Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-269

MITRE ↗

Improper Privilege Management

401
CRITICAL
1,938
HIGH
752
MEDIUM
71
LOW
3,229 CVEs · Page 5/65
8.8
CVE-2026-46921

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp

8.8
CVE-2026-46928

Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supp

8.8
CVE-2026-46929

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported ve

8.8
CVE-2026-46937

Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Repor

8.8
CVE-2026-46940

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported ve

8.8
CVE-2026-46942

Vulnerability in the Oracle Process Manufacturing Process Planning product of Oracle E-Business Suite (component: Intern

8.8
CVE-2026-46951

Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported vers

8.8
CVE-2026-46952

Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported vers

8.8
CVE-2026-46961

Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operation

8.8
CVE-2026-46962

Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operation

8.8
CVE-2026-46972

Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Intern

8.8
CVE-2026-46973

Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Intern

8.8
CVE-2026-12165

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privi

8.8
CVE-2026-12448

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to

8.8
CVE-2026-56216

Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows ap

8.8
CVE-2026-8157

The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new u

8.8
CVE-2026-54099

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR au

8.8
CVE-2026-57995

phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GR

8.8
CVE-2026-12224

The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all ve

8.8
CVE-2026-13228

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Esca

8.8
CVE-2026-14482

The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The v

8.8
CVE-2026-13756

The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3

8.8
CVE-2026-14262

The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Byp

8.8
CVE-2026-59260

OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users t

8.8
CVE-2026-61463

Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to m

8.8
CVE-2026-57996

phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAd

8.8
CVE-2026-12525

The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving cus

8.8
CVE-2026-13741

The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all v

8.8
CVE-2026-15103

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Pr

8.8
CVE-2026-16365

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

8.8
CVE-2026-16366

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

8.8
CVE-2026-16371

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13,

8.8
CVE-2026-16372

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbir

8.8
CVE-2026-16379

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 1

8.8
CVE-2026-16396

Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153,

8.8
CVE-2026-16401

Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird

8.8
CVE-2026-46995

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata P

8.8
CVE-2026-60175

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21

8.8
CVE-2026-60419

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers

8.8
CVE-2026-60583

Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Install). The support

8.8
CVE-2026-60654

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).

8.8
CVE-2026-60678

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Support

8.8
CVE-2026-60863

Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supp

8.8
CVE-2026-60872

Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).

8.8
CVE-2026-60890

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers

8.8
CVE-2026-60897

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers

8.8
CVE-2026-60898

Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). S

8.8
CVE-2026-60901

Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). S

8.8
CVE-2026-60920

Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Operations). Supporte

8.8
CVE-2026-60924

Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).

Frequently Asked Questions

What is CWE-269?

CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-269?

There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.

How can I protect against CWE-269 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.

Detect CWE-269 Vulnerabilities

CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.

Get Started