Search Results (3657 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-102112 2 Accellion, Kiteworks 2 Kiteworks, Core 2026-10-07 7.8 High
A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.
CVE-2026-102093 2 Accellion, Kiteworks 2 Kiteworks, Core 2026-10-07 7.2 High
Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permissions to elevate another user to full system-administrator privileges beyond those the administrative user was authorized to grant.
CVE-2026-76742 2026-10-07 9.8 Critical
Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to gain unauthorized access to the affected system.
CVE-2026-28625 1 Google 1 Android 2026-10-07 7.8 High
In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-28641 1 Google 1 Android 2026-10-07 7.8 High
In shouldDisableUninstallButton of ApplicationActionButtonsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-28647 1 Google 1 Android 2026-10-07 7.8 High
In updateState of DeviceAdminAppsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-87782 2026-10-07 8.8 High
The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.
CVE-2026-55307 1 Google 1 Android 2026-10-07 4.4 Medium
In kdn_set_sysregs_prot of hwcrypto-kdn.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-106492 2026-10-07 7.6 High
Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults package is affected by improper preservation of access restrictions during service credential delegation. An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. This could allow a restricted service to perform operations beyond its intended scope, including write operations on plugins it was restricted to read-only access for. This issue is fixed in versions 0.16.1 and 0.17.8.
CVE-2026-67269 2026-10-06 9.9 Critical
Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining root-level access on cluster nodes.
CVE-2026-81445 1 Dell 6 Dell Openmanage Server Administrator Managed Node For Rhel 8.10, Dell Openmanage Server Administrator Managed Node For Rhel 9.4, Dell Openmanage Server Administrator Managed Node For Sles 15 and 3 more 2026-10-06 7.2 High
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
CVE-2026-81442 1 Dell 6 Dell Openmanage Server Administrator Managed Node For Rhel 8.10, Dell Openmanage Server Administrator Managed Node For Rhel 9.4, Dell Openmanage Server Administrator Managed Node For Sles 15 and 3 more 2026-10-06 8.1 High
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access.
CVE-2026-105687 1 Penpot 1 Penpot 2026-10-06 4.9 Medium
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to remove any member other than themselves but does not protect the team owner. A non-owner administrator can delete the owner's team-profile-rel membership and lock the owner out of the team and its projects, files, fonts, and media. This issue is fixed in version 2.18.0.
CVE-2026-105634 1 Makeplane 1 Plane 2026-10-06 8.1 High
Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrators and Members and deny them project control. This vulnerability is fixed in 1.3.0.
CVE-2026-92015 1 Mozilla 2 Firefox, Thunderbird 2026-10-06 8.8 High
Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
CVE-2026-92017 1 Mozilla 2 Firefox, Thunderbird 2026-10-06 8.8 High
Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
CVE-2026-105688 1 Penpot 1 Penpot 2026-10-06 6.7 Medium
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the owner role because invitation roles are persisted and applied without the role-ceiling check used by update-team-member-role. An administrator can invite another account as an owner, create multiple owners, and then use the new owner account to obtain owner-only control over the team. This issue is fixed in version 2.18.0.
CVE-2026-104412 1 Ghost 1 Ghost 2026-10-06 4.3 Medium
Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role to other staff despite lacking permission to do so. An authenticated Editor or Super Editor can promote Author and Contributor users to Editor or Super Editor.
CVE-2026-105126 1 Laradashboard 1 Lara Dashboard 2026-10-05 7.2 High
LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution.
CVE-2026-92073 1 Mozilla 2 Firefox, Thunderbird 2026-10-05 8.8 High
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.