The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it m
The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after use
An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper p
The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields fro
In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves th
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0
A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC
A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA)
CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through po
A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient val
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software fo
An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system
CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation le
In VBMeta, there is a possible way to modify and resign VBMeta using a test key, assuming the original image was previou
In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. Thi
In createSessionInternal of PackageInstallerService.java, there is a possible way for an app to update its ownership due
In multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This c
International Data Casting (IDC) SFX2100 satellite receiver comes with the `/sbin/ip` utility installed with the setuid
A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a l
Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DP
The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory.
Improper Privilege Management in certain Zoom Clients for Windows may allow an authenticated user to conduct an escalati
OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in
Hirschmann Industrial HiVision versions 05.0.00 through 08.3.01 prior to 08.3.02 contain an arbitrary code execution vul
The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a
AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service avail
An issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escal
AGL app-framework-binder (afb-daemon) through v19.90.0 contains a privilege escalation vulnerability in the supervision
An issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and Perf
Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker t
PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonom
A consistency issue was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonom
The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Ta
In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalat
In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missi
In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell u
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke
Inappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass la
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged age
Frequently Asked Questions
What is CWE-269?
CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-269?
There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.
How can I protect against CWE-269 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.
Detect CWE-269 Vulnerabilities
CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.
Get Started