Windows Win32k Elevation of Privilege Vulnerability
Azure IoT CLI extension Elevation of Privilege Vulnerability
DirectX Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
Windows Desktop Bridge Elevation of Privilege Vulnerability
An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to dele
An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to ac
A validation issue was addressed with improved logic. This issue is fixed in macOS High Sierra 10.13.5, Security Update
Improper Access Control in attribute in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update
A vulnerability in the user account management system of Cisco AsyncOS for Cisco Content Security Management Appliance (
Windows Partition Management Driver Elevation of Privilege Vulnerability
In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in othe
Privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x ma
A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could
Dell EMC Avamar Server versions 18.2, 19.1, 19.2, 19.3, and 19.4 contain an improper privilege management vulnerability
Windows WLAN Service Elevation of Privilege Vulnerability
A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local att
Azure RTOS Elevation of Privilege Vulnerability
Azure RTOS Elevation of Privilege Vulnerability
Azure RTOS Elevation of Privilege Vulnerability
An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through
Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remot
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all ve
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improp
Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders f
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal
Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.
Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to thi
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation
OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configurat
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a conta
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. The -oP option is available to the exim user, and all
Windows InstallService Elevation of Privilege Vulnerability
Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an
An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the
A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 b
Improper privilege management vulnerability in maconfig for McAfee Agent for Windows prior to 5.7.4 allows a local user
An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local
A local privilege escalation vulnerability in ethtraceroute of Juniper Networks Junos OS may allow a locally authenticat
A sensitive information disclosure vulnerability in the mosquitto message broker of Juniper Networks Junos OS may allow
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.5 and iPadOS 14.5, tvOS 14.5. A lo
An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting fr
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
Windows Feedback Hub Elevation of Privilege Vulnerability
Windows 10 Update Assistant Elevation of Privilege Vulnerability
A vulnerability in the web UI of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started