The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unpri
The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allo
An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improp
Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to chan
Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin
Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin
An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4,
Sentry is an error tracking and performance monitoring platform. In versions of the sentry python library prior to 22.11
authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, an
A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of t
A vulnerability classified as critical was found in Axios Italia Axios RE 1.7.0/7.0.0. This vulnerability affects unknow
A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85 and classified as critical. This issue affects some unkn
A vulnerability has been found in SICUNET Access Controller 0.32-05z and classified as critical. Affected by this vulner
A vulnerability was found in SICUNET Access Controller 0.32-05z and classified as critical. Affected by this issue is so
A vulnerability was found in uTorrent Web. It has been declared as critical. Affected by this vulnerability is an unknow
A vulnerability was found in uTorrent. It has been rated as critical. Affected by this issue is some unknown functionali
A vulnerability, which was classified as critical, has been found in uTorrent. This issue affects some unknown processin
A vulnerability was found in Elefant CMS 1.3.12-RC. It has been classified as critical. Affected is an unknown function
A vulnerability was found in Hindu Matrimonial Script. It has been rated as critical. Affected by this issue is some unk
A vulnerability classified as critical has been found in Hindu Matrimonial Script. This affects an unknown part of the f
A vulnerability classified as critical was found in Hindu Matrimonial Script. This vulnerability affects unknown code of
A vulnerability, which was classified as critical, has been found in Hindu Matrimonial Script. This issue affects some u
A vulnerability, which was classified as critical, was found in Hindu Matrimonial Script. Affected is an unknown functio
A vulnerability has been found in Hindu Matrimonial Script and classified as critical. Affected by this vulnerability is
A vulnerability was found in Hindu Matrimonial Script and classified as critical. Affected by this issue is some unknown
A vulnerability was found in Hindu Matrimonial Script. It has been classified as critical. This affects an unknown part
A vulnerability was found in Hindu Matrimonial Script. It has been declared as critical. This vulnerability affects unkn
A vulnerability was found in Hindu Matrimonial Script. It has been rated as critical. This issue affects some unknown pr
A vulnerability classified as critical has been found in Hindu Matrimonial Script. Affected is an unknown function of th
A vulnerability classified as critical was found in Hindu Matrimonial Script. Affected by this vulnerability is an unkno
A vulnerability, which was classified as critical, has been found in Hindu Matrimonial Script. Affected by this issue is
A vulnerability, which was classified as critical, was found in Hindu Matrimonial Script. This affects an unknown part o
A vulnerability was found in Apple iPhone up to 12.4.1. It has been declared as critical. Affected by this vulnerability
An improper privilege management vulnerability [CWE-269] in FortiADC versions 6.2.1 and below, 6.1.5 and below, 6.0.4 an
A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this vulnerability is an unknown f
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into th
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_tok
Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected
Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.
A vulnerability was found in HumHub 0.20.1/1.0.0-beta.3. It has been classified as critical. This affects an unknown par
An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned
In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could le
In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change priv
The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authe
Dell PowerScale OneFS, versions 8.2.0-9.3.0, contains an Improper Handling of Insufficient Permissions vulnerability. An
A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restr
Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to acc
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started