Improper Privilege Management (CWE-269)
CWE-269 is a Class for products that do not properly assign, modify, track or check an actor's privileges. The result is an unintended sphere of control for that actor. MITRE discourages mapping to it, noting it is often confused with privilege escalation, which is an impact rather than a root cause.
About CWE-269
The listed consequence is that an actor gains privileges or assumes an identity beyond what was intended.
MITRE marks CWE-269 as DISCOURAGED for mapping real-world vulnerabilities because it is often conflated with the privilege escalation impact.
Mitigations
- +Manage the setting and handling of privileges carefully and define trust zones explicitly.
- +Follow the principle of least privilege when assigning access rights.
- +Apply separation of privilege by requiring multiple conditions before granting access to a resource.
Detection
Automated static analysis (SAST) is rated highly effective at finding some instances.
CWE-269 Vulnerabilities
11 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-84869 | ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions | ConnectWise | 9.9 | 0.9% | KEV | 2026-09-08 |
| CVE-2026-21533 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | Microsoft | 7.8 | 4.2% | KEV | 2026-02-10 |
| CVE-2024-8068 | Privilege escalation to NetworkService Account access | Citrix | 5.1 | 3.5% | KEV | 2024-11-12 |
| CVE-2024-49035 | Partner.Microsoft.Com Elevation of Privilege Vulnerability | Microsoft | 8.7 | 1.3% | KEV | 2024-11-26 |
| CVE-2024-38014 | Windows Installer Elevation of Privilege Vulnerability | Microsoft | 7.8 | 6.3% | KEV | 2024-09-10 |
| CVE-2024-26169 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Microsoft | 7.8 | 4.0% | KEV | 2024-03-12 |
| CVE-2023-28434 | MinIO is vulnerable to privilege escalation on Linux/MacOS | minio | 8.8 | 7.9% | KEV | 2023-03-22 |
| CVE-2021-25337 | Samsung Mobile Devices Improper Access Control Vulnerability | Samsung Mobile | 4.4 | 2.8% | KEV | 2021-03-04 |
| CVE-2021-20021 | SonicWall Email Security Improper Privilege Management Vulnerability | SonicWall | 9.8 | 88.8% | KEV | 2021-04-09 |
| CVE-2021-23874 | McAfee Total Protection (MTP) privilege escalation vulnerability | McAfee,LLC | 8.2 | 1.0% | KEV | 2021-02-10 |
| CVE-2026-1492 | User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration | wpeverest | 9.8 | 28.0% | 2026-03-03 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-269?→
CWE-269 is improper privilege management: the product mishandles the assignment, change, tracking or checking of privileges.
Should 'privilege escalation' reports be mapped to CWE-269?→
MITRE says no when only the impact is known. The CWE for the actual mistake that allowed escalation should be used.
How many exploited vulnerabilities are classified as CWE-269?→
This database lists 11 CVE records mapped to CWE-269 by their CVE Numbering Authority. 10 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 2 to known ransomware campaigns. Examples include CVE-2026-84869, CVE-2026-21533, CVE-2024-8068.
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.