What is CWE-269?
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-269 is a class-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Language: Not Language-Specific.
Source: MITRE CWE (CWE-269 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Access Control — Gain Privileges or Assume Identity
Source: MITRE CWE, common consequences.
How CWE-269 is exploited in the wild
Threadlinqs maps 38 CVEs to CWE-269, published between 2020-12-09 and 2026-09-29. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 9 critical, 18 high, 8 medium. The highest EPSS score in the set is 22.7% (CVE-2026-21533), the modelled probability of exploitation in the next 30 days. 160 tracked threats reference CWE-269 directly or through a CVE it covers; the most recent is “CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD” (2026-10-02). Affected products concentrate in Oracle Corporation (8), Linuxfabrik (2), Microsoft (2), among 29 vendors in total.
Vulnerabilities (CVEs)
All 38 CVEs mapped to CWE-269, CISA KEV first, then by CVSS score.
- CVE-2026-84869 — CISA KEV · CVSS 9.9 critical · EPSS 0.6% · published 2026-09-08
- CVE-2026-21533 — CISA KEV · CVSS 7.8 high · EPSS 22.7% · published 2026-02-10
- CVE-2026-60366 — CVSS 10 critical · published 2026-07-22
- CVE-2026-60369 — CVSS 9.9 critical · EPSS 0.4% · published 2026-07-22
- CVE-2026-58053 — CVSS 9.9 critical · EPSS 0.2% · published 2026-06-28
- CVE-2026-46817 — CVSS 9.8 critical · EPSS 0.6% · published 2026-05-28
- CVE-2026-60367 — CVSS 9.8 critical · EPSS 0.5% · published 2026-07-22
- CVE-2026-60372 — CVSS 9.8 critical · EPSS 0.5% · published 2026-07-22
- CVE-2026-15369 — CVSS 9.8 critical · published 2026-08-29
- CVE-2026-73842 — CVSS 9 critical · EPSS 0.1% · published 2026-08-13
- CVE-2026-60373 — CVSS 8.8 high · EPSS 0.4% · published 2026-07-22
- CVE-2026-77203 — CVSS 8.8 high · EPSS 0.3% · published 2026-09-26
- CVE-2026-57995 — CVSS 8.8 high · EPSS 0.3% · published 2026-06-30
- CVE-2026-67356 — CVSS 8.8 high · EPSS 0.2% · published 2026-08-02
- CVE-2026-94425 — CVSS 8.8 high · EPSS 0.1% · published 2026-09-21
- CVE-2026-60439 — CVSS 8.8 high · published 2026-07-22
- CVE-2026-102317 — CVSS 8.6 high · published 2026-09-29
- CVE-2026-43978 — CVSS 8.1 high · EPSS 0.2% · published 2026-07-16
- CVE-2026-87958 — CVSS 8.1 high · EPSS 0.2% · published 2026-09-10
- CVE-2023-3467 — CVSS 8 high · EPSS 0.4% · published 2023-07-19
- CVE-2026-60371 — CVSS 8 high · EPSS 0.2% · published 2026-07-22
- CVE-2023-20598 — CVSS 7.8 high · EPSS 0.4% · published 2023-10-17
- CVE-2026-90894 — CVSS 7.8 high · EPSS 0.1% · published 2026-09-14
- CVE-2026-62145 — CVSS 7.5 high · EPSS 0.3% · published 2026-07-22
- CVE-2026-87998 — CVSS 7.1 high · EPSS 0.2% · published 2026-09-09
- CVE-2026-55550 — CVSS 7.1 high · EPSS 0.1% · published 2026-07-20
- CVE-2020-17103 — CVSS 7 high · EPSS 1.0% · published 2020-12-09
- CVE-2026-94048 — CVSS 6.6 medium · EPSS 0.2% · published 2026-09-20
- CVE-2026-94047 — CVSS 6.3 medium · EPSS 0.4% · published 2026-09-20
- CVE-2026-16764 — CVSS 6.3 medium · EPSS 0.2% · published 2026-07-23
- CVE-2026-22721 — CVSS 6.2 medium · EPSS 0.0% · published 2026-02-25
- CVE-2026-20246 — CVSS 6 medium · EPSS 0.1% · published 2026-06-17
- CVE-2026-73973 — CVSS 5.5 medium · EPSS 0.2% · published 2026-08-18
- CVE-2026-73974 — CVSS 5.5 medium · EPSS 0.1% · published 2026-08-18
- CVE-2026-90487 — CVSS 4.3 medium · published 2026-09-12
- CVE-2026-53645 — EPSS 0.2% · published 2026-07-06
- CVE-2026-53444 — EPSS 0.2% · published 2026-07-15
- CVE-2026-73664 — published 2026-08-13
Affected vendors
- Oracle Corporation — 8 CVEs
- Linuxfabrik — 2 CVEs
- Microsoft — 2 CVEs
- AMD — 1 CVE
- Addify — 1 CVE
- ArcadeData — 1 CVE
- Cisco — 1 CVE
- Citrix — 1 CVE
- CodeAstro — 1 CVE
- ConnectWise — 1 CVE
- FOSSBilling — 1 CVE
- FreePBX — 1 CVE
Threat activity
160 tracked threats cite CWE-269; the 25 most recent are listed.
- CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVDCRITICAL
- Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)CRITICAL
- Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)CRITICAL
- Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)CRITICAL
- Zero-Permission Android Apps Can Chain AtlasService and olc2 to Gain Root on OnePlus/OPPO Devices via OxygenOS Confused-Deputy FlawsHIGH
- Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal Browser/Crypto CredentialsHIGH
- ConfigConfusion: Missing Authorization Check in GCP Config Connector Lets a Kubernetes Namespace User Seize Organization OwnerCRITICAL
- Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing Flaws Across Azure and Copilot AI Products, Plus a Windows Secure Kernel EoP (CVE-2026-85921)CRITICAL
- CISA Warns of Active Exploitation of Critical ConnectWise ScreenConnect Flaw (CVE-2026-84869, CVSS 9.9)CRITICAL
- CVE-2026-90894 ("ParaShells"): Parallels Desktop for Mac Local Privilege Escalation via Appliance Extract Argument InjectionHIGH
- CVE-2026-87886: Actively Exploited Privilege Escalation Flaw in Acronis cPanel Backup PluginHIGH
- SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent BackdoorCRITICAL
- Dell ObjectScale Critical Deserialization Flaw (CVE-2026-70416, CVSS 10.0) Enables Unauthenticated RCECRITICAL
- Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment InjectionMEDIUM
- Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)CRITICAL
- Multiple Fortinet FortiOS Vulnerabilities (incl. CVE-2024-23113) Affect Siemens RUGGEDCOM APE1808 via Bundled Fortinet NGFW < V7.4.3 (SSA-832273)CRITICAL
- Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated Cyberattacks and Data TheftCRITICAL
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046)CRITICAL
- FalconFlank — CrowdStrike Falcon Sensor Local Privilege Escalation Zero-Day with Public PoCHIGH
- FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation DLL HijackingHIGH
- HardBreacher PoC Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Local Privilege EscalationMEDIUM
- CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code ExecutionCRITICAL
- Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425)HIGH
- CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud Enumeration (AA26-237A)HIGH
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)HIGH
Mitigations
- Architecture and Design, Operation: Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
- Architecture and Design / Separation of Privilege: Follow the principle of least privilege when assigning access rights to entities in a software system.
- Architecture and Design / Separation of Privilege: Consider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.