CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

3,089 vulnerabilities with CWE-269
CVE-2026-10610 HIGH
Local privilege escalation in ESET security applications for macOS
CVE-2026-7483 HIGH
Local privilege escalation in ESET security applications for macOS
CVE-2026-12981 HIGH
CAFEHAUS API <= 1.0.0 - Unauthenticated Arbitrary User Password Reset
CVSS 7.5
CVE-2026-12497 HIGH
ProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role Selection
CVSS 7.5
CVE-2026-12736 HIGH
WPify Woo <= 5.4.16 - Authenticated (Shop Manager+) Privilege Escalation via Arbitrary Option Update via save_option REST Endpoint
CVSS 8.0
CVE-2026-16764 MEDIUM
OWASP DefectDojo API/Web serializers.py UserSerializer privileges management
CVSS 6.3
CVE-2026-38764 HIGH
Protegent 360 2.0.0.4 - Local Privilege Escalation via pgsecdl.sys Kernel Driver
CVSS 7.8
CVE-2026-34496 HIGH
victor Web - Priviledge Escalation
CVE-2026-15630 CRITICAL
Casdoor < v3.115.0 - Authenticated Cross-Tenant Resource Manipulation via ID Parameter Mismatch
CVSS 9.9
CVE-2026-65897 HIGH
Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups
CVSS 8.8
CVE-2026-15017 HIGH
MDJM Event Management <= 1.7.8.4 - Authenticated (Subscriber+) Privilege Escalation via 'set-permissions' and 'change_role' Handlers
CVSS 8.8
CVE-2026-61246 HIGH
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60455 HIGH
Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0 Auth RCE via Thirdparty Jars
CVSS 8.8
CVE-2026-60439 HIGH
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60373 HIGH
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60372 CRITICAL
Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0 - Unauth RCE via Thirdparty Jars
CVSS 9.8
CVE-2026-60371 HIGH
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via Physical Network Access
CVSS 8.0
CVE-2026-60369 CRITICAL
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Remote Code Execution via Centralized Thirdparty Jars
CVSS 9.9
CVE-2026-60367 CRITICAL
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60366 CRITICAL
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 10.0
CVE-2026-38766 HIGH
Protegent 360 2.0.0.4 - Local Privilege Escalation via sub_186f4 Function
CVSS 7.8
CVE-2026-38765 HIGH
Protegent 360 2.0.0.4 - Local Privilege Escalation via pgsecdl.sys Kernel Driver
CVSS 7.8
CVE-2026-16607 HIGH
Authenticated local root privilege escalation vulnerability in openFT for Linux and Oracle Solaris
CVSS 7.8
CVE-2026-62145 HIGH
checkpoint Quantum Security Gateway - Local Privilege Escalation in Gaia Portal
CVSS 7.5
CVE-2026-65603 HIGH
Grav Login Plugin 3.8.11 Privilege Escalation via Profile Update
CVSS 8.8
Details
Vulnerabilities 3,089
Exploit Likelihood Medium