CWE-269: Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
1,360 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-8489 — King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege Escalation
- CVE-2026-1492 — User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration
- CVE-2026-79090 — Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging soci
- CVE-2026-32760 — File Browser Self Registration Grants Any User Admin Access When Default Permissions Include Admin
- CVE-2026-31852 — Jellyfin Possible Organization/Secret Compromise from dangerous CI implementation
- CVE-2026-22238 — Administrator Account Creation Vulnerability in BLUVOYIX
- CVE-2026-22039 — Kyverno Cross-Namespace Privilege Escalation via Policy apiCall
- CVE-2025-12425 — Local Privilege Escalation
- CVE-2025-12424 — Privilege Escalation through SUID-bit Binary
- CVE-2026-79226 — Improper privilege management in Regional Capabilities in Google Chrome prior to 152.0.7977.65 allowed a remote attacker
- CVE-2025-8572 — Truelysell Core <= 1.8.7 - Unauthenticated Privilege Escalation via Registration
- CVE-2025-15403 — RegistrationMagic <= 6.0.7.1 - Privilege Escalation via admin_order
- CVE-2025-13851 — Buyent Theme (with Buyent Classified Plugin) <= 1.0.7 - Unauthenticated Privilege Escalation via User Registration
- CVE-2025-13559 — EduKart Pro <= 1.0.3 - Unauthenticated Privilege Escalation
- CVE-2026-78999 — Improper privilege management in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had co
- CVE-2026-30960 — RSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI Interface
- CVE-2024-13997 — Nagios XI < 2024R1.1.3 Privilege Escalation via Migrate Server Feature to Root on Host
- CVE-2025-66266 — Insecure SYSTEM Service Permissions in UPSilon2000V6.0 (RupsMon.exe) leading to trivial Local Privilege Escalation
- CVE-2025-33187 — NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to
- CVE-2026-29127 — Incorrect Permission Assignment(777) on `monitor` Users Home Directory Containing SUID Root Binaries in IDC SFX2100
Recently published
- CVE-2026-88891 — OpenPanel Read-Only Access Level Enforcement Bypass via Mutations
- CVE-2026-88863 — capgo.app through 12.207.1 Privilege Escalation via invite_new_user_to_org
- CVE-2026-84042 — Crun: crun: rootful krun with passt executes container payload as host root
- CVE-2026-87998 — Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
- CVE-2026-86746 — Snipe-IT before 8.7.0 Authorization Bypass via Livewire Snapshot Replay
- CVE-2026-12858 — Local privilege escalation vulnerability in ESET AV Remover
- CVE-2026-14359 — YITH WooCommerce Waitlist Premium <= 3.35.0 - Authenticated (Subscriber+) Privilege Escalation to Admin via wp_ajax_yith_wcwtl_add_user
- CVE-2026-75927 — PublishPress Capabilities <= 2.50.0 - Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant
- CVE-2026-17553 — Shopping Cart & eCommerce Store <= 5.9.3 - Authenticated (Store Manager+) Privilege Escalation to ec_ajax_save_page_default_options AJAX Action
- CVE-2026-76801 — FireBox <= 3.1.10 - Authenticated (Author+) Remote Code Execution to Privilege Escalation
- CVE-2026-84869 — ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
- CVE-2026-77968 — Hawtio-operator: hawtio-operator: cluster-wide secrets read/write granted to operator serviceaccount
- CVE-2026-86516 — elenavanengelenmaslova mocknest-serverless AWS GitHub OIDC Deployment Helper Script github-oidc-role.yaml privileges management
- CVE-2026-80166 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-14444 — WP Fusion (Pro) <= 3.47.13 - Authenticated (Subscriber+) Privilege Escalation via ThriveCart Auto Login 'role' Parameter
- CVE-2026-80178 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-77697 — Privilege Escalation
- CVE-2026-85640 — Privilege Escalation
- CVE-2026-77699 — Privilege Escalation
- CVE-2026-77698 — Privilege Escalation