VulnSea

CWE-269

CVEs classified under CWE-269, newest first.

470 CVEsRSS

CVE-2026-73842Critical· 9.0
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requir…

▾ Midnightopenchoreo · github.com/openchoreo/openchoreoEPSS 0.27%via NVD
CVE-2026-73284High· 8.8
1mo ago

RustFS is a distributed object storage system built in Rust

RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an attacker-controlled target_user after only checking CreateServiceAccountAdminAction, passes …

▾ TwilightEPSS 0.52%via NVD
CVE-2026-73269Critical· 9.9
1mo ago

A flaw was found in the cluster-curator-controller component

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to…

▾ MidnightRed Hat · multicluster-engine/cluster-curator-controller-rhel9EPSS 0.56%via NVD
CVE-2026-73293High· 8.8
1mo ago

Semaphore UI is a web interface for managing DevOps tools

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProjectOrGlobalRoleBySlug allow a project manager to use POST /api/project/{id}/roles to cre…

▾ Twilightsemaphoreui · github.com/semaphoreui/semaphoreEPSS 0.57%via NVD
CVE-2026-68752High· 7.2
1mo ago

A Project Resource Manager may gain broader administrative privileges under specific conditions.

A Project Resource Manager may gain broader administrative privileges under specific conditions.

▾ TwilightEPSS 0.49%via NVD
CVE-2026-73218None
1mo ago

Cursor is a code editor built for programming with AI

Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container …

▾ SunlitEPSS 0.63%via NVD
CVE-2026-18702Medium· 6.4
1mo ago

An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the intended database

An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the intended database. This could allow suppressio…

▾ Sunlitmongodb · mongodbEPSS 0.27%via NVD
CVE-2026-68821High· 7.3
1mo ago

Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.

Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · app_installerEPSS 0.32%via NVD
CVE-2026-72886Critical· 9.9
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the…

▾ MidnightEPSS 0.52%via NVD
CVE-2026-72863Critical· 9.9
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session but never authorize it. They establish who the user is via valida…

▾ MidnightEPSS 0.55%via NVD
CVE-2026-19381High· 7.8
1mo ago

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper p…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-19360Medium· 4.7
1mo ago

A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3

A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results in improper privilege management. The a…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-14526Critical· 9.8
1mo ago

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. T…

▾ MidnightEPSS 0.91%via NVD
CVE-2026-48086Critical· 9.9
1mo ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-u…

▾ MidnightEPSS 0.44%via NVD
CVE-2026-20308Medium· 4.3
1mo ago

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerabilit…

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerabilit…

▾ SunlitCisco · Cisco IOS XE SoftwareEPSS 0.32%via NVD
CVE-2026-16071Medium· 5.4
1mo ago

A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories

A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished N…

▾ Sunlitredhat · build_of_keycloakEPSS 0.32%via NVD
CVE-2026-9193Critical· 9.9
1mo ago

An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged o…

An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged o…

▾ MidnightEPSS 0.46%via NVD
CVE-2026-8709Critical· 9.9
1mo ago

An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute…

An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute…

▾ MidnightEPSS 0.46%via NVD
CVE-2026-7329Critical· 9.9
1mo ago

An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges …

An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges …

▾ MidnightEPSS 0.57%via NVD
CVE-2026-7327High· 8.1
1mo ago

An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges

An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This …

▾ TwilightEPSS 0.39%via NVD
CVE-2026-67356High· 8.8
1mo ago

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission…

▾ TwilightEPSS 0.44%via NVD
CVE-2026-16635High· 8.8
1mo ago

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$l…

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$l…

▾ TwilightEPSS 0.58%via NVD
CVE-2026-15414High· 8.8
1mo ago

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan me…

▾ TwilightEPSS 0.81%via NVD
CVE-2026-65835Medium· 6.6
1mo ago

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

▾ Sunlitprojectcapsule · github.com/projectcapsule/capsuleEPSS 0.33%via GHSA
CVE-2026-50570High· 8.5
2mo ago

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

▾ Twilightfission · github.com/fission/fissionEPSS 0.46%via GHSA
GHSA-j9fc-w3mr-x6mvHigh· 8.8
2mo ago

Budibase: Privilege escalation via public role assignment API missing app-level authorization

Budibase: Privilege escalation via public role assignment API missing app-level authorization

▾ Twilightbudibase · @budibase/servervia GHSA
CVE-2026-15630Critical· 9.9PoC
2mo ago

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

▾ AbyssalCasdoor · CasdoorEPSS 0.34%via NVD
CVE-2026-65897High· 8.8
2mo ago

Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions

Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions. Attackers …

▾ TwilightEPSS 0.52%via NVD
GHSA-wq64-hcrf-8m56High
2mo ago

Duplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs

Duplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs

▾ Twilightn8n · n8nvia GHSA
CVE-2026-65595High
2mo ago

n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs

n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs

▾ Twilightn8n · n8nEPSS 0.69%via GHSA
CWE-269 vulnerabilities (CVEs) — page 12 · VulnSea