The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
3,090 vulnerabilities with CWE-269
CVE-2026-60150
HIGH
Oracle VM VirtualBox 7.2.12 - Local Privilege Escalation to Host Takeover
CVSS 7.8
CVE-2026-47054
HIGH
Oracle VM VirtualBox 7.2.12 - Local Privilege Escalation to Host Takeover on Windows
CVSS 7.8
CVE-2026-47047
HIGH
Oracle VM VirtualBox 7.2.12 - Local Privilege Escalation to Host Takeover
CVSS 7.8
CVE-2026-46995
HIGH
Oracle Enterprise Manager Base Platform 13.5 and 24.1 - Authenticated Remote Takeover via Metadata Plugin over HTTPS
CVSS 8.8
CVE-2026-47416
CRITICAL
PraisonAI Platform < 0.1.4 Member Role Endpoint - Privilege Escalation
CVSS 9.6
CVE-2026-47413
CRITICAL
praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members
CVSS 9.6
CVE-2026-47412
HIGH
praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
CVSS 8.1
CVE-2026-47411
MEDIUM
PraisonAI Platform < 0.1.4 Workspace Settings - Authorization Bypass
CVSS 6.5
CVE-2026-47409
HIGH
PraisonAI Platform < 0.1.4 Member Delete Endpoint - Owner Lockout
CVSS 8.1
CVE-2026-47407
CRITICAL
PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation
CVE-2026-16401
HIGH
Mozilla Firefox - Privilege Escalation in the Data Loss Prevention Component
CVSS 8.8
CVE-2026-16396
HIGH
Mozilla Firefox - Privilege Escalation in WebExtensions
CVSS 8.8
CVE-2026-16379
HIGH
Privilege escalation in the DOM: Content Processes component
CVSS 8.8
CVE-2026-16372
HIGH
Privilege escalation in the DOM: Content Processes component
CVSS 8.8
CVE-2026-16371
HIGH
Privilege escalation in the DOM: Navigation component
CVSS 8.8
CVE-2026-16366
HIGH
Privilege escalation in the DOM: Navigation component
CVSS 8.8
CVE-2026-16365
HIGH
Privilege escalation in the DOM: Workers component
CVSS 8.8
CVE-2026-13439
CRITICAL
Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint
CVSS 9.8
CVE-2026-55550
HIGH
NextCRM 0.12.1 - Product Catalog RBAC Bypass via MCP Tools
CVSS 7.1
CVE-2026-44231
CRITICAL
RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint
CVSS 9.1
CVE-2026-16337
CRITICAL
dotCMS < 26.06.22-03 - Improper Privilege Management
CVE-2026-62183
CRITICAL
Apache Syncope: User self-service privilege escalation
CVSS 9.8
CVE-2026-13142
HIGH
Passwordless Login by VentraConnect < 1.4.1 - Unauthenticated Account Takeover via Email OTP Brute Force
CVSS 8.1
CVE-2026-47870
HIGH
VMware Avi Load Balancer Privilege Escalation Vulnerability
CVSS 7.1
CVE-2026-47868
HIGH
VMware Avi Load Balancer Local Privilege Escalation Vulnerability
CVSS 7.8
Details
Vulnerabilities
3,090
Exploit Likelihood
Medium