A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbi
A vulnerability classified as critical has been found in Demokratian. This affects an unknown part of the file install/i
A vulnerability, which was classified as critical, was found in MONyog Ultimate 6.63. This affects an unknown part of th
A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85. It has been declared as critical. Affected by this vuln
ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privilege
A vulnerability, which was classified as critical, was found in Teleopti WFM 7.1.0. This affects an unknown part of the
Improper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5
In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an aut
A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write acces
The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code a
A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to
VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network
Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress.
vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this iss
A vulnerability has been identified in Micro Focus ZENworks 2020 Update 3a and prior versions. This vulnerability allows
Potential product security bypass vulnerability in McAfee Application and Change Control (MACC) prior to version 8.3.4 a
shelljs is vulnerable to Improper Privilege Management
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. In affe
An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for
A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, mac
Azure Batch Node Agent Elevation of Privilege Vulnerability
An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has al
A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing cred
A vulnerability in the configuration import mechanism of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier,
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI h
A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1
The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability tha
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that co
The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that c
A highly privileged user can exploit SUID-root program to escalate his privileges to root on a local Unix system.
Vulnerabilities in the Mint WorkBench allow a low privileged attacker to create and write to a file anywhere on the file
A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and a
The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only fo
Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malici
In Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privi
DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Affec
Improper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 an
Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unkn
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege
Azure Site Recovery Elevation of Privilege Vulnerability
Azure Site Recovery Elevation of Privilege Vulnerability
Azure Site Recovery Elevation of Privilege Vulnerability
Azure Site Recovery Elevation of Privilege Vulnerability
A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user w
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some s
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started