public r
Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA)
API Privilege Escalation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. Full system takeover.
Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privile
Improper Privilege Management in GitHub repository nocodb/nocodb prior to 0.91.7+.
Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or cu
A vulnerability classified as critical was found in GE Voluson S8. Affected is the underlying Windows XP operating syste
The user access rights validation in the web server of the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.0
The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editi
Active Directory Domain Services Elevation of Privilege Vulnerability
In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. Th
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin
An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (buil
matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. Attackers can specify a specific string of charac
A vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administra
Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.
Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs beca
Smart eVision has an improper privilege management vulnerability. A remote attacker with general user privilege can expl
Brocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allo
Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 co
Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate p
Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows
A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A miscon
A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and pri
Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1.
In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.5.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when
An Improper Access Control vulnerability in the bdservicehost.exe component, as used in Bitdefender Engines for Windows,
In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755,
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started