CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

3,089 vulnerabilities with CWE-269
CVE-2026-65835 MEDIUM
Capsule >= 0.13.0, < 0.13.8 - Cross-Tenant Cluster-Scoped Resource Creation
CVSS 6.6
CVE-2026-14980 HIGH
IBM WebSphere Application Server Liberty is affected by a cross-site request forgery
CVSS 8.3
CVE-2026-12687 HIGH
ProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted Group ID
CVSS 7.5
CVE-2026-17969 HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.8
CVE-2026-17956 HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.8
CVE-2026-17952 HIGH
Google Chrome - Arbitrary Code Execution
CVSS 7.5
CVE-2026-17950 HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.8
CVE-2026-17877 HIGH
Google Chrome - Privilege Escalation
CVSS 8.4
CVE-2026-17868 HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-17864 HIGH
Google Chrome - Privilege Escalation
CVSS 7.8
CVE-2026-17863 HIGH
Google Chrome - Privilege Escalation
CVSS 7.8
CVE-2026-17816 HIGH
Google Chrome - Privilege Escalation
CVSS 7.5
CVE-2026-17751 HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.8
CVE-2026-17744 HIGH
Google Chrome < 151.0.7922.72 - Sandbox Escape via File Input Inappropriate Implementation on Linux
CVSS 7.1
CVE-2026-12144 HIGH
Wholesale for WooCommerce <= 2.0.5 - Authenticated (Author+) Privilege Escalation via 'user_role_set' Parameter
CVSS 8.8
CVE-2026-18107 HIGH
Criu: criu: container escape via rseq critical section hijack during checkpoint/restore
CVSS 7.8
CVE-2026-15992 HIGH
WP Password Policy <= 3.7.1 - Authenticated (Subscriber+) Privilege Escalation
CVSS 8.8
CVE-2026-14328 HIGH
Eazy Plugin Manager <= 4.4.1 - Authenticated (Subscriber+) Privilege Escalation via pos_get_option AJAX Action and admin/login REST Endpoint
CVSS 8.8
CVE-2026-14545 CRITICAL
TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password Reset
CVSS 9.8
CVE-2026-66015 HIGH
JFrog Platform contains an authorization flaw that may allow authenticated privilege escalation.
CVSS 7.2
CVE-2026-66399 MEDIUM
phpMyFAQ before 4.1.6 Privilege Escalation via Group Membership
CVSS 6.5
CVE-2026-13152 HIGH
Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escalation
CVSS 8.1
CVE-2026-12394 CRITICAL
MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator
CVSS 9.8
CVE-2026-12502 HIGH
Loytec LINX firmware: Improper Privilege Management in /usr/bin/ltsudo
CVE-2026-16743 MEDIUM
Accountsservice: accountsservice: arbitrary file read via seticonfile for systemd-homed users
CVSS 5.5
Details
Vulnerabilities 3,089
Exploit Likelihood Medium