Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-269

MITRE ↗

Improper Privilege Management

401
CRITICAL
1,938
HIGH
752
MEDIUM
71
LOW
3,229 CVEs · Page 6/65
8.8
CVE-2026-60932

Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Sup

8.8
CVE-2026-60952

Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations)

8.8
CVE-2026-60989

Vulnerability in the Oracle Advanced Collections product of Oracle E-Business Suite (component: Internal Operations). S

8.8
CVE-2026-61010

Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operat

8.8
CVE-2026-61062

Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Cash Management)

8.8
CVE-2026-61063

Vulnerability in the PeopleSoft Enterprise SCM Supplier Contract Management product of Oracle PeopleSoft (component: Sec

8.8
CVE-2026-61098

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).

8.8
CVE-2026-61099

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).

8.8
CVE-2026-61110

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported version

8.8
CVE-2026-61121

Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th

8.8
CVE-2026-61127

Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Solut

8.8
CVE-2026-61149

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

8.8
CVE-2026-61168

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that

8.8
CVE-2026-61179

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Pr

8.8
CVE-2026-61180

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Pr

8.8
CVE-2026-61243

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffin

8.8
CVE-2026-61311

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported

8.8
CVE-2026-61320

Vulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Internal Operations). Supported ver

8.8
CVE-2026-61322

Vulnerability in the TeleSales product of Oracle E-Business Suite (component: Internal Operations). Supported versions

8.8
CVE-2026-62447

Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versi

8.8
CVE-2026-62464

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers

8.8
CVE-2026-62476

Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).

8.8
CVE-2026-62478

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)

8.8
CVE-2026-62496

Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Suppor

8.8
CVE-2026-62498

Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Sup

8.8
CVE-2026-62534

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Suppo

8.8
CVE-2026-14551

The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are v

8.8
CVE-2026-65595

n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardle

8.8
CVE-2026-65603

The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated pr

8.8
CVE-2026-60373

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

8.8
CVE-2026-60439

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

8.8
CVE-2026-60455

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

8.8
CVE-2026-61246

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

8.8
CVE-2026-15017

The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin

8.8
CVE-2026-65897

Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing au

8.8
CVE-2026-14328

The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privil

8.8
CVE-2026-15992

The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.

8.8
CVE-2026-12144

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl

8.8
CVE-2026-17751

Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute ar

8.8
CVE-2026-17868

Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform priv

8.8
CVE-2026-17950

Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to

8.8
CVE-2026-17956

Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute

8.8
CVE-2026-17969

Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute a

8.8
CVE-2026-15414

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and incl

8.8
CVE-2026-16635

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0

8.8
CVE-2026-67356

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowin

8.8
CVE-2026-18322

The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu

8.8
CVE-2026-15215

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing

8.8
CVE-2026-18950

A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how Rol

8.8
CVE-2026-72534

A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s

Frequently Asked Questions

What is CWE-269?

CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-269?

There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.

How can I protect against CWE-269 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.

Detect CWE-269 Vulnerabilities

CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.

Get Started