CWE-269
CVEs classified under CWE-269, newest first.
470 CVEsRSS
CVE-2026-13756High· 8.8The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3
The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key validation in the `update()` handler for the `/wp-json/wpgb/v2/…
CVE-2026-44787High· 8.2Discourse is an open-source discussion platform
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group m…
CVE-2026-0276NoneA privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user.
A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user.
CVE-2026-50201Medium· 6.5Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
GHSA-rggc-m335-3wvjHighOpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
CVE-2026-46680High· 7.8PoCcontainerd is an open-source container runtime
containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leadi…
GHSA-7m8x-qg2j-4m3vHigh· 8.1Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec
Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec
CVE-2026-50545Critical· 9.9Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover
Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover
CVE-2026-50563Critical· 9.9Fission Container Executor Function PodSpec Injection Leading to Node Escape
Fission Container Executor Function PodSpec Injection Leading to Node Escape
CVE-2026-50564Critical· 9.9Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape
Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape
CVE-2026-50565Medium· 4.9Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
CVE-2026-50566Critical· 9.9Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation
Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation
CVE-2026-52808High· 7.1Gogs's write-level collaborators can mutate admin-only repository settings via API
Gogs's write-level collaborators can mutate admin-only repository settings via API
GHSA-qxvg-h7q2-hcxhCritical· 9.8motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
CVE-2026-54099High· 8.8A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not rej…
CVE-2026-54319Medium· 4.2Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
CVE-2026-53855High· 8.1OpenClaw: Shell positional parameters could weaken strict inline-eval checks
OpenClaw: Shell positional parameters could weaken strict inline-eval checks
CVE-2026-53862Low· 4.2OpenClaw: Bootstrap token replay could widen pending pairing scopes
OpenClaw: Bootstrap token replay could widen pending pairing scopes
CVE-2026-54415High· 8.1PoCMissing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over…
Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over…
CVE-2026-12289High· 8.8Privilege escalation in the Graphics: WebRender component
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
CVE-2026-47725Highnebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints
nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints
CVE-2026-0009High· 7.8PoCIn multiple locations, there is a possible tapjacking due to a logic error in the code
In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0091High· 7.8PoCIn multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user
In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…
CVE-2026-0089High· 7.8In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check
In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed.…
CVE-2026-0086Medium· 6.8In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check
In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti…
CVE-2026-45632Critical· 9.9Dokploy is a free, self-hostable Platform as a Service (PaaS)
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belongi…
CVE-2026-46817Critical· 9.8CISA KEVPoCVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission)
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with netwo…
CVE-2026-23663High· 7.5Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.
Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-9018High· 8.8PoCThe Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function
The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function. This is due to the `wp_ajax_…
CVE-2026-8972High· 8.8Privilege escalation in the WebRTC: Audio/Video component
Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.