On this page

CWE-269: Improper Privilege Management

Weakness Summary

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

  • Canonical source: MITRE CWE-269 (opens in a new tab)
  • Published Atomicorp CVE observations: 13
  • Distinct affected products in those observations: 13
  • Active Atomicorp rules associated with this weakness: 26

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2026-45632Dokploy: Schedule Authorization Bypass Enables Host/Server Command ExecutiondokployAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-64637All Plesk Versions below 18.0.79.5 Reseller Privilege Escalation to RootPleskAttack Blocked by Atomicorp341245 , 344366
CVE-2017-12635Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege EscalationcouchdbAttack Blocked by Atomicorp392301
CVE-2017-5689Intel Active Management Technology - System Privilegesproliant ml10 gen9 server firmwareAttack Blocked by Atomicorp390726 , 392647
CVE-2018-12596Ektron CMS 9.20 SP2 - Improper Access Restrictionsektron cmsAttack Blocked by Atomicorp390727 , 392301 , 392648
CVE-2021-34621WordPress ProfilePress 3.0.0-3.1.3 - Admin User Creation WeaknessprofilepressDetected by Atomicorp377360
CVE-2026-1492WordPress User Registration & Membership <= 5.1.2 - Unauthenticated Privilege EscalationUser Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login BuilderAttack Blocked by Atomicorp300020
CVE-2026-49819UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmdUpSnapAttack Blocked by Atomicorp340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-11423Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege EscalationAltium Enterprise ServerAttack Blocked by Atomicorp344360 , 390709
CVE-2026-7467Read More & Accordion <= 3.5.7 - Authenticated Privilege Escalationexpand-makerDetected by Atomicorp377360
CVE-2026-72830Grav API Plugin before 1.0.13 RCE via ConfigController scope bypassgravAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73664FreePBX: Authenticated Arbitrary SSH Key Injection via Backup ModulebackupAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2017-6339Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilitiesinterscan web security virtual applianceAttack Blocked by Atomicorp340147 , 340148 , 342259 , 345493 , 346755 , 350148 , 390724

Associated Atomicorp WAF Rules

RuleStatusBehavior
300020Activedisruptive (deny)
340014Activedisruptive (deny)
340023Activedisruptive (deny)
340029Activedisruptive (deny)
340147Activedisruptive (deny)
340148Activedisruptive (deny)
341245Activedisruptive (deny)
342259Activedisruptive (deny)
344360Activedisruptive (deny)
344361Activedisruptive (deny)
344363Activedisruptive (deny)
344364Activedisruptive (deny)
344366Activedisruptive (deny)
344370Activedisruptive (deny)
345493Activenon-disruptive (pass)
346755Activedisruptive (deny)
350148Activedisruptive (deny)
377360Activenon-disruptive (pass)
390709Activedisruptive (deny)
390724Activedisruptive (deny)
390726Activedisruptive (deny)
390727Activedisruptive (deny)
392301Activedisruptive (deny)
392647Activedisruptive (deny)
392648Activedisruptive (deny)
393655Activedisruptive (deny)

MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:

CAPEC-122 (opens in a new tab) , CAPEC-233 (opens in a new tab) , CAPEC-58 (opens in a new tab)