The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
3,091 vulnerabilities with CWE-269
CVE-2026-50563
CRITICAL
Fission Container Executor Function PodSpec Injection Leading to Node Escape
CVSS 9.9
CVE-2026-50545
CRITICAL
Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover
CVSS 9.9
CVE-2026-46618
MEDIUM
Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables
CVE-2026-46617
HIGH
Fission < 1.23.0 Runtime Pods - Service Account Token Exposure
CVE-2026-11616
HIGH
Events Calendar for GeoDirectory <= 2.3.28 - Authenticated (Subscriber+) Privilege Escalation
CVSS 8.8
CVE-2026-44119
MEDIUM
Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules
CVSS 5.5
CVE-2026-11423
CRITICAL
Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege Escalation
CVE-2026-11308
MEDIUM
Google Chrome - Privilege Escalation
CVSS 6.3
CVE-2026-11296
HIGH
Google Chrome - Privilege Escalation
CVSS 7.5
CVE-2026-11295
HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-11276
MEDIUM
Google Chrome < 149.0.7827.53 - Discretionary Access Control Bypass via Cast Network Traffic
CVSS 5.1
CVE-2026-11229
MEDIUM
Google Chrome - Privilege Escalation
CVSS 6.1
CVE-2026-11108
HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-11103
HIGH
Google Chrome - Privilege Escalation
CVSS 7.8
CVE-2026-10868
CRITICAL
MISP user edit endpoint mass assignment vulnerability allows unauthorized user account modification
CVE-2026-49189
HIGH
Acer Connect M6E 5G Portable WiFi Router - Broadcast Receiver Privilege Escalation
CVSS 7.8
CVE-2026-8206
CRITICAL
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
CVSS 9.8
CVE-2026-28586
LOW
Android 15-16 AppOpsService - Local Information Disclosure
CVSS 3.3
CVE-2026-0091
HIGH
Google Android - Improper Privilege Management
CVSS 7.8
CVE-2026-0089
HIGH
Google Android - Improper Privilege Management
CVSS 7.8
CVE-2026-0086
MEDIUM
Android 16-qpr2 DisableSupervisionActivity - Local Privilege Escalation
CVSS 6.8
CVE-2026-0055
MEDIUM
Android PackageInstallerService - Path Traversal and Local Privilege Escalation via createSessionInternal
CVSS 6.2
CVE-2026-0050
LOW
Android 15-16 AdapterService - Bluetooth Information Disclosure
CVSS 3.3
CVE-2026-0048
MEDIUM
Android 14-16 WindowState - Permission Approval Tapjacking
CVSS 6.8
CVE-2026-0046
MEDIUM
Android 14-16 Letterbox InputInterceptor - Tapjacking Privilege Escalation
CVSS 6.2
Details
Vulnerabilities
3,091
Exploit Likelihood
Medium