The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allow
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature re
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abus
Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege t
A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary
Improper privilege management vulnerability in McAfee Agent for Windows prior to 5.7.3 allows a local user to modify eve
Microsoft DWM Core Library Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to re
By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to
An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki AP
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (prev
Improper privilege management vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted a
It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which
Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users
Azure CycleCloud Elevation of Privilege Vulnerability
An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSI
Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10
Improper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows u
An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthori
A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1). Incorrect session validation c
NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to ch
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a
The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-F
A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page
Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the
A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restric
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Au
PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module
GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. Privilege escalation can occur via the /ajax/SetU
Z-Cron 5.6 Build 04 allows an unprivileged attacker to elevate privileges by modifying a privileged user's task. This ca
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a r
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a r
HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly gener
Artica Pandora FMS 7.44 allows privilege escalation.
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by a
An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a lack of exploit mitigations vulnerability. Succ
An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not
The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a cra
Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers
lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account cr
Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-
An Improper Privilege Management in crowbar of SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, S
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started