Skip to main content

About CWE-269

The listed consequence is that an actor gains privileges or assumes an identity beyond what was intended.

MITRE marks CWE-269 as DISCOURAGED for mapping real-world vulnerabilities because it is often conflated with the privilege escalation impact.

MITRE name
Improper Privilege Management
Abstraction
Class: a very abstract weakness, typically independent of language or technology
Status
Draft

Mitigations

  • +Manage the setting and handling of privileges carefully and define trust zones explicitly.
  • +Follow the principle of least privilege when assigning access rights.
  • +Apply separation of privilege by requiring multiple conditions before granting access to a resource.

Detection
Automated static analysis (SAST) is rated highly effective at finding some instances.

CWE-269 Vulnerabilities

11 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-84869
ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
ConnectWise9.90.9%KEV2026-09-08
CVE-2026-21533
Windows Remote Desktop Services Elevation of Privilege Vulnerability
Microsoft7.84.2%KEV2026-02-10
CVE-2024-8068
Privilege escalation to NetworkService Account access
Citrix5.13.5%KEV2024-11-12
CVE-2024-49035
Partner.Microsoft.Com Elevation of Privilege Vulnerability
Microsoft8.71.3%KEV2024-11-26
CVE-2024-38014
Windows Installer Elevation of Privilege Vulnerability
Microsoft7.86.3%KEV2024-09-10
CVE-2024-26169
Windows Error Reporting Service Elevation of Privilege Vulnerability
Microsoft7.84.0%KEV2024-03-12
CVE-2023-28434
MinIO is vulnerable to privilege escalation on Linux/MacOS
minio8.87.9%KEV2023-03-22
CVE-2021-25337
Samsung Mobile Devices Improper Access Control Vulnerability
Samsung Mobile4.42.8%KEV2021-03-04
CVE-2021-20021
SonicWall Email Security Improper Privilege Management Vulnerability
SonicWall9.888.8%KEV2021-04-09
CVE-2021-23874
McAfee Total Protection (MTP) privilege escalation vulnerability
McAfee,LLC8.21.0%KEV2021-02-10
CVE-2026-1492
User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration
wpeverest9.828.0%2026-03-03

Most Affected Vendors

Related Weaknesses

Frequently Asked Questions

What is CWE-269?→

CWE-269 is improper privilege management: the product mishandles the assignment, change, tracking or checking of privileges.

Should 'privilege escalation' reports be mapped to CWE-269?→

MITRE says no when only the impact is known. The CWE for the actual mistake that allowed escalation should be used.

How many exploited vulnerabilities are classified as CWE-269?→

This database lists 11 CVE records mapped to CWE-269 by their CVE Numbering Authority. 10 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 2 to known ransomware campaigns. Examples include CVE-2026-84869, CVE-2026-21533, CVE-2024-8068.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.