The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
3,092 vulnerabilities with CWE-269
CVE-2026-26725
CRITICAL
Print Shop Pro WebDesk 18.34 - Privilege Escalation
CVSS 9.8
CVE-2026-26722
CRITICAL
Key Systems GFMS 20230721a - Privilege Escalation
CVSS 9.4
CVE-2026-1994
CRITICAL
s2Member WordPress Plugin <260127 - Privilege Escalation
CVSS 9.8
CVE-2026-0912
HIGH
Toret Manager Plugin 1.2.7 - Privilege Escalation
CVSS 8.8
CVE-2026-23599
HIGH
HPE Aruba ClearPass OnGuard Linux - Privilege Escalation
CVSS 7.8
CVE-2026-2563
MEDIUM
JingDong JD Cloud Box AX6600 <4.5.1.r4533 - Remote Privilege Escala...
CVSS 6.3
CVE-2026-2562
MEDIUM
JingDong JD Cloud Box AX6600 <4.5.1.r4533 - Remote Privilege Escala...
CVSS 6.3
CVE-2026-2561
MEDIUM
JingDong JD Cloud Box AX6600 <4.5.1.r4533 - Remote Privilege Escala...
CVSS 6.3
CVE-2026-26369
CRITICAL
eNet SMART HOME 2.2.1/2.3.1 - Privilege Escalation
CVSS 9.8
CVE-2026-1750
HIGH
Ecwid by Lightspeed Ecommerce Shopping Cart <7.0.7 - Privilege Esca...
CVSS 8.8
CVE-2026-2144
HIGH
Magic Login Mail or QR Code <2.05 - Privilege Escalation
CVSS 8.1
CVE-2026-24894
HIGH
FrankenPHP <1.11.2 - Info Disclosure
CVSS 7.5
CVE-2026-26010
HIGH
OpenMetadata < 1.11.8 - Unauthenticated JWT Leak via Ingestion Pipeline API
CVSS 7.6
CVE-2026-21533
HIGH
KEV
Windows 10/11 Remote Desktop Authenticated Privilege Escalation
CVSS 7.8
CVE-2026-25643
CRITICAL
Frigate < 0.16.4 - Remote Command Execution via go2rtc exec Directive
CVSS 9.1
CVE-2026-23896
HIGH
immich <2.5.0 - Privilege Escalation
CVSS 7.2
CVE-2026-22039
CRITICAL
Kyverno < 1.15.3 - Authenticated Server-Side Request Forgery via Namespaced Policy apiCall
CVSS 9.9
CVE-2026-0920
CRITICAL
LA-Studio Element Kit - Privilege Escalation
CVSS 9.8
CVE-2026-23990
MEDIUM
Flux Operator <0.40.0 - Privilege Escalation
CVSS 5.3
CVE-2026-21983
HIGH
Oracle VM VirtualBox 7.1.14 and 7.2.4 - Privilege Escalation
CVSS 7.5
CVE-2026-21981
MEDIUM
Oracle VM VirtualBox 7.1.14 and 7.2.4 - Authenticated Unauthorized Data Access and Partial Denial of Service
CVSS 4.6
CVE-2026-21963
MEDIUM
Oracle VM VirtualBox 7.1.14 and 7.2.4 - Authenticated Unauthorized Data Access
CVSS 6.0
CVE-2026-21957
HIGH
Oracle VM VirtualBox 7.1.14 and 7.2.4 - Privilege Escalation in Core Component
CVSS 7.5
CVE-2026-21223
HIGH
Microsoft Edge - Privilege Escalation
CVSS 7.1
CVE-2026-1010
HIGH
Altium On-Prem Enterprise Server - Authenticated Stored Cross-Site Scripting via Workflow Form Submission
CVSS 8.0
Details
Vulnerabilities
3,092
Exploit Likelihood
Medium