CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

3,090 vulnerabilities with CWE-269
CVE-2026-58053 CRITICAL
Gitea act_runner - Container Hardening Bypass via Workflow Container Options
CVSS 9.9
CVE-2026-12415 CRITICAL
Invoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' Parameter
CVSS 9.8
CVE-2026-45256 MEDIUM
FreeBSD - Missing Permission Check in thr_kill2(2)
CVSS 5.5
CVE-2026-52808 HIGH
Gogs: Write-level collaborators can mutate admin-only repository settings via API
CVSS 7.1
CVE-2026-56245 HIGH
Supabase Capgo - Unauthenticated Cross-Tenant Build-Time Accounting Poisoning via record_build_time RPC
CVSS 8.2
CVE-2026-54319 MEDIUM
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
CVSS 4.2
CVE-2026-56225 HIGH
Capgo - Authorization Bypass in API Key Management via App-Limited Keys
CVSS 8.3
CVE-2026-54099 HIGH
Red Hat OpenShift WMCO WICD CSR - Cluster-Admin Privilege Escalation
CVSS 8.8
CVE-2026-8157 HIGH
Vitepos < 3.4.2 - Outlet Manager+ Privilege Escalation
CVSS 8.8
CVE-2026-56239 HIGH
Capgo - Privilege Escalation via SECURITY DEFINER Function apply_usage_overage
CVSS 7.6
CVE-2026-56216 HIGH
Capgo - Scope Escalation via API Key Creation in /functions/v1/apikey
CVSS 8.8
CVE-2026-56212 LOW
Capgo - Improper 2FA Enforcement Logic via Team Security Settings
CVSS 3.8
CVE-2026-50201 MEDIUM
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
CVSS 6.5
CVE-2026-20246 MEDIUM
Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability
CVSS 6.0
CVE-2026-54415 HIGH
Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover
CVSS 8.1
CVE-2026-12450 MEDIUM
Google Chrome < 149.0.7827.155 - Information Disclosure via Media Component
CVSS 6.5
CVE-2026-12448 HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-12165 HIGH
Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter
CVSS 8.8
CVE-2026-0063 HIGH
Android - Local Privilege Escalation via PhoneInterfaceManager Logic Error
CVSS 7.8
CVE-2026-0019 HIGH
Android 17 - Local Privilege Escalation via SettingsLib Logic Error
CVSS 7.8
CVE-2026-46973 HIGH
Oracle Outsourced Mfg for Discrete Industries 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46972 HIGH
Oracle Outsourced Mfg for Discrete Industries 12.2.3-12.2.15 - Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-46971 HIGH
Oracle HR Intelligence 12.2.3-12.2.15 - Authenticated Remote Code Execution
CVSS 7.5
CVE-2026-46970 HIGH
Oracle HR Intelligence 12.2.3-12.2.15 - Authenticated Remote Code Execution
CVSS 7.2
CVE-2026-46966 HIGH
Oracle Universal Work Queue 12.2.3-12.2.15 - Remote Code Execution via Work Provider
CVSS 7.5
Details
Vulnerabilities 3,090
Exploit Likelihood Medium