CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

3,091 vulnerabilities with CWE-269
CVE-2026-46895 CRITICAL
Oracle Enterprise Command Center Framework V15 and V16 - Remote Code Execution via HTTP
CVSS 9.9
CVE-2026-46893 CRITICAL
JD Edwards EnterpriseOne General Ledger 9.2 - Remote Code Execution via SMB
CVSS 9.9
CVE-2026-46885 HIGH
Oracle Siebel CRM Integration 17.0-26.5 - Authenticated Remote Code Execution in EAI Component
CVSS 8.8
CVE-2026-46877 MEDIUM
Oracle VM VirtualBox 7.2.8 - Authenticated Unauthorized Data Access via VMSVGA Device
CVSS 6.0
CVE-2026-46873 HIGH
Oracle VM VirtualBox 7.2.8 - Authenticated Remote Code Execution in VMSVGA Device
CVSS 7.5
CVE-2026-46867 HIGH
Oracle Enterprise Manager Base Platform 13.5 and 24.1 - Remote Code Execution via Extensibility Framework
CVSS 7.2
CVE-2026-46852 CRITICAL
Oracle Enterprise Manager Base Platform 13.5 and 24.1 - Remote Code Execution via Metadata Plugin
CVSS 9.9
CVE-2026-46804 HIGH
Oracle WebCenter Content 14.1.2.0.0 - Unauthorized Data Access and Modification via HTTP
CVSS 8.7
CVE-2026-46794 CRITICAL
Oracle Identity Manager Connector 12.2.1.4.0 and 14.1.2.1.0 - Authenticated Remote Code Execution via SSH
CVSS 9.9
CVE-2026-35291 MEDIUM
Oracle WebLogic Server 14.1.2.0.0 and 15.1.1.0.0 - Authenticated Remote Code Execution in Console
CVSS 6.6
CVE-2026-35288 HIGH
PeopleSoft Enterprise PT PeopleTools 8.61-8.62 - Authenticated Remote Code Execution in Deployment Package
CVSS 8.2
CVE-2026-35272 HIGH
PeopleSoft Enterprise PT PeopleTools 8.61-8.62 - Unauthenticated Remote Code Execution in Deployment Package
CVSS 8.4
CVE-2026-12313 MEDIUM
Information disclosure, sandbox escape in the Security: Process Sandboxing component
CVSS 4.7
CVE-2026-12289 HIGH
Privilege escalation in the Graphics: WebRender component
CVSS 8.8
CVE-2026-8176 HIGH
LatePoint < 5.5.1 - Privilege Escalation
CVSS 7.5
CVE-2026-39118 HIGH
Kandji Agent < 4.7.5(5374) - Local Privilege Escalation via Client Validation Gap
CVSS 8.4
CVE-2026-36213 HIGH
Microvirt MEmu Android Emulator 9.2.7.0 - Privilege Escalation via MemuService.exe
CVSS 7.8
CVE-2026-12217 HIGH
DVDFab Virtual Drive Signed Kernel Driver dvdfabio.sys privileges management
CVSS 7.8
CVE-2026-46716 CRITICAL
Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron
CVSS 9.9
CVE-2026-12018 HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-45176 HIGH
Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communication or File Operation Manipulation
CVSS 7.8
CVE-2026-50570 HIGH
Fission < 1.25.0 PodSpec Validation - CAP_SYS_TIME Privilege Escalation
CVSS 8.5
CVE-2026-50566 CRITICAL
Fission < 1.24.0 Environment Validation - Privileged Pod Creation
CVSS 9.9
CVE-2026-50565 MEDIUM
Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
CVSS 4.9
CVE-2026-50564 CRITICAL
Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape
CVSS 9.9
Details
Vulnerabilities 3,091
Exploit Likelihood Medium