The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
3,091 vulnerabilities with CWE-269
CVE-2026-8787
HIGH
Firebase Support & Chat Management <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
CVSS 8.8
CVE-2026-9490
MEDIUM
Acer Care Center creates a Named Pipe with a weak Security Descriptor
CVSS 5.5
CVE-2026-9489
HIGH
NitroSense V3: Local Privilege Escalation (LPE) vulnerability
CVE-2026-6898
HIGH
WishList Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Generate API Secret Key via 'wlm3_generate_api_key' AJAX action
CVSS 8.8
CVE-2026-6897
HIGH
Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Options Update via 'wishlistmember_team_accounts_save_settings' AJAX action
CVSS 8.8
CVE-2026-6895
HIGH
Wishlist Member < 3.30.1 - Privilege Escalation
CVSS 8.8
CVE-2026-6419
HIGH
Wishlist Member < 3.30.1 - Privilege Escalation
CVSS 8.8
CVE-2026-23663
HIGH
Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability
CVSS 7.5
CVE-2026-40172
HIGH
authentik: Privilege Escalation via User PATCH: Superuser Group Assignment Bypasses enable_group_superuser
CVSS 8.1
CVE-2026-9018
HIGH
Easy Elements for Elementor – Addons & Website Templates <= 1.4.5 - Unauthenticated Privilege Escalation via 'custom_meta' Parameter
CVSS 8.8
CVE-2026-8327
MEDIUM
Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass.
CVSS 4.3
CVE-2026-5118
CRITICAL
Divi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role'
CVSS 9.8
CVE-2026-45254
MEDIUM
FreeBSD 15.0-RELEASE < p9, 14.4-RELEASE < p5, 14.3-RELEASE < p14 - Improper Privilege Management in cap_net Service
CVSS 6.5
CVE-2026-7467
HIGH
Read More & Accordion <= 3.5.7 - Privilege Escalation via importData
CVSS 8.8
CVE-2026-7284
CRITICAL
Easy Elements for Elementor <= 1.4.4 - Unauthenticated Privilege Escalation via easyel_handle_register
CVSS 9.8
CVE-2026-31070
CRITICAL
LalanaChami Pharmacy Management System - Unauthenticated Privilege Escalation via Role Parameter Manipulation
CVSS 9.8
CVE-2026-8972
HIGH
Privilege escalation in the WebRTC: Audio/Video component
CVSS 8.8
CVE-2026-8970
HIGH
Firefox < 140.11 and 140.11-150.0 - Privilege Escalation
CVSS 8.8
CVE-2026-8957
HIGH
Firefox < 140.11 and 140.11-140.* and >=151 - Privilege Escalation in Enterprise Policies
CVSS 8.8
CVE-2026-8955
HIGH
Privilege escalation in the DOM: Workers component
CVSS 8.8
CVE-2026-8952
HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Privilege Escalation in Application Update Component
CVSS 8.8
CVE-2026-32323
HIGH
Mullvad VPN for macOS: Local Privilege Escalation via unverified bundle path in installer
CVSS 7.3
CVE-2026-41085
HIGH
Thermo Fisher Scientific Torrent Suite Dx <=5.14.2 - Privilege Escalation
CVSS 8.8
CVE-2026-8719
HIGH
AI Engine for WordPress 3.4.9 - MCP OAuth Privilege Escalation
CVSS 8.8
CVE-2026-45395
HIGH
Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution
CVSS 7.2
Details
Vulnerabilities
3,091
Exploit Likelihood
Medium