CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

3,090 vulnerabilities with CWE-269
CVE-2026-60150 HIGH
Oracle VM VirtualBox 7.2.12 - Local Privilege Escalation to Host Takeover
CVSS 7.8
CVE-2026-47054 HIGH
Oracle VM VirtualBox 7.2.12 - Local Privilege Escalation to Host Takeover on Windows
CVSS 7.8
CVE-2026-47047 HIGH
Oracle VM VirtualBox 7.2.12 - Local Privilege Escalation to Host Takeover
CVSS 7.8
CVE-2026-46995 HIGH
Oracle Enterprise Manager Base Platform 13.5 and 24.1 - Authenticated Remote Takeover via Metadata Plugin over HTTPS
CVSS 8.8
CVE-2026-47416 CRITICAL
PraisonAI Platform < 0.1.4 Member Role Endpoint - Privilege Escalation
CVSS 9.6
CVE-2026-47413 CRITICAL
praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members
CVSS 9.6
CVE-2026-47412 HIGH
praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
CVSS 8.1
CVE-2026-47411 MEDIUM
PraisonAI Platform < 0.1.4 Workspace Settings - Authorization Bypass
CVSS 6.5
CVE-2026-47409 HIGH
PraisonAI Platform < 0.1.4 Member Delete Endpoint - Owner Lockout
CVSS 8.1
CVE-2026-47407 CRITICAL
PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation
CVE-2026-16401 HIGH
Mozilla Firefox - Privilege Escalation in the Data Loss Prevention Component
CVSS 8.8
CVE-2026-16396 HIGH
Mozilla Firefox - Privilege Escalation in WebExtensions
CVSS 8.8
CVE-2026-16379 HIGH
Privilege escalation in the DOM: Content Processes component
CVSS 8.8
CVE-2026-16372 HIGH
Privilege escalation in the DOM: Content Processes component
CVSS 8.8
CVE-2026-16371 HIGH
Privilege escalation in the DOM: Navigation component
CVSS 8.8
CVE-2026-16366 HIGH
Privilege escalation in the DOM: Navigation component
CVSS 8.8
CVE-2026-16365 HIGH
Privilege escalation in the DOM: Workers component
CVSS 8.8
CVE-2026-13439 CRITICAL
Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint
CVSS 9.8
CVE-2026-55550 HIGH
NextCRM 0.12.1 - Product Catalog RBAC Bypass via MCP Tools
CVSS 7.1
CVE-2026-44231 CRITICAL
RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint
CVSS 9.1
CVE-2026-16337 CRITICAL
dotCMS < 26.06.22-03 - Improper Privilege Management
CVE-2026-62183 CRITICAL
Apache Syncope: User self-service privilege escalation
CVSS 9.8
CVE-2026-13142 HIGH
Passwordless Login by VentraConnect < 1.4.1 - Unauthenticated Account Takeover via Email OTP Brute Force
CVSS 8.1
CVE-2026-47870 HIGH
VMware Avi Load Balancer Privilege Escalation Vulnerability
CVSS 7.1
CVE-2026-47868 HIGH
VMware Avi Load Balancer Local Privilege Escalation Vulnerability
CVSS 7.8
Details
Vulnerabilities 3,090
Exploit Likelihood Medium