Threats Tagged 'cwe-269'
View all threats tagged with 'cwe-269'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-269'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-64637: CWE-269 Improper Privilege Management in WebPros PleskCVE-2026-64637 0 A critical vulnerability in the XML-RPC API of Plesk before version 18.0.80 allows an authenticated reseller to escalate privileges and obtain an administrative session for the root user account. This improper privilege management flaw can lead to full system compromise without user interaction. Join the discussion | GCVE Database | 08/07/2026, 17:57:25 UTC Added: 08/08/2026, 14:52:17 UTC |
CVE-2024-8424: CWE-269 in WatchGuard Endpoint SecurityCVE-2024-8424 0 CVE-2024-8424 is an improper privilege management vulnerability affecting WatchGuard EPDR, Panda AD360, and Panda Dome on Windows in the PSANHost.exe module. It allows an attacker with limited privileges to delete arbitrary files with SYSTEM-level permissions. The vulnerability affects versions of EPDR and Panda AD360 before 8.00.23.0000, and Panda Dome before 22.03.00. The CVSS score is 7.8, indicating a high severity risk. No patch or official fix information is provided in the available data. Join the discussion | GCVE Database | 11/07/2024, 23:27:50 UTC Added: 08/08/2026, 14:51:58 UTC |
CVE-2026-14526: CWE-269 Improper Privilege Management in wupsales AI Copilot – Content GeneratorCVE-2026-14526 0 The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create a new administrator-level user account and achieve full site takeover by saving and executing a malicious workflow containing a wp_create_user action node specifying role=administrator. This vulnerability is exploitable by unauthenticated attackers on any site where the [aiwu-form] shortcode or public chatbot is rendered on a frontend page, as the waic-nonce value is emitted into publicly accessible JavaScript (WAIC_DATA.waicNonce) on those pages, rendering the nonce check a non-functional authorization barrier. Join the discussion | CVE Database V5 | 08/08/2026, 09:30:20 UTC Added: 08/08/2026, 12:51:35 UTC |
CVE-2024-8424: CWE-269 in WatchGuard Endpoint SecurityCVE-2024-8424 0 Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions. Join the discussion | CVE Database V5 | 11/07/2024, 23:27:50 UTC Added: 08/07/2026, 23:56:58 UTC |
CVE-2026-64637: CWE-269 Improper Privilege Management in WebPros PleskCVE-2026-64637 0 Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account. Join the discussion | CVE Database V5 | 08/07/2026, 17:57:25 UTC Added: 08/07/2026, 18:26:48 UTC |
CVE-2026-15215: CWE-269 Improper Privilege Management in Subscriptions for WooCommerceCVE-2026-15215 0 The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution. Join the discussion | CVE Database V5 | 08/07/2026, 06:30:28 UTC Added: 08/07/2026, 06:11:59 UTC |
CVE-2026-48086: CWE-269: Improper Privilege Management in open-reception appointment-booking-softwareCVE-2026-48086 0 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN` enum value from any tenant admin updating their own tenant's staff. No policy check enforces that "only an existing GLOBAL_ADMIN may grant GLOBAL_ADMIN", so the schema validation IS the authorization decision. After re-login, the JWT contains the new role and the formerly-tenant-scoped admin reaches every other tenant on the platform. On the hosted OpenReception service this is a scope-changed escalation: a single customer-side tenant administrator gains full platform-wide administrative control over all other tenants' configuration, users, staff records, operational metadata, and tenant lifecycle. Plaintext appointment contents remain subject to the E2E model unless chained with the staff-crypto poisoning issue (V-4) or with staff-passkey hijacking (V-1). On a single-tenant self-hosted deployment it is still a privilege escalation because TENANT_ADMIN should not be able to create new tenants, modify global configuration, or manage other administrators. The same handler also accepts updates targeted at any colleague within the tenant. A tenant admin can promote a separate collaborator account instead of themselves, leaving their own audit trail clean while the platform-wide breach happens through a separate identity. Version 1.0.2 fixes the issue. Join the discussion | CVE Database V5 | 08/06/2026, 21:30:32 UTC Added: 08/06/2026, 22:13:26 UTC |
CVE-2026-19007: Improper Privilege Management in mf-yang openclaw-cnCVE-2026-19007 0 A vulnerability in mf-yang openclaw-cn up to version 0.2.1 affects the isApprovedElevatedSender function in the src/auto-reply/reply/reply-elevated.ts file. This vulnerability involves improper privilege management and can be exploited remotely. The issue has been publicly disclosed, but the project has not yet responded or issued a fix. Join the discussion | GCVE Database | 08/06/2026, 06:15:08 UTC Added: 08/06/2026, 18:17:09 UTC |
CVE-2026-19005: Improper Privilege Management in nanocoai NanoClawCVE-2026-19005 0 A vulnerability in nanocoai NanoClaw up to version 2.0.64 affects the handleCreateAgent function in the Child-Agent Creation component. This flaw involves improper privilege management that can be exploited remotely. The exploit code is publicly available, but there is no vendor response or patch at this time. Join the discussion | GCVE Database | 08/06/2026, 05:45:09 UTC Added: 08/06/2026, 18:17:07 UTC |
CVE-2026-1728: CWE-269: Improper Privilege Management in WSO2 WSO2 API ManagerCVE-2026-1728 0 Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it. Join the discussion | CVE Database V5 | 08/06/2026, 07:33:25 UTC Added: 08/06/2026, 08:11:48 UTC |
Showing 1 to 10 of 98 results