CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

2,642 vulnerabilities with CWE-269
CVE-2026-26369 CRITICAL
eNet SMART HOME 2.2.1/2.3.1 - Privilege Escalation
CVSS 9.8
CVE-2026-1750 HIGH
Ecwid by Lightspeed Ecommerce Shopping Cart <7.0.7 - Privilege Esca...
CVSS 8.8
CVE-2026-2144 HIGH
Magic Login Mail or QR Code <2.05 - Privilege Escalation
CVSS 8.1
CVE-2026-24894 HIGH
FrankenPHP <1.11.2 - Info Disclosure
CVSS 7.5
CVE-2026-26010 HIGH
Open-metadata Openmetadata < 1.11.8 - Improper Privilege Management
CVSS 7.6
CVE-2026-21533 HIGH KEV
Microsoft Windows 10 1607 - Improper Privilege Management
CVSS 7.8
CVE-2026-25643 CRITICAL
Frigate <0.16.4 - RCE
CVSS 9.1
CVE-2026-23896 HIGH
immich <2.5.0 - Privilege Escalation
CVSS 7.2
CVE-2026-22039 CRITICAL
Kyverno < 1.15.3 - SSRF
CVSS 9.9
CVE-2026-0920 CRITICAL
LA-Studio Element Kit - Privilege Escalation
CVSS 9.8
CVE-2026-23990 MEDIUM
Flux Operator <0.40.0 - Privilege Escalation
CVSS 5.3
CVE-2026-21983 HIGH
Oracle VM Virtualbox - Improper Privilege Management
CVSS 7.5
CVE-2026-21981 MEDIUM
Oracle VM Virtualbox - Improper Privilege Management
CVSS 4.6
CVE-2026-21963 MEDIUM
Oracle VM Virtualbox - Improper Privilege Management
CVSS 6.0
CVE-2026-21957 HIGH
Oracle VM Virtualbox - Improper Privilege Management
CVSS 7.5
CVE-2026-21223 HIGH
Microsoft Edge - Privilege Escalation
CVSS 7.1
CVE-2026-1010 HIGH
Altium On-prem Enterprise Server - XSS
CVSS 8.0
CVE-2026-23477 HIGH
Rocket.Chat <6.12.0 - Info Disclosure
CVSS 7.7
CVE-2026-22708 CRITICAL
Anysphere Cursor < 2.3 - Command Injection
CVSS 9.8
CVE-2026-22238 CRITICAL
Blusparkglobal Bluvoyix - Missing Authentication
CVSS 9.8
CVE-2026-22804 HIGH
Termix < 1.10.0 - XSS
CVSS 8.0
CVE-2026-22043 CRITICAL
Rustfs < 1.0.0-alpha.79 - Improper Access Control
CVSS 9.8
CVE-2026-22536 HIGH
Sudo <unknown> - Privilege Escalation
CVE-2025-69689 HIGH
Untitled
CVSS 8.8
CVE-2025-70795 MEDIUM
STProcessMonitor 11.11.4.0 - DoS
CVSS 5.5
Details
Vulnerabilities 2,642
Exploit Likelihood Medium