A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
1,014 vulnerabilities with CWE-266
CVE-2026-53902
MEDIUM
Mycomplianceoffice Mco < 25.3.3.1 - Privilege Escalation
CVSS 6.5
CVE-2026-56247
HIGH
Capgo - Privilege Escalation via Cross-Scope RBAC Role Assignment
CVSS 8.8
CVE-2026-4629
MEDIUM
Keycloak: keycloak: privilege escalation through hardcoded role mapper injection
CVSS 6.5
CVE-2026-12388
MEDIUM
Keycloak-broker: keycloak: privilege escalation to realm administrator via improper authorization in identity provider mapper
CVSS 6.5
CVE-2026-13591
MEDIUM
DeepMyst Mysti Contact Tracking ChannelBridge.ts _isTrackedConversation improper authorization
CVSS 5.0
CVE-2026-13568
HIGH
SourceCodester Inventory Management System User Registration Endpoint users_handler.php access control
CVSS 7.3
CVE-2026-22078
HIGH
O+ Connect's lack of authentication for IPC channels led to a local privilege escalation vulnerability.
CVSS 7.3
CVE-2026-13544
MEDIUM
Feehi CMS API users access control
CVSS 6.3
CVE-2026-13524
MEDIUM
CherryHQ cherry-studio MCP OAuth Local Callback Server callback.ts improper authorization
CVSS 5.6
CVE-2026-13511
LOW
VoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation improper authorization
CVSS 3.1
CVE-2026-49413
HIGH
FreeBSD - Flaw in Linuxulator Execution of Setugid Binaries
CVSS 7.1
CVE-2026-45259
MEDIUM
FreeBSD - Sigqueue(2) Missing Capability Mode Restriction
CVSS 6.5
CVE-2026-56033
CRITICAL
WordPress Dokan Pro plugin <= 5.0.4 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-56030
CRITICAL
WordPress Paytium plugin <= 5.0.2 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-56028
CRITICAL
WordPress Easy Elements for Elementor – Addons & Website Templates plugin <= 1.4.9 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-56010
HIGH
WordPress Abandoned Cart Pro for WooCommerce plugin <= 10.4.0 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-56008
HIGH
WordPress Fusion Builder plugin <= 3.15.4 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-12164
MEDIUM
Privilege Escalation in Fortra File Integrity Monitoring (FIM)
CVSS 4.4
CVE-2026-12823
LOW
Browserbase Autobrowse Trace Artifact default permission
CVSS 3.3
CVE-2026-56251
MEDIUM
Capgo - Privilege Escalation via Broken Row Level Security in org_users
CVSS 6.5
CVE-2026-12799
MEDIUM
BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization
CVSS 4.3
CVE-2026-12786
HIGH
Ezbsystems UltraISO Premium Edition Kernel Driver bootpt64.sys access control
CVSS 7.8
CVE-2026-12784
HIGH
IM-Magic Partition Resizer Kernel Driver MDA_NTDRV.sys access control
CVSS 7.8
CVE-2026-12782
HIGH
EaseUS Partition Master Kernel Driver EUEDKEPM.sys access control
CVSS 7.8
CVE-2026-12781
HIGH
EaseUS Partition Master Kernel Driver epmntdrv.sys access control
CVSS 7.8
Details
Vulnerabilities
1,014