CWE-269Class10 in KEV

Improper Privilege Management

Draft in the CWE catalog · 1,612 CVEs mapped

1,612
CVEs mapped
10
In KEV
7.8
Median CVSS
What it is

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Recent examples
9.1cvss
CVE-2026-86153

Tenda CP3 Redirect.cpp SetRedirectEnable privileges management

A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.

CRITICALno explanation yet
epss
none
CVE-2026-86195

CVE-2026-86195 - UNKNOWN Severity Vulnerability

grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super. A non-super user manager with api.access and api.users.write permissions can create an invitation with a dot-keyed super flag in the access payload that bypasses the guard and persists to the new account. Attackers can accept the invitation through the public endpoint without real invitee interaction to create a super-admin account and immediately receive a valid JWT for full site control.

no explanation yet
epss
8.8cvss
CVE-2026-81543

CVE-2026-81543 - HIGH Severity Vulnerability

The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap_save_connector_settings, wcap_send_manual_email, wcap_abandoned_cart_info, and wcap_change_manual_email_data. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify SMTP connector settings to route administrator recovery emails through an attacker-controlled server and intercept auto-login links to gain full administrative access. The plugin's auto-login feature must be enabled, which is the default configuration.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-269
Abstraction
Class
Structure
Simple
Status
Draft
References (1)