CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

3,091 vulnerabilities with CWE-269
CVE-2026-8787 HIGH
Firebase Support & Chat Management <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
CVSS 8.8
CVE-2026-9490 MEDIUM
Acer Care Center creates a Named Pipe with a weak Security Descriptor
CVSS 5.5
CVE-2026-9489 HIGH
NitroSense V3: Local Privilege Escalation (LPE) vulnerability
CVE-2026-6898 HIGH
WishList Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Generate API Secret Key via 'wlm3_generate_api_key' AJAX action
CVSS 8.8
CVE-2026-6897 HIGH
Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Options Update via 'wishlistmember_team_accounts_save_settings' AJAX action
CVSS 8.8
CVE-2026-6895 HIGH
Wishlist Member < 3.30.1 - Privilege Escalation
CVSS 8.8
CVE-2026-6419 HIGH
Wishlist Member < 3.30.1 - Privilege Escalation
CVSS 8.8
CVE-2026-23663 HIGH
Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability
CVSS 7.5
CVE-2026-40172 HIGH
authentik: Privilege Escalation via User PATCH: Superuser Group Assignment Bypasses enable_group_superuser
CVSS 8.1
CVE-2026-9018 HIGH
Easy Elements for Elementor – Addons & Website Templates <= 1.4.5 - Unauthenticated Privilege Escalation via 'custom_meta' Parameter
CVSS 8.8
CVE-2026-8327 MEDIUM
Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass.
CVSS 4.3
CVE-2026-5118 CRITICAL
Divi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role'
CVSS 9.8
CVE-2026-45254 MEDIUM
FreeBSD 15.0-RELEASE < p9, 14.4-RELEASE < p5, 14.3-RELEASE < p14 - Improper Privilege Management in cap_net Service
CVSS 6.5
CVE-2026-7467 HIGH
Read More & Accordion <= 3.5.7 - Privilege Escalation via importData
CVSS 8.8
CVE-2026-7284 CRITICAL
Easy Elements for Elementor <= 1.4.4 - Unauthenticated Privilege Escalation via easyel_handle_register
CVSS 9.8
CVE-2026-31070 CRITICAL
LalanaChami Pharmacy Management System - Unauthenticated Privilege Escalation via Role Parameter Manipulation
CVSS 9.8
CVE-2026-8972 HIGH
Privilege escalation in the WebRTC: Audio/Video component
CVSS 8.8
CVE-2026-8970 HIGH
Firefox < 140.11 and 140.11-150.0 - Privilege Escalation
CVSS 8.8
CVE-2026-8957 HIGH
Firefox < 140.11 and 140.11-140.* and >=151 - Privilege Escalation in Enterprise Policies
CVSS 8.8
CVE-2026-8955 HIGH
Privilege escalation in the DOM: Workers component
CVSS 8.8
CVE-2026-8952 HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Privilege Escalation in Application Update Component
CVSS 8.8
CVE-2026-32323 HIGH
Mullvad VPN for macOS: Local Privilege Escalation via unverified bundle path in installer
CVSS 7.3
CVE-2026-41085 HIGH
Thermo Fisher Scientific Torrent Suite Dx <=5.14.2 - Privilege Escalation
CVSS 8.8
CVE-2026-8719 HIGH
AI Engine for WordPress 3.4.9 - MCP OAuth Privilege Escalation
CVSS 8.8
CVE-2026-45395 HIGH
Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution
CVSS 7.2
Details
Vulnerabilities 3,091
Exploit Likelihood Medium