CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

3,090 vulnerabilities with CWE-269
CVE-2026-52533 CRITICAL
D-Link DIR-1253 1.0.1.250923.142435 - Privilege Escalation via /etc/shadow File Access
CVSS 9.8
CVE-2026-61463 HIGH
Shiori Authenticated Privilege Escalation via PATCH /api/v1/auth/account
CVSS 8.8
CVE-2026-59245 HIGH
Apache Airflow Fab Provider < 3.7.2 - Privilege Escalation
CVSS 8.1
CVE-2026-59260 HIGH
OpenWrt luci-app-samba4 read ACL remote code execution via smbd
CVSS 8.8
CVE-2026-14262 HIGH
Simple JWT Login <= 3.6.6 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' Parameter
CVSS 8.8
CVE-2026-13756 HIGH
WP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter
CVSS 8.8
CVE-2026-55843 MEDIUM
Snipe-IT: Improper Privilege Management
CVSS 6.5
CVE-2026-51119 CRITICAL
Invixium IXM WEB 2.3.85.25 - Privilege Escalation via SystemUsers/CreateAppUser Endpoint
CVSS 9.1
CVE-2026-40009 MEDIUM
Apache IoTDB 2.0.8 to < 2.0.10 - Authenticated Privilege Escalation
CVSS 6.5
CVE-2026-44787 HIGH
Discourse: Signup-time primary_group_id assignment grants whisperer access
CVSS 8.2
CVE-2026-0276 HIGH
Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability
CVSS 7.8
CVE-2026-0275 MEDIUM
Prisma Browser: Local Privilege Escalation on macOS
CVSS 6.7
CVE-2026-54652 HIGH
Frigate viewer can read logs exposing admin and camera credentials
CVSS 8.1
CVE-2026-14250 MEDIUM
Themehunk Login Registration <= 1.0.2 - Unauthenticated Privilege Escalation via 'role' Parameter
CVSS 6.3
CVE-2026-9842 HIGH
Backstage <= 1.4.2 - Unauthenticated Privilege Escalation via Permissive Demo Role Capabilities
CVSS 7.5
CVE-2026-14482 HIGH
多说社会化评论框 <= 1.2 - Unauthenticated Privilege Escalation via api.php 'option'/'value' Parameters
CVSS 8.8
CVE-2026-58583 HIGH
FluxInk Color Management Driver local privilege escalation
CVSS 7.1
CVE-2026-53645 HIGH
FOSSBilling < 0.8.0 - Staff Permission Privilege Escalation
CVE-2026-14719 HIGH
SourceCodester Onlne Examination & Learning Management System Registration Endpoint register.php privileges management
CVSS 7.3
CVE-2026-46680 HIGH
containerd user ID handling bypass allows runAsNonRoot evasion
CVSS 7.8
CVE-2026-13228 HIGH
LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter
CVSS 8.8
CVE-2026-12224 HIGH
Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint
CVSS 8.8
CVE-2026-57995 HIGH
phpMyFAQ - Privilege Escalation via Missing Self-Rights Constraint in GroupController::updatePermissions
CVSS 8.8
CVE-2026-14124 HIGH
Google Chrome - Privilege Escalation
CVSS 7.8
CVE-2026-14101 CRITICAL
Google Chrome < 150.0.7871.47 - Sandbox Escape via Crafted HTML Page
CVSS 9.6
Details
Vulnerabilities 3,090
Exploit Likelihood Medium