Privilege Escalation vulnerability in McAfee Total Protection (MTP) trial prior to 4.0.176.1 allows local users to sched
An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Pa
Privilege Escalation vulnerability in Microsoft Windows client McAfee Total Protection (MTP) prior to 16.0.29 allows loc
Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-
MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or
A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bu
An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user ca
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespace
There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers mi
SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group pri
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges t
An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and Ci
A CWE-269: Improper privilege management (write) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older)
IBM Security Guardium Insights 2.0.1 performs an operation at a privilege level that is higher than the minimum level re
A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell,
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlin
An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially craf
In Pivotal tc Server, 3.x versions prior to 3.2.19 and 4.x versions prior to 4.0.10, and Pivotal tc Runtimes, 7.x versio
It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3,
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An a
A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification v
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecti
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting
An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 pri
The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Ce
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Privilege Escalation vulnerability in the installer in McAfee McAfee Total Protection (MTP) trial prior to 4.0.161.1 all
Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restr
In BIG-IP versions 15.1.0-15.1.0.4 and 15.0.0-15.0.1.3 the Certificate Administrator user role and higher privileged rol
A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allo
A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addit
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-4
Accessing functionality not properly constrained by ACLs vulnerability in the autorun start-up protection in McAfee Endp
A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and
systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits
Privilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows a low privi
In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This c
A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE) could allow an aut
Exploitation of Privilege/Trust vulnerability in file in McAfee Endpoint Security (ENS) Prior to 10.7.0 February 2020 Up
Privilege escalation vulnerability in McTray.exe in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 202
AR System Mid Tier in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote auth
The BIRT Engine servlet in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote
The bt/bt_core system service in Tizen allows an unprivileged process to create a system user interface and control the
The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged
An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Server, aka 'Microsoft Dynamics 365 Elevation o
The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link t
Nagios Log Server 2.1.3 has Incorrect Access Control.
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started