The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
3,091 vulnerabilities with CWE-269
CVE-2026-45675
HIGH
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
CVSS 8.1
CVE-2026-46333
HIGH
ptrace: slightly saner 'get_dumpable()' logic
CVSS 7.1
CVE-2026-6228
HIGH
Frontend Admin by DynamiApps <= 3.28.36 - Unauthenticated Privilege Escalation via Edit User Form
CVSS 8.8
CVE-2026-5193
MEDIUM
Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.13 - Authenticated (Author+) Limited Privilege Escalation via register_user
CVSS 6.5
CVE-2026-44470
HIGH
Claude Desktop: Local Privilege Escalation via Directory Junction in CoworkVMService
CVSS 7.8
CVE-2026-42289
HIGH
ChurchCRM: Cross-Site Request Forgery (CSRF) Leading to Admin Privilege Escalation
CVSS 8.8
CVE-2026-42844
HIGH
Grav: Low-privileged API users can create super-admin accounts via blueprint-upload
CVSS 8.8
CVE-2026-44224
HIGH
Wiki.js: Privilege Escalation via Missing Group Validation in users.update
CVSS 8.8
CVE-2026-44218
LOW
ciguard: Container image runs as root (no USER directive)
CVSS 3.0
CVE-2026-33821
HIGH
Microsoft Dynamics 365 Customer Insights Elevation of Privilege Vulnerability
CVSS 7.7
CVE-2026-43886
HIGH
Outline: OAuth Scope Validation Logic Error Allows Privilege Escalation to Wildcard API Access
CVSS 8.2
CVE-2026-41489
HIGH
Pi-hole: Local privilege escalation via config-controlled path in root-executed service hooks
CVSS 8.8
CVE-2026-28995
HIGH
iOS and iPadOS < 18.7.9 - Sandbox Escape via Logic Issue
CVSS 8.8
CVE-2026-28976
HIGH
macOS < 26.5 - Unauthorized Root Privilege Escalation
CVSS 7.5
CVE-2026-28919
HIGH
macOS - Privilege Escalation
CVSS 7.8
CVE-2026-28840
HIGH
macOS - Privilege Escalation
CVSS 7.8
CVE-2026-42609
HIGH
Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic
CVSS 8.1
CVE-2026-26946
MEDIUM
Dell ECS 3.8.1.0-3.8.1.7 and ObjectScale < 4.3.0.0 - Privilege Escalation
CVSS 6.7
CVE-2026-42562
HIGH
Plainpad: Privilege Escalation via Writable Admin Field in Profile Update (Access Control)
CVSS 8.3
CVE-2026-41163
HIGH
bubblewrap vulnerable to privilege escalation in setuid mode via ptrace
CVSS 7.0
CVE-2026-44987
LOW
SysReptor: Privilege Escalation from User Admin to Superuser
CVSS 3.8
CVE-2026-42185
MEDIUM
People: Privilege Escalation via Missing Role Ceiling in Mail Domain Invitation
CVSS 5.5
CVE-2026-8069
HIGH
PredatorSense V3: Local Privilege Escalation (LPE) vulnerability
CVE-2026-7994
HIGH
Google Chrome < 148.0.7778.96 - Local Privilege Escalation via Malicious File
CVSS 7.8
CVE-2026-7977
MEDIUM
Google Chrome < 148.0.7778.96 - Same Origin Policy Bypass via Canvas
CVSS 6.3
Details
Vulnerabilities
3,091
Exploit Likelihood
Medium