# CWE-269: Improper Privilege Management

**Likelihood of exploit:** Medium · **KEV-linked**

> As of 2026-10-05, CWE-269 (Improper Privilege Management) underlies 38 CVEs tracked by Threadlinqs, 2 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 160 tracked threats. MITRE rates its likelihood of exploit as Medium.

**Last updated:** 2026-10-05

## What is CWE-269?

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

CWE-269 is a class-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Language: Not Language-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/269.html) (CWE-269 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Access Control** — Gain Privileges or Assume Identity

_Source: MITRE CWE, common consequences._

## How CWE-269 is exploited in the wild

Threadlinqs maps 38 CVEs to CWE-269, published between 2020-12-09 and 2026-09-29. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 9 critical, 18 high, 8 medium. The highest EPSS score in the set is 22.7% (CVE-2026-21533), the modelled probability of exploitation in the next 30 days. 160 tracked threats reference CWE-269 directly or through a CVE it covers; the most recent is “CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD” (2026-10-02). Affected products concentrate in Oracle Corporation (8), Linuxfabrik (2), Microsoft (2), among 29 vendors in total.

## Vulnerabilities (CVEs)

All 38 CVEs mapped to CWE-269, CISA KEV first, then by CVSS score.

- [CVE-2026-84869](https://intel.threadlinqs.com/cve/CVE-2026-84869) — CISA KEV · CVSS 9.9 critical · EPSS 0.6% · published 2026-09-08
- [CVE-2026-21533](https://intel.threadlinqs.com/cve/CVE-2026-21533) — CISA KEV · CVSS 7.8 high · EPSS 22.7% · published 2026-02-10
- [CVE-2026-60366](https://intel.threadlinqs.com/cve/CVE-2026-60366) — CVSS 10 critical · published 2026-07-22
- [CVE-2026-60369](https://intel.threadlinqs.com/cve/CVE-2026-60369) — CVSS 9.9 critical · EPSS 0.4% · published 2026-07-22
- [CVE-2026-58053](https://intel.threadlinqs.com/cve/CVE-2026-58053) — CVSS 9.9 critical · EPSS 0.2% · published 2026-06-28
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817) — CVSS 9.8 critical · EPSS 0.6% · published 2026-05-28
- [CVE-2026-60367](https://intel.threadlinqs.com/cve/CVE-2026-60367) — CVSS 9.8 critical · EPSS 0.5% · published 2026-07-22
- [CVE-2026-60372](https://intel.threadlinqs.com/cve/CVE-2026-60372) — CVSS 9.8 critical · EPSS 0.5% · published 2026-07-22
- [CVE-2026-15369](https://intel.threadlinqs.com/cve/CVE-2026-15369) — CVSS 9.8 critical · published 2026-08-29
- [CVE-2026-73842](https://intel.threadlinqs.com/cve/CVE-2026-73842) — CVSS 9 critical · EPSS 0.1% · published 2026-08-13
- [CVE-2026-60373](https://intel.threadlinqs.com/cve/CVE-2026-60373) — CVSS 8.8 high · EPSS 0.4% · published 2026-07-22
- [CVE-2026-77203](https://intel.threadlinqs.com/cve/CVE-2026-77203) — CVSS 8.8 high · EPSS 0.3% · published 2026-09-26
- [CVE-2026-57995](https://intel.threadlinqs.com/cve/CVE-2026-57995) — CVSS 8.8 high · EPSS 0.3% · published 2026-06-30
- [CVE-2026-67356](https://intel.threadlinqs.com/cve/CVE-2026-67356) — CVSS 8.8 high · EPSS 0.2% · published 2026-08-02
- [CVE-2026-94425](https://intel.threadlinqs.com/cve/CVE-2026-94425) — CVSS 8.8 high · EPSS 0.1% · published 2026-09-21
- [CVE-2026-60439](https://intel.threadlinqs.com/cve/CVE-2026-60439) — CVSS 8.8 high · published 2026-07-22
- [CVE-2026-102317](https://intel.threadlinqs.com/cve/CVE-2026-102317) — CVSS 8.6 high · published 2026-09-29
- [CVE-2026-43978](https://intel.threadlinqs.com/cve/CVE-2026-43978) — CVSS 8.1 high · EPSS 0.2% · published 2026-07-16
- [CVE-2026-87958](https://intel.threadlinqs.com/cve/CVE-2026-87958) — CVSS 8.1 high · EPSS 0.2% · published 2026-09-10
- [CVE-2023-3467](https://intel.threadlinqs.com/cve/CVE-2023-3467) — CVSS 8 high · EPSS 0.4% · published 2023-07-19
- [CVE-2026-60371](https://intel.threadlinqs.com/cve/CVE-2026-60371) — CVSS 8 high · EPSS 0.2% · published 2026-07-22
- [CVE-2023-20598](https://intel.threadlinqs.com/cve/CVE-2023-20598) — CVSS 7.8 high · EPSS 0.4% · published 2023-10-17
- [CVE-2026-90894](https://intel.threadlinqs.com/cve/CVE-2026-90894) — CVSS 7.8 high · EPSS 0.1% · published 2026-09-14
- [CVE-2026-62145](https://intel.threadlinqs.com/cve/CVE-2026-62145) — CVSS 7.5 high · EPSS 0.3% · published 2026-07-22
- [CVE-2026-87998](https://intel.threadlinqs.com/cve/CVE-2026-87998) — CVSS 7.1 high · EPSS 0.2% · published 2026-09-09
- [CVE-2026-55550](https://intel.threadlinqs.com/cve/CVE-2026-55550) — CVSS 7.1 high · EPSS 0.1% · published 2026-07-20
- [CVE-2020-17103](https://intel.threadlinqs.com/cve/CVE-2020-17103) — CVSS 7 high · EPSS 1.0% · published 2020-12-09
- [CVE-2026-94048](https://intel.threadlinqs.com/cve/CVE-2026-94048) — CVSS 6.6 medium · EPSS 0.2% · published 2026-09-20
- [CVE-2026-94047](https://intel.threadlinqs.com/cve/CVE-2026-94047) — CVSS 6.3 medium · EPSS 0.4% · published 2026-09-20
- [CVE-2026-16764](https://intel.threadlinqs.com/cve/CVE-2026-16764) — CVSS 6.3 medium · EPSS 0.2% · published 2026-07-23
- [CVE-2026-22721](https://intel.threadlinqs.com/cve/CVE-2026-22721) — CVSS 6.2 medium · EPSS 0.0% · published 2026-02-25
- [CVE-2026-20246](https://intel.threadlinqs.com/cve/CVE-2026-20246) — CVSS 6 medium · EPSS 0.1% · published 2026-06-17
- [CVE-2026-73973](https://intel.threadlinqs.com/cve/CVE-2026-73973) — CVSS 5.5 medium · EPSS 0.2% · published 2026-08-18
- [CVE-2026-73974](https://intel.threadlinqs.com/cve/CVE-2026-73974) — CVSS 5.5 medium · EPSS 0.1% · published 2026-08-18
- [CVE-2026-90487](https://intel.threadlinqs.com/cve/CVE-2026-90487) — CVSS 4.3 medium · published 2026-09-12
- [CVE-2026-53645](https://intel.threadlinqs.com/cve/CVE-2026-53645) — EPSS 0.2% · published 2026-07-06
- [CVE-2026-53444](https://intel.threadlinqs.com/cve/CVE-2026-53444) — EPSS 0.2% · published 2026-07-15
- [CVE-2026-73664](https://intel.threadlinqs.com/cve/CVE-2026-73664) — published 2026-08-13

## Affected vendors

- **Oracle Corporation** — 8 CVEs
- **Linuxfabrik** — 2 CVEs
- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 2 CVEs
- **AMD** — 1 CVE
- **Addify** — 1 CVE
- **ArcadeData** — 1 CVE
- [Cisco](https://intel.threadlinqs.com/vendors/cisco) — 1 CVE
- [Citrix](https://intel.threadlinqs.com/vendors/citrix) — 1 CVE
- **CodeAstro** — 1 CVE
- **ConnectWise** — 1 CVE
- [FOSSBilling](https://intel.threadlinqs.com/vendors/fossbilling) — 1 CVE
- **FreePBX** — 1 CVE

## Threat activity

160 tracked threats cite CWE-269; the 25 most recent are listed.

- [CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD](https://intel.threadlinqs.com/threat/TL-2026-2843) — CRITICAL · 2026-10-02
- [Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)](https://intel.threadlinqs.com/threat/TL-2026-2851) — CRITICAL · 2026-10-02
- [Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)](https://intel.threadlinqs.com/threat/TL-2026-2902) — CRITICAL · 2026-10-02
- [Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)](https://intel.threadlinqs.com/threat/TL-2026-2803) — CRITICAL · 2026-09-30
- [Zero-Permission Android Apps Can Chain AtlasService and olc2 to Gain Root on OnePlus/OPPO Devices via OxygenOS Confused-Deputy Flaws](https://intel.threadlinqs.com/threat/TL-2026-2683) — HIGH · 2026-09-27
- [Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal Browser/Crypto Credentials](https://intel.threadlinqs.com/threat/TL-2026-2664) — HIGH · 2026-09-26
- [ConfigConfusion: Missing Authorization Check in GCP Config Connector Lets a Kubernetes Namespace User Seize Organization Owner](https://intel.threadlinqs.com/threat/TL-2026-2629) — CRITICAL · 2026-09-23
- [Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing Flaws Across Azure and Copilot AI Products, Plus a Windows Secure Kernel EoP (CVE-2026-85921)](https://intel.threadlinqs.com/threat/TL-2026-2563) — CRITICAL · 2026-09-18
- [CISA Warns of Active Exploitation of Critical ConnectWise ScreenConnect Flaw (CVE-2026-84869, CVSS 9.9)](https://intel.threadlinqs.com/threat/TL-2026-2533) — CRITICAL · 2026-09-16
- [CVE-2026-90894 ("ParaShells"): Parallels Desktop for Mac Local Privilege Escalation via Appliance Extract Argument Injection](https://intel.threadlinqs.com/threat/TL-2026-2536) — HIGH · 2026-09-16
- [CVE-2026-87886: Actively Exploited Privilege Escalation Flaw in Acronis cPanel Backup Plugin](https://intel.threadlinqs.com/threat/TL-2026-2523) — HIGH · 2026-09-15
- [SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2497) — CRITICAL · 2026-09-14
- [Dell ObjectScale Critical Deserialization Flaw (CVE-2026-70416, CVSS 10.0) Enables Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-2475) — CRITICAL · 2026-09-13
- [Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injection](https://intel.threadlinqs.com/threat/TL-2026-2478) — MEDIUM · 2026-09-13
- [Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)](https://intel.threadlinqs.com/threat/TL-2026-2486) — CRITICAL · 2026-09-13
- [Multiple Fortinet FortiOS Vulnerabilities (incl. CVE-2024-23113) Affect Siemens RUGGEDCOM APE1808 via Bundled Fortinet NGFW < V7.4.3 (SSA-832273)](https://intel.threadlinqs.com/threat/TL-2026-2489) — CRITICAL · 2026-09-13
- [Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated Cyberattacks and Data Theft](https://intel.threadlinqs.com/threat/TL-2026-2466) — CRITICAL · 2026-09-12
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046)](https://intel.threadlinqs.com/threat/TL-2026-2407) — CRITICAL · 2026-09-08
- [FalconFlank — CrowdStrike Falcon Sensor Local Privilege Escalation Zero-Day with Public PoC](https://intel.threadlinqs.com/threat/TL-2026-2350) — HIGH · 2026-09-06
- [FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation DLL Hijacking](https://intel.threadlinqs.com/threat/TL-2026-2362) — HIGH · 2026-09-06
- [HardBreacher PoC Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Local Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-2258) — MEDIUM · 2026-08-31
- [CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code Execution](https://intel.threadlinqs.com/threat/TL-2026-2177) — CRITICAL · 2026-08-28
- [Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425)](https://intel.threadlinqs.com/threat/TL-2026-2182) — HIGH · 2026-08-28
- [CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud Enumeration (AA26-237A)](https://intel.threadlinqs.com/threat/TL-2026-2161) — HIGH · 2026-08-26
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — HIGH · 2026-08-21

## Mitigations

- **Architecture and Design, Operation**: Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
- **Architecture and Design / Separation of Privilege**: Follow the principle of least privilege when assigning access rights to entities in a software system.
- **Architecture and Design / Separation of Privilege**: Consider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource.

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Automated Static Analysis** (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-284 Improper Access Control](https://intel.threadlinqs.com/cwe/CWE-284)

Canonical: https://intel.threadlinqs.com/cwe/CWE-269
Source definition: https://cwe.mitre.org/data/definitions/269.html
Detection rules and IOCs for threats exploiting CWE-269 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
