A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C
A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authen
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Dow
An issue was discovered in CapMon Access Manager 5.4.1.1005. CALRunElevated.exe provides "NT AUTHORITY\SYSTEM" access to
CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file
An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to proper
An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the RunVpncScript co
Robotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (un
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allo
Privilege escalation in the "HTC Account Service" and "ViveportDesktopService" in HTC VIVEPORT before 1.0.0.36 allows lo
An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability coul
Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.
The Windows versions of Snapview Mikogo, versions before 5.10.2 are affected by insecure implementations which allow loc
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum an
CloudBerry Backup v6.1.2.34 allows local privilege escalation via a Pre or Post backup action. With only user-level acce
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Win
In Platform, there is a possible bypass of user interaction requirements due to missing permission checks. This could le
CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This too
ESET Cyber Security 6.7.900.0 for macOS allows a local attacker to execute unauthorized commands as root by abusing an u
The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device
Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU1, may be susceptible to a privilege escalation vulnerabili
cobbler has local privilege escalation via the use of insecure location for PYTHON_EGG_CACHE
lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled
The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/stati
gksu-polkit: permissive PolicyKit policy configuration file allows privilege escalation
Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to
An issue was discovered in TitanHQ WebTitan before 5.18. It has a sudoers file that enables low-privilege users to execu
mom creates world-writable pid files in /var/run
A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file.
oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
Mate 20 Pro smartphones with versions earlier than 9.1.0.135(C00E133R3P1) have an improper authorization vulnerability.
An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security c
On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1,
A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space
gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it d
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `r
An Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated se
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing glob
A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the
Lawrence Livermore National Laboratory msr-safe v1.1.0 is affected by: Incorrect Access Control. The impact is: An attac
Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.wri
This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerabil
The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files
In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST tha
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started