CVE-2026-2450
.NET misconfiguration: use of impersonation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Hijacking a Privileged Thread of Execution.This issue affects upKeeper Instant Privilege Access: through 1.5.0.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.27%
- CWE
- CWE-520
- Published
- 2026-04-14
- Last modified
- 2026-04-14
Affected products
- upKeeper Solutions upKeeper Instant Privilege Access
Weakness type
Related vulnerabilities
- CVE-2026-13444 — Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
- CVE-2026-13442 — Langflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthenticated and insufficiently authorized API endpoints
- CVE-2019-25608 — Iperius Backup 6.1.0 Privilege Escalation via Backup Job