Incorrect Privilege Assignment vulnerability in Hitachi Hitachi Storage Plug-in for VMware vCenter allows remote authent
A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the compon
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of co
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of co
Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags paramet
A vulnerability, which was classified as problematic, was found in ShadeYouVPN.com Client 2.0.1.11. Affected is an unkno
In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.
SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database -
GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to
Azure Site Recovery Elevation of Privilege Vulnerability
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combinati
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a pa
Improper access control vulnerability in SamsungRecovery prior to version 8.1.43.0 allows local attckers to delete arbit
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 1
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root priv
One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authe
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6
Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any
matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. The Internet Relay Chat (IRC) protocol allows you
Improper privilege management vulnerability in summary report management in Synology Presto File Server before 2.1.2-160
Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execu
Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbi
(Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-
Konica Minolta bizhub MFP devices before 2022-04-14 have an internal Chromium browser that executes with root (aka super
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email
A logged-in and authenticated user with a Reviewer Role may lock a content item.
fof/byobu is a private discussions extension for Flarum forum. Affected versions were found to not respect private discu
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the syste
Nextcloud files access control is a nextcloud app to manage access control for files. Users with limited access can see
Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to rea
Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permi
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalat
A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engi
OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allo
OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allo
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalatio
Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remo
Privilege chaining vulnerability in acmailer ver. 4.0.2 and earlier, and acmailer DB ver. 1.1.4 and earlier allows remot
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account
pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerabi
Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via i
A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePr
A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfileP
KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits runn
ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM.
An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by releas
The set_user extension module before 2.0.1 for PostgreSQL allows a potential privilege escalation using RESET SESSION AU
A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissio
The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticate
Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVisi
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started