The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
3,091 vulnerabilities with CWE-269
CVE-2026-46895
CRITICAL
Oracle Enterprise Command Center Framework V15 and V16 - Remote Code Execution via HTTP
CVSS 9.9
CVE-2026-46893
CRITICAL
JD Edwards EnterpriseOne General Ledger 9.2 - Remote Code Execution via SMB
CVSS 9.9
CVE-2026-46885
HIGH
Oracle Siebel CRM Integration 17.0-26.5 - Authenticated Remote Code Execution in EAI Component
CVSS 8.8
CVE-2026-46877
MEDIUM
Oracle VM VirtualBox 7.2.8 - Authenticated Unauthorized Data Access via VMSVGA Device
CVSS 6.0
CVE-2026-46873
HIGH
Oracle VM VirtualBox 7.2.8 - Authenticated Remote Code Execution in VMSVGA Device
CVSS 7.5
CVE-2026-46867
HIGH
Oracle Enterprise Manager Base Platform 13.5 and 24.1 - Remote Code Execution via Extensibility Framework
CVSS 7.2
CVE-2026-46852
CRITICAL
Oracle Enterprise Manager Base Platform 13.5 and 24.1 - Remote Code Execution via Metadata Plugin
CVSS 9.9
CVE-2026-46804
HIGH
Oracle WebCenter Content 14.1.2.0.0 - Unauthorized Data Access and Modification via HTTP
CVSS 8.7
CVE-2026-46794
CRITICAL
Oracle Identity Manager Connector 12.2.1.4.0 and 14.1.2.1.0 - Authenticated Remote Code Execution via SSH
CVSS 9.9
CVE-2026-35291
MEDIUM
Oracle WebLogic Server 14.1.2.0.0 and 15.1.1.0.0 - Authenticated Remote Code Execution in Console
CVSS 6.6
CVE-2026-35288
HIGH
PeopleSoft Enterprise PT PeopleTools 8.61-8.62 - Authenticated Remote Code Execution in Deployment Package
CVSS 8.2
CVE-2026-35272
HIGH
PeopleSoft Enterprise PT PeopleTools 8.61-8.62 - Unauthenticated Remote Code Execution in Deployment Package
CVSS 8.4
CVE-2026-12313
MEDIUM
Information disclosure, sandbox escape in the Security: Process Sandboxing component
CVSS 4.7
CVE-2026-12289
HIGH
Privilege escalation in the Graphics: WebRender component
CVSS 8.8
CVE-2026-8176
HIGH
LatePoint < 5.5.1 - Privilege Escalation
CVSS 7.5
CVE-2026-39118
HIGH
Kandji Agent < 4.7.5(5374) - Local Privilege Escalation via Client Validation Gap
CVSS 8.4
CVE-2026-36213
HIGH
Microvirt MEmu Android Emulator 9.2.7.0 - Privilege Escalation via MemuService.exe
CVSS 7.8
CVE-2026-12217
HIGH
DVDFab Virtual Drive Signed Kernel Driver dvdfabio.sys privileges management
CVSS 7.8
CVE-2026-46716
CRITICAL
Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron
CVSS 9.9
CVE-2026-12018
HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-45176
HIGH
Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communication or File Operation Manipulation
CVSS 7.8
CVE-2026-50570
HIGH
Fission < 1.25.0 PodSpec Validation - CAP_SYS_TIME Privilege Escalation
CVSS 8.5
CVE-2026-50566
CRITICAL
Fission < 1.24.0 Environment Validation - Privileged Pod Creation
CVSS 9.9
CVE-2026-50565
MEDIUM
Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
CVSS 4.9
CVE-2026-50564
CRITICAL
Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape
CVSS 9.9
Details
Vulnerabilities
3,091
Exploit Likelihood
Medium