VulnSea

CWE-266

CVEs classified under CWE-266, newest first.

165 CVEsRSS

CVE-2026-77654Medium· 6.1
2w ago

Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalat…

Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalat…

▾ SunlitAlgosec · Horizon Security AnalyzerEPSS 0.14%via NVD
CVE-2026-86516Medium· 4.7
2w ago

A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0

A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Scri…

▾ Sunlitelenavanengelenmaslova · mocknest-serverlessEPSS 0.40%via NVD
CVE-2026-86512Medium· 6.3PoC
2w ago

A vulnerability was identified in java-json-tools json-patch up to 1.13

A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move O…

▾ Twilightjava-json-tools · json-patchEPSS 0.37%via NVD
CVE-2026-81792Medium· 6.5
2w ago

Incorrect Privilege Assignment vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX woocommerce-catalog-enquiry allows Privilege Escalation.This issue affects Product Catalog Enquiry for WooCommerce by Mu…

Incorrect Privilege Assignment vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX woocommerce-catalog-enquiry allows Privilege Escalation.This issue affects Product Catalog Enquiry for WooCommerce by Mu…

▾ SunlitMultiVendorX · woocommerce-catalog-enquiryEPSS 0.33%via NVD
CVE-2026-86500Medium· 5.5
2w ago

In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin

In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin

▾ SunlitJetBrains · YouTrackEPSS 0.27%via NVD
CVE-2026-86482High· 8.8
2w ago

In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation

In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation

▾ TwilightJetBrains · YouTrackEPSS 0.42%via NVD
CVE-2026-86285Medium· 4.3PoC
2w ago

A vulnerability was detected in BookStack up to 26.05.2

A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attachment Edit Endpoint. T…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-86275Medium· 5.3PoC
2w ago

A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0

A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manipulation of the argument role results i…

▾ TwilightSourceCodester · Syllabus-Aligned Learning Management & Examination SystemEPSS 0.48%via NVD
CVE-2026-86228Medium· 4.3PoC
3w ago

A security vulnerability has been detected in JeecgBoot up to 3.9.3

A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-86212Medium· 4.3PoC
3w ago

A vulnerability has been found in Open5GS 2.7.7/2.8.0

A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit has…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-86153Critical· 9.1
3w ago

A vulnerability has been found in Tenda CP3 27.5.57.101

A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the at…

▾ MidnightTenda · CP3EPSS 0.71%via NVD
CVE-2026-85513Medium· 6.3PoC
3w ago

StackStorm st2 NoOp RBAC backend actionexecutions.py privileges management

A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_user_query_param_is_provided of the file st2api/st2api/controllers/v1/actionexecutions.py of the component NoOp RBAC ba…

▾ TwilightStackStorm · st2EPSS 0.43%via CVEORG
CVE-2026-84756High· 7.1
3w ago

Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.

Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.

▾ TwilightEPSS 0.28%via NVD
CVE-2026-82553Medium· 6.3
4w ago

A vulnerability was detected in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5

A vulnerability was detected in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is the function mysqli_query of the file student_dashboard.php of the component Student Dashboard.…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-82486Medium· 5.0
4w ago

A vulnerability was found in SiteServer SSCMS 7.4.0

A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument SecurityKey results in improper access cont…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-11861Critical· 9.6
1mo ago

A flaw was found in FreeIPA

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This …

▾ Midnightfreeipa · freeipaEPSS 0.21%via NVD
CVE-2026-67846High· 7.8
1mo ago

Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect privilege assignment issue in the v3 and v4 NBDTLB implementations

Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect privilege assignment issue in the v3 and v4 NBDTLB implementations. The raw mstatus.SUM value participates in the read an…

▾ TwilightEPSS 0.15%via NVD
CVE-2026-19928Medium· 6.3
1mo ago

A vulnerability was determined in OpenBoxes up to 0.9.7

A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a manipulation can le…

▾ SunlitEPSS 0.44%via NVD
CVE-2026-19918Medium· 6.3
1mo ago

A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3

A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation leads to improper access controls. The attack can only…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-72826High· 8.8
1mo ago

The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey

The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target path of requireApiKeyPermission() requires only the baseli…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-72840High· 8.8PoC
1mo ago

OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration

OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL …

▾ Midnightopenwrt · luciEPSS 0.44%via NVD
CVE-2026-72839Critical· 9.8
1mo ago

filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting

filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full cre…

▾ MidnightEPSS 0.57%via NVD
CVE-2026-58443Critical· 9.6
1mo ago

code.gitea.io/gitea: Gitea: Unauthorized update of private pull request branches via public-only tokens (CVE-2026-58443)

A flaw was found in Gitea. This vulnerability allows an attacker to use tokens intended for public repositories to modify private pull request (PR) branches. This could lead to unauthorized changes in private code, compromising the integri…

▾ MidnightRed Hat · OpenShift PipelinesEPSS 0.58%via CSAF
CVE-2026-71468Medium· 5.3
1mo ago

A flaw was found in acm-search-v2-api-rhel9

A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authent…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.11EPSS 0.42%via NVD
CVE-2026-73281Low· 3.5
1mo ago

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bin…

▾ Sunlitopenbsd · opensshEPSS 0.16%via NVD
CVE-2026-15467High· 8.1
1mo ago

A flaw was found in the trustyai-service-operator's LMEvalJob controller

A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the us…

▾ TwilightRed Hat · rhoai/odh-trustyai-service-operator-rhel9EPSS 0.60%via NVD
CVE-2026-18621High· 7.6
1mo ago

A flaw was found in Data Science Pipelines (DSP)

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with …

▾ TwilightRed Hat · rhoai/odh-ml-pipelines-api-server-v2-rhel9EPSS 0.51%via NVD
CVE-2026-19381High· 7.8
1mo ago

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper p…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-19376High· 7.3
1mo ago

A vulnerability has been found in Uasoft Badaso 3.0.0-alpha

A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues. It is possible …

▾ TwilightEPSS 0.47%via NVD
CVE-2026-19360Medium· 4.7
1mo ago

A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3

A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results in improper privilege management. The a…

▾ SunlitEPSS 0.38%via NVD
CWE-266 vulnerabilities (CVEs) — page 3 · VulnSea