CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

3,092 vulnerabilities with CWE-269
CVE-2026-26725 CRITICAL
Print Shop Pro WebDesk 18.34 - Privilege Escalation
CVSS 9.8
CVE-2026-26722 CRITICAL
Key Systems GFMS 20230721a - Privilege Escalation
CVSS 9.4
CVE-2026-1994 CRITICAL
s2Member WordPress Plugin <260127 - Privilege Escalation
CVSS 9.8
CVE-2026-0912 HIGH
Toret Manager Plugin 1.2.7 - Privilege Escalation
CVSS 8.8
CVE-2026-23599 HIGH
HPE Aruba ClearPass OnGuard Linux - Privilege Escalation
CVSS 7.8
CVE-2026-2563 MEDIUM
JingDong JD Cloud Box AX6600 <4.5.1.r4533 - Remote Privilege Escala...
CVSS 6.3
CVE-2026-2562 MEDIUM
JingDong JD Cloud Box AX6600 <4.5.1.r4533 - Remote Privilege Escala...
CVSS 6.3
CVE-2026-2561 MEDIUM
JingDong JD Cloud Box AX6600 <4.5.1.r4533 - Remote Privilege Escala...
CVSS 6.3
CVE-2026-26369 CRITICAL
eNet SMART HOME 2.2.1/2.3.1 - Privilege Escalation
CVSS 9.8
CVE-2026-1750 HIGH
Ecwid by Lightspeed Ecommerce Shopping Cart <7.0.7 - Privilege Esca...
CVSS 8.8
CVE-2026-2144 HIGH
Magic Login Mail or QR Code <2.05 - Privilege Escalation
CVSS 8.1
CVE-2026-24894 HIGH
FrankenPHP <1.11.2 - Info Disclosure
CVSS 7.5
CVE-2026-26010 HIGH
OpenMetadata < 1.11.8 - Unauthenticated JWT Leak via Ingestion Pipeline API
CVSS 7.6
CVE-2026-21533 HIGH KEV
Windows 10/11 Remote Desktop Authenticated Privilege Escalation
CVSS 7.8
CVE-2026-25643 CRITICAL
Frigate < 0.16.4 - Remote Command Execution via go2rtc exec Directive
CVSS 9.1
CVE-2026-23896 HIGH
immich <2.5.0 - Privilege Escalation
CVSS 7.2
CVE-2026-22039 CRITICAL
Kyverno < 1.15.3 - Authenticated Server-Side Request Forgery via Namespaced Policy apiCall
CVSS 9.9
CVE-2026-0920 CRITICAL
LA-Studio Element Kit - Privilege Escalation
CVSS 9.8
CVE-2026-23990 MEDIUM
Flux Operator <0.40.0 - Privilege Escalation
CVSS 5.3
CVE-2026-21983 HIGH
Oracle VM VirtualBox 7.1.14 and 7.2.4 - Privilege Escalation
CVSS 7.5
CVE-2026-21981 MEDIUM
Oracle VM VirtualBox 7.1.14 and 7.2.4 - Authenticated Unauthorized Data Access and Partial Denial of Service
CVSS 4.6
CVE-2026-21963 MEDIUM
Oracle VM VirtualBox 7.1.14 and 7.2.4 - Authenticated Unauthorized Data Access
CVSS 6.0
CVE-2026-21957 HIGH
Oracle VM VirtualBox 7.1.14 and 7.2.4 - Privilege Escalation in Core Component
CVSS 7.5
CVE-2026-21223 HIGH
Microsoft Edge - Privilege Escalation
CVSS 7.1
CVE-2026-1010 HIGH
Altium On-Prem Enterprise Server - Authenticated Stored Cross-Site Scripting via Workflow Form Submission
CVSS 8.0
Details
Vulnerabilities 3,092
Exploit Likelihood Medium