CWE-286Class

Incorrect User Management

Incomplete in the CWE catalog · 26 CVEs mapped

26
CVEs mapped
6.3
Median CVSS
What it is

The product does not properly manage a user within its environment.

Recent examples
8.1cvss
CVE-2026-56428

The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration

The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in possession of the corresponding private key could leverage it to bypass authentication and gain root-level access to the appliance.

HIGHno explanation yet
0%
epss
7.1cvss
CVE-2026-60135

Weintek cMT3092X Incorrect User Management

An attacker can modify data that should be restricted to read‑only access.

HIGHno explanation yet
0%
epss
8.7cvss
CVE-2026-35638

OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UI

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated sessions to retain self-declared privileged scopes without device identity verification. Attackers can exploit the device-less allow path in the trusted-proxy mechanism to maintain elevated permissions by declaring arbitrary scopes, bypassing device identity requirements.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-286
Abstraction
Class
Structure
Simple
Status
Incomplete