CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

3,090 vulnerabilities with CWE-269
CVE-2026-48010 MEDIUM
Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts
CVSS 6.5
CVE-2026-15380 MEDIUM
Broadcom Symantec Management Suite - Local Privilege Escalation in Symantec ITMS
CVE-2026-15379 MEDIUM
Broadcom Symantec IT Management Suite - Arbitrary File Read as SYSTEM in Symantec ITMS
CVE-2026-9810 CRITICAL
AI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privilege Escalation via MCP OAuth
CVSS 9.8
CVE-2026-11961 HIGH
User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation via Unbound members_data Membership ID
CVSS 8.1
CVE-2026-15982 CRITICAL
All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit < 2.8.4 - Privilege Escalation
CVSS 9.8
CVE-2026-14956 CRITICAL
Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter
CVSS 9.8
CVE-2026-43978 HIGH
wger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managers
CVSS 8.1
CVE-2026-36425 MEDIUM
OPSWAT AppRemover Driver <= 2017.10.02.1551 - Unauthenticated Local Process Termination via IOCTL 0x2420031
CVSS 6.5
CVE-2026-6423 HIGH
Local privilege escalation via unauthenticated ALPC in ESET Inspect Connector
CVE-2026-15103 HIGH
WPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation via 'group_id' Path Parameter
CVSS 8.8
CVE-2026-13741 HIGH
Digits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' Parameter
CVSS 8.8
CVE-2026-12525 HIGH
Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator
CVSS 8.8
CVE-2026-53444 HIGH
Wekan: Missing authorization on OIDC Meteor methods allows privilege escalation to admin
CVE-2026-62355 MEDIUM
TDengine: Standard User permission unexpect
CVSS 5.4
CVE-2026-53515 HIGH
Better Auth: Privilege escalation via SSO provider registration: missing admin role check in @better-auth/sso
CVSS 7.1
CVE-2026-14961 MEDIUM
Pegatron Corp. Tdelo64.sys - Privilege Escalation
CVSS 6.2
CVE-2026-14960 CRITICAL
Pegatron Tdelo64.sys < 02-17-2025 - Unauthenticated Arbitrary Hardware I/O Port Read and Write via IOCTL Handlers
CVSS 9.8
CVE-2026-57996 HIGH
phpMyFAQ - Privilege Escalation via Missing SuperAdmin Guard in user/add Endpoint
CVSS 8.8
CVE-2026-49501 MEDIUM
Dell PowerScale OneFS - Improper Privilege Management
CVSS 6.7
CVE-2026-50391 HIGH
Microsoft Windows 10 Version 1607 - Windows Group Policy Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-50343 HIGH
Microsoft Install Service Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-50295 MEDIUM
Microsoft Windows 11 Version 24H2 - Windows Zero Trust DNS Security Feature Bypass Vulnerability
CVSS 5.5
CVE-2026-49176 HIGH
Microsoft Windows 10 Version 1607 - Windows WalletService Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-53565 HIGH
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges
Details
Vulnerabilities 3,090
Exploit Likelihood Medium