CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,942 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 96 of 99
- CVE-2026-62145HIGHCVSS 7.5EG 7.52026-07-22
A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.
- CVE-2026-62183CRITICALCVSS 9.8EG 9.82026-07-20
Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for us…
- CVE-2026-6226HIGHCVSS 8.8EG 8.82026-05-28
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2. This is due to insecure form submission handling that accepts arbitrary form definitions fr…
- CVE-2026-6228HIGHCVSS 8.8EG 8.82026-05-15
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient authorization checks in the role field update mechanism combined with overly p…
- CVE-2026-62355MEDIUMCVSS 5.4EG 5.42026-07-15
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Cloud DB instance could run create udf even though standard users should have read-only pe…
- CVE-2026-62447HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network …
- CVE-2026-62453MEDIUMCVSS 6.3EG 6.32026-07-21
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with netwo…
- CVE-2026-62456HIGHCVSS 8.2EG 8.22026-07-21
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with net…
- CVE-2026-62464HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network…
- CVE-2026-62473HIGHCVSS 8.3EG 8.32026-07-21
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with…
- CVE-2026-62474MEDIUMCVSS 6.3EG 6.32026-07-21
Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Lease Authoring). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged atta…
- CVE-2026-62476HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacke…
- CVE-2026-62478HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged atta…
- CVE-2026-62493HIGHCVSS 7.5EG 7.52026-07-21
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with n…
- CVE-2026-62496HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with…
- CVE-2026-62498HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows low privileged attacker w…
- CVE-2026-62515HIGHCVSS 7.6EG 7.62026-07-21
Vulnerability in the Oracle Advanced Planning Command Center product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privil…
- CVE-2026-62524MEDIUMCVSS 6.3EG 6.32026-07-21
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with netw…
- CVE-2026-62525MEDIUMCVSS 6.3EG 6.32026-07-21
Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wi…
- CVE-2026-62534HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker wi…
- CVE-2026-62548HIGHCVSS 7.2EG 7.22026-07-21
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with netw…
- CVE-2026-62561HIGHCVSS 7.8EG 7.82026-07-21
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon…
- CVE-2026-62565HIGHCVSS 7.1EG 7.12026-07-21
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with netwo…
- CVE-2026-63700HIGHCVSS 7.8EG 7.82026-08-14
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
- CVE-2026-63701HIGHCVSS 7.8EG 7.82026-08-14
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privile…
- CVE-2026-6386MEDIUMCVSS 6.2EG 6.22026-04-22
In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled this failed to take into account the presence of 1GB largepage mappings created u…
- CVE-2026-6389HIGHCVSS 8.8EG 8.82026-04-30
IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator …
- CVE-2026-6419HIGHCVSS 8.8EG 8.82026-05-23
The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check in the ajax_get_screen() function. This …
- CVE-2026-6423HIGHCVSS 8.5EG 8.52026-07-16
A local privilege escalation vulnerability in ESET Inspect Connector. The vulnerability was caused by improper authentication in an IPC channel.
- CVE-2026-64634HIGHCVSS 8.4EG 8.42026-08-04
A vulnerability allowing local privilege escalation to the Reporter service context.
- CVE-2026-64637CRITICALCVSS 9.9EG 9.92026-08-07
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
- CVE-2026-65595HIGHCVSS 8.8EG 8.82026-07-22
n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of the acting user's role. On instances where the Token Exchange feature and Public API are enabled, a low-privilege…
- CVE-2026-65603HIGHCVSS 8.8EG 8.82026-07-22
The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the update_user task). Unlike the registration handler, this handler d…
- CVE-2026-65835MEDIUMCVSS 6.6EG 6.62026-07-30
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResource RawItems and Generators in internal/controllers/resources/collect.go, including handleR…
- CVE-2026-65897HIGHCVSS 8.8EG 8.82026-07-23
Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions. Attackers ca…
- CVE-2026-66015HIGHCVSS 7.2EG 7.22026-07-27
An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.
- CVE-2026-66399MEDIUMCVSS 6.5EG 6.52026-07-27
phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-management permissions to join privileged groups without verification of required rights. At…
- CVE-2026-67356HIGHCVSS 8.8EG 8.82026-08-02
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission c…
- CVE-2026-6741HIGHCVSS 8.8EG 8.82026-04-27
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 5.4.1. This is due to a missing authorization check in the execute() method of…
- CVE-2026-6750HIGHCVSS 8.8EG 8.82026-04-21
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
- CVE-2026-6761HIGHCVSS 8.8EG 8.82026-04-21
Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
- CVE-2026-6769HIGHCVSS 8.8EG 8.82026-04-21
Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
- CVE-2026-68561HIGHCVSS 8.8EG 8.82026-08-19
Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permissions/boards.js called canUpdateBoardSort in server/lib/utils.js, which authorized any board member whenever fieldNames …
- CVE-2026-68752HIGHCVSS 7.2EG 7.22026-08-12
A Project Resource Manager may gain broader administrative privileges under specific conditions.
- CVE-2026-68821HIGHCVSS 7.8EG 7.82026-08-11
Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-6895HIGHCVSS 8.8EG 8.82026-05-23
The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing capability checks in th…
- CVE-2026-6897HIGHCVSS 8.8EG 8.82026-05-23
The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in all versions up to, and including, 3.30…
- CVE-2026-6898HIGHCVSS 8.8EG 8.82026-05-23
The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions up to, and including, 3.30.1. This make…
- CVE-2026-69414HIGHCVSS 7.8EG 7.82026-08-14
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this…
- CVE-2026-70421HIGHCVSS 7.2EG 7.22026-08-19
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →