A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
1,014 vulnerabilities with CWE-266
CVE-2026-35671
HIGH
phpMyFAQ - Insecure Direct Object Reference in User Password API
CVSS 8.8
CVE-2026-9795
HIGH
Keycloak: keycloak: privilege escalation via improper scope mapping enforcement
CVSS 7.3
CVE-2026-42758
CRITICAL
WordPress WebinarIgnition plugin < 4.08.253 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-42731
CRITICAL
WordPress miniorange otp verification plugin <= 5.4.9 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-9604
MEDIUM
JeecgBoot AiragModelController access control
CVSS 4.3
CVE-2026-9581
MEDIUM
JeecgBoot add access control
CVSS 6.3
CVE-2026-9580
HIGH
JeecgBoot selectDepart LoginController.selectDepart access control
CVSS 7.3
CVE-2026-9579
MEDIUM
JeecgBoot SysUser userEdit user.getUsername access control
CVSS 6.3
CVE-2026-9562
HIGH
sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard access control
CVSS 7.3
CVE-2026-9517
HIGH
hemant6488 CodeIgniter-StudentManagementSystem Student Management addStudentView access control
CVSS 7.3
CVE-2026-45216
HIGH
WordPress Smart Manager plugin <= 8.85.0 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-9484
MEDIUM
SourceCodester Student Grades Management System classroom.php removeStudentFromClassroom improper authorization
CVSS 6.3
CVE-2026-9483
MEDIUM
SourceCodester Student Grades Management System grades.php improper authorization
CVSS 6.3
CVE-2026-9412
MEDIUM
SourceCodester Indian Invoicing System Backend Endpoint access control
CVSS 6.3
CVE-2026-9410
MEDIUM
Sushmi-pal Invoice-System Profile Workflow profile improper authorization
CVSS 4.3
CVE-2026-9409
MEDIUM
Sushmi-pal Invoice-System User Management user improper authorization
CVSS 4.3
CVE-2026-9397
HIGH
Besen BS20 EV Charging Station OTA Update Installation improper authorization
CVSS 8.1
CVE-2026-9376
MEDIUM
JPress UCenter Article Submission Endpoint doWriteSave improper authorization
CVSS 6.3
CVE-2026-48172
CRITICAL
KEV
LiteSpeed cPanel Plugin < 2.4.5 - Privilege Escalation via Redis Feature Mishandling
CVSS 9.8
CVE-2026-22315
HIGH
Mesalvo Meona Client Launcher <= 19.06.2020 & Server <= 2025.04 - Unprotected User Data Exposure
CVSS 7.2
CVE-2026-8752
MEDIUM
h2oai h2o-3 Rapids setproperty Primitive AstSetProperty.java exec access control
CVSS 5.3
CVE-2026-8747
MEDIUM
Z-BlogPHP Commend Approval c_system_event.php CheckComment improper authorization
CVSS 6.3
CVE-2026-8743
MEDIUM
Open5GS AMF/MME context.c ran_ue_find_by_amf_ue_ngap_id improper authorization
CVSS 6.3
CVE-2026-35062
MEDIUM
F5 BIG-IP 21.1.0-21.0.0.1/17.5.1-17.5.1.4/17.1.0-17.1.3.1/16.1.0 Authenticated Info Disclosure via iControl SOAP
CVSS 6.5
CVE-2026-44997
MEDIUM
OpenClaw < 2026.4.22 - Security Envelope Constraint Bypass in ACP Child Sessions
CVSS 4.3
Details
Vulnerabilities
1,014