CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

3,089 vulnerabilities with CWE-269
CVE-2026-65595 HIGH
n8n before 2.30.1 Privilege Escalation via Token Exchange
CVSS 8.8
CVE-2026-57599 MEDIUM
Hikvision DS-2CD Series - Privilege Escalation
CVSS 6.6
CVE-2026-14551 HIGH
Local Privilege Escalation in servereye client (sensorhub)
CVSS 8.8
CVE-2026-62565 HIGH
Oracle Hrms (us) < 12.2.15 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 7.1
CVE-2026-62561 HIGH
Oracle HRMS (US) 12.2.3-12.2.15 - Authenticated Remote Takeover via Internal Operations Component
CVSS 7.8
CVE-2026-62548 HIGH
Oracle Hrms (us) < 12.2.15 - Improper Privilege Management
CVSS 7.2
CVE-2026-62534 HIGH
Oracle Applications Framework 12.2.11-12.2.15 - Authenticated Remote Code Execution via Web Utilities
CVSS 8.8
CVE-2026-62525 MEDIUM
Oracle Quality < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62524 MEDIUM
Oracle Hrms (us) < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62515 HIGH
Oracle Advanced Planning Command Center 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 7.6
CVE-2026-62498 HIGH
Oracle Flow Manufacturing 12.2.7-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62496 HIGH
Oracle Yard Management 12.2.6-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62493 HIGH
Oracle Purchasing 12.2.11-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-62478 HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62476 HIGH
Oracle Public Sector Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62474 MEDIUM
Oracle Lease And Finance Management < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62473 HIGH
Oracle Installed Base < 12.2.15 - Denial of Service
CVSS 8.3
CVE-2026-62464 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-62456 HIGH
Oracle HRMS (UK) 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTPS
CVSS 8.2
CVE-2026-62453 MEDIUM
Oracle Hrms (uk) < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62447 HIGH
Oracle Trade Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Claim LOV Component
CVSS 8.8
CVE-2026-61336 HIGH
Oracle Lease And Finance Management < 12.2.15 - Improper Privilege Management
CVSS 7.2
CVE-2026-61322 HIGH
Oracle TeleSales 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-61320 HIGH
Oracle Payables 12.2.8-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-61311 HIGH
Oracle Product Hub 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
Details
Vulnerabilities 3,089
Exploit Likelihood Medium