Threadlinqs IntelligenceStart free

Weakness · ClassCWE-269

CWE-269: Improper Privilege Management

Likelihood of exploit: MediumKEV-linkedClass

As of 2026-10-05, CWE-269 (Improper Privilege Management) underlies 38 CVEs tracked by Threadlinqs, 2 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 160 tracked threats. MITRE rates its likelihood of exploit as Medium.

CVEs
38Mapped to CWE-269
CISA KEV
2Exploited in the wild
Critical
9CVSS v3 critical CVEs
Threats
160Tracked campaigns citing it
Likelihood
MediumMITRE likelihood of exploit

Last updated:

What is CWE-269?

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

CWE-269 is a class-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Language: Not Language-Specific.

Source: MITRE CWE (CWE-269 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Access Control — Gain Privileges or Assume Identity

Source: MITRE CWE, common consequences.

How CWE-269 is exploited in the wild

Threadlinqs maps 38 CVEs to CWE-269, published between 2020-12-09 and 2026-09-29. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 9 critical, 18 high, 8 medium. The highest EPSS score in the set is 22.7% (CVE-2026-21533), the modelled probability of exploitation in the next 30 days. 160 tracked threats reference CWE-269 directly or through a CVE it covers; the most recent is “CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD” (2026-10-02). Affected products concentrate in Oracle Corporation (8), Linuxfabrik (2), Microsoft (2), among 29 vendors in total.

Vulnerabilities (CVEs)

All 38 CVEs mapped to CWE-269, CISA KEV first, then by CVSS score.

Affected vendors

  • Oracle Corporation — 8 CVEs
  • Linuxfabrik — 2 CVEs
  • Microsoft — 2 CVEs
  • AMD — 1 CVE
  • Addify — 1 CVE
  • ArcadeData — 1 CVE
  • Cisco — 1 CVE
  • Citrix — 1 CVE
  • CodeAstro — 1 CVE
  • ConnectWise — 1 CVE
  • FOSSBilling — 1 CVE
  • FreePBX — 1 CVE

Threat activity

160 tracked threats cite CWE-269; the 25 most recent are listed.

Mitigations

  • Architecture and Design, Operation: Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
  • Architecture and Design / Separation of Privilege: Follow the principle of least privilege when assigning access rights to entities in a software system.
  • Architecture and Design / Separation of Privilege: Consider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.