Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-269

MITRE ↗

Improper Privilege Management

401
CRITICAL
1,938
HIGH
752
MEDIUM
71
LOW
3,229 CVEs · Page 7/65
8.8
CVE-2026-72537

A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s

8.8
CVE-2026-15426

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v

8.8
CVE-2026-73284

RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/servi

8.8
CVE-2026-73293

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5,

8.8
CVE-2026-18713

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could eleva

8.8
CVE-2026-17082

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper val

8.8
CVE-2026-16722

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improp

8.8
CVE-2026-18101

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management of thre

8.8
CVE-2026-73305

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRo

8.8
CVE-2026-72829

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's cr

8.8
CVE-2026-72830

Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowin

8.8
CVE-2026-72833

The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerabili

8.8
CVE-2026-15001

The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up

8.8
CVE-2026-15312

The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all ve

8.8
CVE-2026-14279

The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.2.2

8.8
CVE-2026-70495

A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing

8.8
CVE-2026-75481

SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service acco

8.8
CVE-2026-74935

Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,

8.8
CVE-2026-74939

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,

8.8
CVE-2026-74941

Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 14

8.8
CVE-2026-74942

Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 1

8.8
CVE-2026-74950

Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thu

8.8
CVE-2026-74952

Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154 and Thunderbird 15

8.8
CVE-2026-74953

Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.

8.8
CVE-2026-74955

Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1,

8.8
CVE-2026-74965

Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14

8.8
CVE-2026-61231

Vulnerability in the Oracle Virtual Directory product of Oracle Fusion Middleware (component: Virtual Directory Server).

8.8
CVE-2026-70818

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

8.8
CVE-2026-70819

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

8.8
CVE-2026-70821

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

8.8
CVE-2026-70928

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

8.8
CVE-2026-70940

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

8.8
CVE-2026-70944

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

8.8
CVE-2026-71150

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

8.8
CVE-2026-16850

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command inj

8.8
CVE-2026-68561

Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permiss

8.8
CVE-2026-76253

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_searc

8.8
CVE-2026-76259

In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to

8.8
CVE-2026-76350

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_searc

8.8
CVE-2026-19449

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to

8.8
CVE-2026-59799

Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of t

8.8
CVE-2026-53527

LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user upda

8.8
CVE-2026-19883

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to

8.8
CVE-2026-16149

The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,

8.8
CVE-2026-79226

Improper privilege management in Regional Capabilities in Google Chrome prior to 152.0.7977.65 allowed a remote attacker

8.8
CVE-2026-75977

The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all v

8.8
CVE-2026-55485

Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0,

8.7
CVE-2025-67905

Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which

8.7
CVE-2026-44543

Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.3

8.7
CVE-2026-46804

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The sup

Frequently Asked Questions

What is CWE-269?

CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-269?

There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.

How can I protect against CWE-269 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.

Detect CWE-269 Vulnerabilities

CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.

Get Started