CVE-2026-103752Critical· 9.8▾ MidnightUnauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54072Critical· 9.3Authorizer is an open-source, self-hostable authentication and authorization server
CVE-2026-103068High· 8.8Subscriber Privilege Escalation in ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 versions.
CVE-2026-103286High· 7.3Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff roles
CVE-2026-103494Medium· 6.6In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
CVE-2026-103534Medium· 6.3A vulnerability was determined in David-Crty databasement up to 1.7.1
CVE-2026-103532Medium· 5.3A vulnerability has been found in immich-app Immich up to 2.7.5