Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Linux prior to 3.1.0 Hotfix 1 allo
Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Mac prior to 3.1.0 Hotfix 1 allows
Privilege Escalation vulnerability in McAfee Active Response (MAR) for Windows prior to 2.4.3 Hotfix 1 allows a maliciou
Privilege Escalation vulnerability in McAfee Active Response (MAR) for Linux prior to 2.4.3 Hotfix 1 allows a malicious
Privilege Escalation vulnerability in McAfee Active Response (MAR) for Mac prior to 2.4.3 Hotfix 1 allows a malicious sc
Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command
In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registri
Sympa before 6.2.56 allows privilege escalation.
Privilege Escalation vulnerability during daily DAT updates when using McAfee Virus Scan Enterprise (VSE) prior to 8.8 P
FusionSphere OpenStack 6.5.1 have an improper permissions management vulnerability. The software does not correctly perf
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege
An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core s
Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unaut
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user sti
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability
Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification
A vulnerability has been identified in License Management Utility (LMU) (All versions < V2.4). The lmgrd service of the
Privilege Escalation vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users t
In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to bec
An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen
Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying
<p>An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly
<p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles jun
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a privilege elevation vulnerability. Due to lack of priv
FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform
Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation.
An issue was discovered in ProlinOS through 2.4.161.8859R. An attacker with local code execution privileges as a normal
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on t
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on t
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root grou
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on t
A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD)
A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an a
FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper p
Nanosystems SupRemo 4.1.3.2348 allows attackers to obtain LocalSystem access because File Manager can be used to rename
Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit`
Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.
Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.
Joomla! before 2.5.3 allows Admin Account Creation.
Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. Th
An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and mai
Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the
Privilege escalation vulnerability in McAfee Total Protection (ToPS) for Mac OS prior to 4.6 allows local users to gain
An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files
Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edi
Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrato
An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started