CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

3,091 vulnerabilities with CWE-269
CVE-2026-50563 CRITICAL
Fission Container Executor Function PodSpec Injection Leading to Node Escape
CVSS 9.9
CVE-2026-50545 CRITICAL
Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover
CVSS 9.9
CVE-2026-46618 MEDIUM
Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables
CVE-2026-46617 HIGH
Fission < 1.23.0 Runtime Pods - Service Account Token Exposure
CVE-2026-11616 HIGH
Events Calendar for GeoDirectory <= 2.3.28 - Authenticated (Subscriber+) Privilege Escalation
CVSS 8.8
CVE-2026-44119 MEDIUM
Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules
CVSS 5.5
CVE-2026-11423 CRITICAL
Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege Escalation
CVE-2026-11308 MEDIUM
Google Chrome - Privilege Escalation
CVSS 6.3
CVE-2026-11296 HIGH
Google Chrome - Privilege Escalation
CVSS 7.5
CVE-2026-11295 HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-11276 MEDIUM
Google Chrome < 149.0.7827.53 - Discretionary Access Control Bypass via Cast Network Traffic
CVSS 5.1
CVE-2026-11229 MEDIUM
Google Chrome - Privilege Escalation
CVSS 6.1
CVE-2026-11108 HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-11103 HIGH
Google Chrome - Privilege Escalation
CVSS 7.8
CVE-2026-10868 CRITICAL
MISP user edit endpoint mass assignment vulnerability allows unauthorized user account modification
CVE-2026-49189 HIGH
Acer Connect M6E 5G Portable WiFi Router - Broadcast Receiver Privilege Escalation
CVSS 7.8
CVE-2026-8206 CRITICAL
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
CVSS 9.8
CVE-2026-28586 LOW
Android 15-16 AppOpsService - Local Information Disclosure
CVSS 3.3
CVE-2026-0091 HIGH
Google Android - Improper Privilege Management
CVSS 7.8
CVE-2026-0089 HIGH
Google Android - Improper Privilege Management
CVSS 7.8
CVE-2026-0086 MEDIUM
Android 16-qpr2 DisableSupervisionActivity - Local Privilege Escalation
CVSS 6.8
CVE-2026-0055 MEDIUM
Android PackageInstallerService - Path Traversal and Local Privilege Escalation via createSessionInternal
CVSS 6.2
CVE-2026-0050 LOW
Android 15-16 AdapterService - Bluetooth Information Disclosure
CVSS 3.3
CVE-2026-0048 MEDIUM
Android 14-16 WindowState - Permission Approval Tapjacking
CVSS 6.8
CVE-2026-0046 MEDIUM
Android 14-16 Letterbox InputInterceptor - Tapjacking Privilege Escalation
CVSS 6.2
Details
Vulnerabilities 3,091
Exploit Likelihood Medium