CVE-2026-62106
Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-266
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- Cozy Vision Technologies Pvt. Ltd. SMS Alert Order Notifications
Weakness type
Related vulnerabilities
- CVE-2026-62102 — WordPress Gato GraphQL plugin <= 19.2.3 - Privilege Escalation vulnerability
- CVE-2026-8303 — Privilege Escalation in TUBITAK BILGEM's Pardus-software
- CVE-2026-81805 — WordPress SiteSkite plugin <= 2.1.5 - Privilege Escalation vulnerability
- CVE-2026-15140 — A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP)....
- CVE-2026-86804 — seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization
- CVE-2026-77654 — Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Security Analyzer
- CVE-2026-85400 — TYPO3 CMS - Missing Authorization in lowlevel commands
- CVE-2026-81792 — WordPress Product Catalog Enquiry for WooCommerce by MultiVendorX plugin <= 6.1.4 - Privilege Escalation vulnerability