be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered u
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Le
A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher p
Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to acce
A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allo
An information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT
An information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT
An information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT
An information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c406144 functionality of NZXT CAM 4.8.0.
An information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c402084 functionality of NZXT CAM 4.8.0.
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 pri
The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root pri
An issue exists in Safend Data Protector Agent 3.4.5586.9772 in the securitylayer.log file in the logs.9972 directory, w
Improper Access Control vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to bypass secur
A vulnerability in the application-hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attack
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlin
An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symb
qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for
GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary fi
AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering
In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This
An information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c406104 functionality of NZXT CAM 4.8.0.
Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link.
Azure Sphere Elevation of Privilege Vulnerability
COVIDSafe through v1.0.17 allows a remote attacker to access phone name and model information because a BLE device can h
a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package
In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.
An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PS
An issue was discovered in Squid through 4.7. When Squid is run as root, it spawns its child processes as a lesser user,
The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actio
In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.
An issue was discovered in Deskpro before 2019.8.0. The /api/people endpoint failed to properly validate a user's privil
An issue was discovered in Deskpro before 2019.8.0. The /api/tickets endpoint failed to properly validate a user's privi
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and subscriptions" page
In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S
A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticat
A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to g
Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.
A vulnerability in the user management functionality of Cisco IoT Field Network Director (FND) could allow an authentica
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version
NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethack
Privilege escalation vulnerability in the administrative user interface in McAfee Endpoint Security (ENS) for Windows pr
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions,
Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security
Apport reads and writes information on a crashed process to /proc/pid with elevated privileges. Apport then determines w
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 does not have device jailbreak detection which could result i
A privilege escalation vulnerability in BDLDaemon as used in Bitdefender Antivirus for Mac allows a local attacker to ob
An access issue was addressed with additional sandbox restrictions. This issue affected versions prior to iOS 12, macOS
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started