In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrec
autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current
A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin use
BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a norm
A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulne
Improperly configured memory protection allows read/write access to modem image from HLOS kernel in Snapdragon Auto, Sna
Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup script
A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Ho
The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity process
An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in memory. An attacker who
An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memory. An attacker who
An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only
Privilege escalation vulnerability in INplc-RT 3.08 and earlier allows an attacker with administrator rights to execute
In the Android kernel in the vl53L0 driver there is a possible out of bounds write due to a permissions bypass. This cou
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call
An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admin
DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an
An issue was discovered in Uniqkey Password Manager 1.14. Upon entering new credentials to a site that is not registered
An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6
Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to ro
On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, a user with the Resource
Optergy Proton/Enterprise devices have an Unauthenticated SMS Sending Service.
MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts ar
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a user with access to audit logs to obtain sensitive
The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
An issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs And
An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0
Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploa
There is an information leakage vulnerability on some Huawei products(AR120-S;AR1200;AR1200-S;AR150;AR150-S;AR160;AR200;
IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror f
Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking
In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration Manager (AAM) wamd pr
In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore requ
Improper access control in the API for the Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenti
The BIG-IP APM Edge Client for macOS bundled with BIG-IP APM 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.
On BIG-IP versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IQ versions
A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict p
An elevation of privilege vulnerability exists in Microsoft Azure Active Directory Connect build 1.3.20.0, which allows
A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of ser
A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should n
It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When
A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d
A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user to view process defin
IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest us
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor
An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.
An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started