The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
3,090 vulnerabilities with CWE-269
CVE-2026-58053
CRITICAL
Gitea act_runner - Container Hardening Bypass via Workflow Container Options
CVSS 9.9
CVE-2026-12415
CRITICAL
Invoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' Parameter
CVSS 9.8
CVE-2026-45256
MEDIUM
FreeBSD - Missing Permission Check in thr_kill2(2)
CVSS 5.5
CVE-2026-52808
HIGH
Gogs: Write-level collaborators can mutate admin-only repository settings via API
CVSS 7.1
CVE-2026-56245
HIGH
Supabase Capgo - Unauthenticated Cross-Tenant Build-Time Accounting Poisoning via record_build_time RPC
CVSS 8.2
CVE-2026-54319
MEDIUM
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
CVSS 4.2
CVE-2026-56225
HIGH
Capgo - Authorization Bypass in API Key Management via App-Limited Keys
CVSS 8.3
CVE-2026-54099
HIGH
Red Hat OpenShift WMCO WICD CSR - Cluster-Admin Privilege Escalation
CVSS 8.8
CVE-2026-8157
HIGH
Vitepos < 3.4.2 - Outlet Manager+ Privilege Escalation
CVSS 8.8
CVE-2026-56239
HIGH
Capgo - Privilege Escalation via SECURITY DEFINER Function apply_usage_overage
CVSS 7.6
CVE-2026-56216
HIGH
Capgo - Scope Escalation via API Key Creation in /functions/v1/apikey
CVSS 8.8
CVE-2026-56212
LOW
Capgo - Improper 2FA Enforcement Logic via Team Security Settings
CVSS 3.8
CVE-2026-50201
MEDIUM
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
CVSS 6.5
CVE-2026-20246
MEDIUM
Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability
CVSS 6.0
CVE-2026-54415
HIGH
Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover
CVSS 8.1
CVE-2026-12450
MEDIUM
Google Chrome < 149.0.7827.155 - Information Disclosure via Media Component
CVSS 6.5
CVE-2026-12448
HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-12165
HIGH
Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter
CVSS 8.8
CVE-2026-0063
HIGH
Android - Local Privilege Escalation via PhoneInterfaceManager Logic Error
CVSS 7.8
CVE-2026-0019
HIGH
Android 17 - Local Privilege Escalation via SettingsLib Logic Error
CVSS 7.8
CVE-2026-46973
HIGH
Oracle Outsourced Mfg for Discrete Industries 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46972
HIGH
Oracle Outsourced Mfg for Discrete Industries 12.2.3-12.2.15 - Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46971
HIGH
Oracle HR Intelligence 12.2.3-12.2.15 - Authenticated Remote Code Execution
CVSS 7.5
CVE-2026-46970
HIGH
Oracle HR Intelligence 12.2.3-12.2.15 - Authenticated Remote Code Execution
CVSS 7.2
CVE-2026-46966
HIGH
Oracle Universal Work Queue 12.2.3-12.2.15 - Remote Code Execution via Work Provider
CVSS 7.5
Details
Vulnerabilities
3,090
Exploit Likelihood
Medium