Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-269 (特权管理不恰当) — Vulnerability Class 1167

1167 vulnerabilities classified as CWE-269 (特权管理不恰当). AI Chinese analysis included.

CWE-269 represents a critical access control weakness where software fails to properly assign, modify, track, or verify privileges for users or processes. This flaw allows actors to operate outside their intended security boundaries, effectively granting them an unintended sphere of control. Attackers typically exploit this vulnerability by manipulating session tokens, bypassing authentication checks, or leveraging insufficient authorization logic to escalate privileges from a standard user to an administrator. Such exploitation can lead to unauthorized data access, system modification, or complete compromise. To prevent this, developers must implement robust identity and access management frameworks that enforce strict least-privilege principles. Regularly auditing permission assignments, utilizing role-based access control, and rigorously validating user rights at every critical application checkpoint are essential strategies to ensure actors only possess the minimum necessary privileges for their specific tasks.

MITRE CWE Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Common Consequences (1)
Access ControlGain Privileges or Assume Identity
Mitigations (3)
Architecture and Design, OperationVery carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
Architecture and DesignFollow the principle of least privilege when assigning access rights to entities in a software system.
Architecture and DesignConsider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource.
Examples (2)
This code temporarily raises the program's privileges to allow creation of a new user folder.
def makeNewUserDir(username): if invalidUsername(username): #avoid CWE-22 and CWE-78 print('Usernames cannot contain invalid characters') return False try: raisePrivileges() os.mkdir('/home/' + username) lowerPrivileges() except OSError: print('Unable to create new user directory for user:' + username) return False return True
Bad · Python
The following example demonstrates the weakness.
seteuid(0); /* do some stuff */ seteuid(getuid());
Bad · C
CVE IDTitleCVSSSeverityPublished
CVE-2026-65835 Capsule: Incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) — capsule 6.6 Medium2026-07-30
CVE-2026-14980 IBM WebSphere Application Server Liberty is affected by a cross-site request forgery — WebSphere Application Server - Liberty 8.3 High2026-07-30
CVE-2026-12144 Wholesale for WooCommerce <= 2.0.5 - Authenticated (Author+) Privilege Escalation via 'user_role_set' Parameter — Wholesale for WooCommerce 8.8 High2026-07-29
CVE-2026-15992 WP Password Policy <= 3.7.1 - Authenticated (Subscriber+) Privilege Escalation — WP Password Policy 8.8 High2026-07-28
CVE-2026-18107 Criu: criu: container escape via rseq critical section hijack during checkpoint/restore — Red Hat Enterprise Linux 10 7.8 High2026-07-28
CVE-2026-14328 Eazy Plugin Manager <= 4.4.1 - Authenticated (Subscriber+) Privilege Escalation via pos_get_option AJAX Action and admin/login REST Endpoint — Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress 8.8 High2026-07-28
CVE-2026-66015 JFrog Platform contains an authorization flaw that may allow authenticated privilege escalation. — artifactory 7.2 High2026-07-27
CVE-2026-66399 phpMyFAQ before 4.1.6 Privilege Escalation via Group Membership — phpMyFAQ 6.5 Medium2026-07-27
CVE-2026-12502 Loytec LINX firmware: Improper Privilege Management in /usr/bin/ltsudo — LIP-ME20xC 8.4 High2026-07-24
CVE-2026-16743 Accountsservice: accountsservice: arbitrary file read via seticonfile for systemd-homed users — Red Hat Enterprise Linux 10 5.5 Medium2026-07-24
CVE-2026-10610 Local privilege escalation in ESET security applications for macOS — ESET Endpoint Security for macOS 8.5 High2026-07-24
CVE-2026-7483 Local privilege escalation in ESET security applications for macOS — ESET Endpoint Security for macOS 8.5 High2026-07-24
CVE-2026-12736 WPify Woo <= 5.4.16 - Authenticated (Shop Manager+) Privilege Escalation via Arbitrary Option Update via save_option REST Endpoint — WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce 8.0 High2026-07-24
CVE-2026-16764 OWASP DefectDojo API/Web serializers.py UserSerializer privileges management — DefectDojo 6.3 Medium2026-07-23
CVE-2026-65897 Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups — grav 8.8 High2026-07-23
CVE-2026-15017 MDJM Event Management <= 1.7.8.4 - Authenticated (Subscriber+) Privilege Escalation via 'set-permissions' and 'change_role' Handlers — MDJM Event Management 8.8 High2026-07-23
CVE-2026-16607 Authenticated local root privilege escalation vulnerability in openFT for Linux and Oracle Solaris — Linux openFT 7.8 High2026-07-22
CVE-2026-62145 Local Privilege Escalation in Gaia Portal — Quantum Security Gateway 7.5 High2026-07-22
CVE-2026-65603 Grav Login Plugin 3.8.11 Privilege Escalation via Profile Update — grav 8.8 High2026-07-22
CVE-2026-65595 n8n before 2.29.8 and 2.30.1 Privilege Escalation via Token Exchange — n8n 8.9 High2026-07-22
CVE-2026-47416 praisonai-platform: Any workspace member can promote themselves (or any other member) to owner via PATCH /workspaces/{id}/members/{user_id} — praisonai-platform 9.6 Critical2026-07-21
CVE-2026-47413 praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members — praisonai-platform 9.6 Critical2026-07-21
CVE-2026-47412 praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id} — praisonai-platform 8.1 High2026-07-21
CVE-2026-47411 praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id} — praisonai-platform 6.5 Medium2026-07-21
CVE-2026-47409 praisonai-platform: Any workspace member can remove any other member (including the owner) via DELETE /workspaces/{id}/members/{user_id} — praisonai-platform 8.1 High2026-07-21
CVE-2026-47407 PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation — praisonai-platform--2026-07-21
CVE-2026-13439 Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint — Easy Form Builder by WhiteStudio – Drag & Drop Form Builder 9.8 Critical2026-07-21
CVE-2026-55550 NextCRM has RBAC Bypass in MCP Product Tools that Allows Low-Privileged Users to Modify the CRM Product Catalog — nextcrm-app 7.1 High2026-07-20
CVE-2026-16337 DotCMS 权限许可和访问控制问题漏洞 — dotCMS--2026-07-20
CVE-2026-62183 Apache Syncope: User self-service privilege escalation — Apache Syncope--2026-07-20

Vulnerabilities classified as CWE-269 (特权管理不恰当) represent 1167 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.