An Execution with Unnecessary Privileges vulnerability in Management Daemon (mgd) of Juniper Networks Junos OS Evolved a
An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users h
A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3. Affected is the file /cardo/api o
Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to p
XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Starting in versions 11.3.7, 11.0
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.
Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a c
Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Release allows unauthori
Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allo
Netskope client prior to 89.x on macOS is impacted by a local privilege escalation vulnerability. The XPC implementation
A unnecessary privilege vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security 10.0 SP1 (on-
Windows DWM Core Library Elevation of Privilege Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Free Antivi
ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attack
In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to es
Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWN
net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a
A vulnerability has been identified in SINUMERIK MC (All versions < V1.15 SP1), SINUMERIK ONE (All versions < V6.15 SP1)
Windows Installer Elevation of Privilege Vulnerability
'Long-term Data Archive Package' service implemented in the following Yokogawa Electric products creates some named pipe
In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing permission check. This
In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local es
In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission chec
In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the co
In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a
A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain s
An Improper Privilege Management vulnerability in the Windows Installer framework used in the Juniper Networks Juniper I
Windows Print Spooler Elevation of Privilege Vulnerability
In placeCall of TelecomManager.java, there is a possible way for an application to keep itself running with foreground s
Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade proce
Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected
A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.
A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container
Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.
An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. When installing, Microsoft SQL Express 2019
A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in
A vulnerability has been found in IVPN Client 2.6.6120.33863 and classified as critical. Affected by this vulnerability
A vulnerability was found in Teradici Management Console 2.2.0. It has been declared as critical. Affected by this vulne
Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local a
Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local a
Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows loca
A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 t
System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
Windows Partition Management Driver Elevation of Privilege Vulnerability
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Storage Spaces Direct Elevation of Privilege Vulnerability
Storage Spaces Direct Elevation of Privilege Vulnerability
Storage Spaces Direct Elevation of Privilege Vulnerability
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started