CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to escalate privileges in t
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and
Go through 1.12.5 on Windows mishandles process creation with a nil environment in conjunction with a non-nil token, whi
Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648. The impact is: Remote Code Execut
HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.
The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator a
The MemberSonic Lite plugin before 1.302 for WordPress has incorrect login access control because only knowlewdge of an
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrec
In K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Securi
An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installin
linux vserver 2.6 before 2.6.17 suffers from privilege escalation in remount code.
Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clic
Collabtive 1.0 has incorrect access control
From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated r
An issue was discovered in ADTRAN PMAA 1.6.2-1, 1.6.3, and 1.6.4. NETCONF Access Management (NACM) allows unprivileged u
A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated but unprivileged (l
AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of sy
Under certain conditions, it is possible to request the modification of role or privilege assignments through SAP Identi
A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_0
An issue was discovered in the Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 devices. An attacker can
In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage u
A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute a
The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.
The peepso-core plugin before 1.6.1 for WordPress has PeepSoProfilePreferencesAjax->save() privilege escalation.
The Elegant Themes Extra theme before 1.2.4 for WordPress has privilege escalation.
The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation.
The Elegant Themes Monarch plugin before 1.2.7 for WordPress has privilege escalation.
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5
SITOS six Build v6.2.1 allows a user with the user role of Seminar Coordinator to escalate their permission to the Syste
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. A setusercontext(3) call wi
After installing the IBM Maximo Health- Safety and Environment Manager 7.6.1, a user is granted additional privileges th
An issue was discovered in the Tightrope Media Carousel digital signage product 7.0.4.104. Due to insecure default permi
In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated
Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated att
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the w
An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitte
In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used.
Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager us
When pairing with a Bluetooth device, it may be possible to pair a malicious device without any confirmation from the us
Hikvision DS-2CD7153-E IP Camera has Privilege Escalation
On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via
An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBa
Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote auth
In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in
In Octopus Deploy 2019.1.0 through 2019.3.1 and 2019.4.0 through 2019.4.5, an authenticated user with the VariableViewUn
OX App Suite 7.10.1 allows Content Spoofing.
A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Con
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started