CWE-269: Improper Privilege Management — known CVE vulnerabilities
CVEs classified under CWE-269 (Improper Privilege Management), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-60366 — CVSS 10.0 (critical): Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars)…
CVE-2026-31852 — CVSS 10.0 (critical): Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary…
CVE-2025-20282 — CVSS 10.0 (critical): A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files…
CVE-2025-0505 — CVSS 10.0 (critical): On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on…
CVE-2023-48418 — CVSS 10.0 (critical): In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure…
CVE-2023-48419 — CVSS 10.0 (critical): An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege
CVE-2023-31273 — CVSS 10.0 (critical): Protection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentially enable…
CVE-2022-1517 — CVSS 10.0 (critical): LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operating system level…
CVE-2021-39168 — CVSS 10.0 (critical): OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with…
CVE-2021-39167 — CVSS 10.0 (critical): OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with…
CVE-2021-1388 — CVSS 10.0 (critical): A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an…
CVE-2020-36155 — CVSS 10.0 (critical): An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta…
CVE-2018-4310 — CVSS 10.0 (critical): An access issue was addressed with additional sandbox restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14.
CVE-2026-75851 — CVSS 9.9 (critical): ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to…
CVE-2026-75843 — CVSS 9.9 (critical): ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing…
CVE-2026-73269 — CVSS 9.9 (critical): A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming…
CVE-2026-72886 — CVSS 9.9 (critical): Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in…
CVE-2026-72863 — CVSS 9.9 (critical): Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log…
CVE-2026-64637 — CVSS 9.9 (critical): Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative…
CVE-2026-48086 — CVSS 9.9 (critical): OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a…
CVE-2026-9193 — CVSS 9.9 (critical): An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an…
CVE-2026-8709 — CVSS 9.9 (critical): An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and…
CVE-2026-7329 — CVSS 9.9 (critical): An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before…
CVE-2026-15630 — CVSS 9.9 (critical): A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by…
CVE-2026-60369 — CVSS 9.9 (critical): Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars)…
CVE-2026-61237 — CVSS 9.9 (critical): Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration). The…
CVE-2026-61209 — CVSS 9.9 (critical): Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported…
CVE-2026-61146 — CVSS 9.9 (critical): Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content…
CVE-2026-61076 — CVSS 9.9 (critical): Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job Opening). The…
CVE-2026-60663 — CVSS 9.9 (critical): Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions…
CVE-2026-58053 — CVSS 9.9 (critical): Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's…
CVE-2026-46964 — CVSS 9.9 (critical): Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration)…
CVE-2026-46933 — CVSS 9.9 (critical): Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions…
CVE-2026-46901 — CVSS 9.9 (critical): Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions…
CVE-2026-46900 — CVSS 9.9 (critical): Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions…
CVE-2026-46895 — CVSS 9.9 (critical): Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions…
CVE-2026-46893 — CVSS 9.9 (critical): Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation). The supported version…
CVE-2026-46852 — CVSS 9.9 (critical): Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported…
CVE-2026-46794 — CVSS 9.9 (critical): Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector). Supported versions…
CVE-2026-50564 — CVSS 9.9 (critical): Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on…
CVE-2026-50563 — CVSS 9.9 (critical): Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on…
CVE-2026-50545 — CVSS 9.9 (critical): Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on…
CVE-2026-47744 — CVSS 9.9 (critical): Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any…
CVE-2026-46824 — CVSS 9.9 (critical): Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration)…
CVE-2026-30269 — CVSS 9.9 (critical): Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin…
CVE-2026-22039 — CVSS 9.9 (critical): Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical…
CVE-2025-67781 — CVSS 9.9 (critical): An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can…
CVE-2025-55187 — CVSS 9.9 (critical): In DriveLock 24.1.4 before 24.1.5, 24.2.5 before 24.2.6, and 25.1.2 before 25.1.4, attackers can gain elevated privileges.
CVE-2024-45496 — CVSS 9.9 (critical): A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build…
CVE-2024-33226 — CVSS 9.9 (critical): An issue in the component Access64.sys of Wistron Corporation TBT Force Power Control v1.0.0.0 allows attackers to escalate privileges and…