By weakness (CWE)

CWE-266: related vulnerabilities

CVEs classified under CWE-266. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

66 published vulnerabilities

  • CVE-2025-15656HIGH 8.8

    Mojoomla School Management contains a privilege escalation vulnerability stemming from improper assignment of user permissions. An authenticated attacker with basic user-level access can exploit this flaw to gain elevated privileges within the application, potentially obtaining administrative capabilities. The vulnerability affects all versions from the earliest tracked through version 93.2.0, making it a broad exposure for deployments that have not yet patched.

  • CVE-2026-12289HIGH 8.8

    A privilege escalation vulnerability exists in Firefox and Thunderbird's WebRender graphics component. An attacker can exploit this through a malicious webpage to gain elevated privileges on a user's system. The vulnerability requires user interaction (visiting a crafted site) but needs no authentication and can be triggered remotely over the network. The impact is severe—an attacker could read sensitive files, modify system data, or execute arbitrary code with higher-level access.

  • CVE-2026-35671HIGH 8.8

    phpMyFAQ versions before 4.1.3 contain a privilege escalation vulnerability in the admin password management API. An authenticated administrator with low-level privileges can manipulate API requests to reset any user's password, including SuperAdmin accounts, bypassing normal authorization checks. This allows attackers to seize full control of the FAQ system.

  • CVE-2026-45830HIGH 8.8

    ChromaDB, a Python vector database project, contains a critical authorization flaw that allows any logged-in user to access, modify, or delete data belonging to other tenants. The vulnerability affects version 0.4.17 and later. Because authorization checks are missing, a legitimate user of one tenant can perform full read, write, update, and delete operations on collections in any other tenant's isolated data space. This is particularly severe in multi-tenant deployments where data isolation is a core security assumption.

  • CVE-2026-49111HIGH 8.8

    ThemeGrill's Masteriyo LMS contains a privilege escalation flaw where user roles and permissions are incorrectly assigned. An authenticated attacker can exploit this to gain elevated privileges within the learning management system, potentially accessing or modifying content and settings they should not be able to reach. The vulnerability affects all versions through 2.2.0.

  • CVE-2026-53814HIGH 8.3

    OpenClaw versions before 2026.5.20 contain a privilege escalation flaw in their hook-triggered agent execution. When a hook is fired, the spawned CLI runtime incorrectly inherits the full scope of the hook's owner instead of being restricted to hook-specific permissions. An attacker who obtains a valid hook token can abuse the /hooks/agent endpoint to run commands with elevated privileges, potentially modifying persistent system state like cron jobs that normally require owner-level access.

  • CVE-2026-12217HIGH 7.8

    DVDFab Virtual Drive version 2.0.0.5 contains a privilege escalation vulnerability in its signed kernel driver component (dvdfabio.sys). A local user with standard privileges can exploit this flaw to gain elevated system access, potentially allowing them to modify system files, install malware, or disable security controls. The vulnerability requires local access and user interaction is not needed once code execution begins. Public exploit code is available, increasing the urgency for affected organizations.

  • CVE-2026-12778HIGH 7.8

    A privilege escalation flaw exists in AOMEI Partition Assistant version 10.10.1 and earlier, affecting the ampa10.sys kernel driver. An authenticated local attacker can exploit improper access controls in the driver to gain elevated system privileges, potentially compromising the entire system. The vulnerability has been publicly disclosed, and exploit code may be in circulation. The vendor has not responded to early disclosure attempts.

  • CVE-2026-12779HIGH 7.8

    AOMEI Dynamic Disk Manager versions up to 10.10.1 contain a privilege escalation vulnerability in the ddmdrv.sys kernel driver that allows a locally authenticated attacker to bypass access controls and gain elevated privileges on the system. An attacker with user-level access can manipulate the kernel driver to achieve high-impact unauthorized actions. The vendor has not responded to early disclosure efforts, and exploit code is publicly available.

  • CVE-2026-12780HIGH 7.8

    AOMEI Backupper, a widely-used backup and disaster recovery application, contains a kernel driver vulnerability that allows local attackers with user-level privileges to bypass access controls and gain elevated capabilities on affected systems. The flaw resides in the amwrtdrv.sys driver and requires an attacker to already have local access to the machine. Public exploit code exists, and the vendor has not responded to early disclosure attempts.

  • CVE-2026-12781HIGH 7.8

    EaseUS Partition Master versions up to 14.5 contain a kernel driver vulnerability that allows authenticated local users to bypass security controls and gain elevated privileges. An attacker with legitimate access to a system running the affected software can exploit an improper access control flaw in the epmntdrv.sys driver to read, modify, or disrupt system functionality. The vendor has confirmed the issue only existed in older versions and has been resolved in current releases.

  • CVE-2026-12782HIGH 7.8

    EaseUS Partition Master versions up to 14.5 contain a kernel driver vulnerability that allows local users with standard privileges to gain elevated system access and control over disk partitioning functions. The flaw stems from improper access controls in the EUEDKEPM.sys driver. Because exploit code is publicly available, this vulnerability poses an active risk to organizations running older versions of the software. The vendor has confirmed the issue is resolved in current releases.

  • CVE-2026-12784HIGH 7.8

    IM-Magic Partition Resizer versions up to 7.9.0 contain a security flaw in its kernel driver (MDA_NTDRV.sys) that fails to properly enforce access controls. An attacker with local system access could exploit this weakness to gain elevated privileges or interfere with system integrity. Public exploit code now exists, elevating the practical risk. The vendor has not responded to early disclosure attempts, leaving affected users without an official patch.

  • CVE-2026-12786HIGH 7.8

    Ezbsystems UltraISO Premium Edition versions up to 9.76 contain a vulnerability in a kernel driver (bootpt64.sys) that fails to enforce proper access controls. An attacker with local system access can exploit this weakness to gain elevated privileges and potentially read, modify, or delete sensitive data on the affected system. The vulnerability has been publicly disclosed, and while the vendor was notified early, they have not provided a response or patch.

  • CVE-2026-45490HIGH 7.8

    A flaw in Microsoft .NET allows an authorized local user to bypass privilege restrictions and gain higher-level access on the same machine. An attacker who already has login credentials can exploit this improper authorization logic to escalate to administrative or system-level permissions, potentially compromising the entire system.

  • CVE-2026-10236HIGH 7.3

    A security flaw exists in SourceCodester Water Billing Management System version 1.0 that allows attackers to bypass authorization controls in the User Management system. An attacker can remotely manipulate user-related operations through the /classes/Users.php?f=save endpoint without needing credentials or user interaction. This means an unauthorized person could potentially create, modify, or access user accounts and associated data. Public disclosure of this vulnerability means attackers are likely already aware of and testing for it.

  • CVE-2026-11462HIGH 7.3

    BeikeShop, an e-commerce platform by Chengdu Everbrite Network Technology, contains an authorization flaw in its Stripe payment plugin that allows unauthenticated attackers to manipulate request parameters and gain unauthorized access to sensitive functions. The vulnerability affects versions up to 1.6.0.22 and has been publicly disclosed, increasing exploitation risk. A patch is available and should be deployed promptly.

  • CVE-2026-12529HIGH 7.3

    SourceCodester's CET Automated Grading System with AI Predictive Analytics version 1.0 contains a flaw in its student self-registration function that allows attackers to bypass access controls. An unauthenticated remote attacker can exploit this weakness to gain unauthorized access to system resources. The vulnerability affects the /index.php endpoint and requires no user interaction to trigger.

  • CVE-2026-9795HIGH 7.3

    A flaw in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature allows a limited administrator to bypass security controls and inject high-privilege roles into a client application. When users authenticate to that client, the injected roles appear in their authentication tokens, granting them unauthorized access. An attacker with restricted admin rights can escalate their own permissions or those of other users without triggering standard approval workflows.

  • CVE-2026-39470HIGH 7.2

    A privilege escalation vulnerability exists in WooCommerce Cart Abandonment Recovery plugin versions prior to 2.1.0. An attacker with shop manager privileges can exploit this flaw to gain unauthorized elevated access within the WordPress environment, potentially compromising administrative functions and sensitive e-commerce data. The vulnerability requires an authenticated attacker with shop manager role, but no additional user interaction is needed for exploitation.

  • CVE-2026-10272MEDIUM 6.5

    A4M4's Student-Management-System contains an authorization flaw in its admin panel that allows unauthenticated attackers to manipulate a parameter called 'sid' in the deleteform.php file, potentially leading to unauthorized data modification or deletion. The vulnerability is network-accessible and does not require user interaction or special privileges to exploit. While the issue has been publicly disclosed and exploit code is available, the development team has not yet issued a patch or formal response.

  • CVE-2026-56251MEDIUM 6.5

    Capgo versions prior to 12.128.2 contain a flaw in their access control system that lets already-authenticated administrators escalate themselves to a super_admin role without proper authorization. The vulnerability stems from broken row-level security (RLS) policies on the org_users table, meaning the database isn't correctly restricting which rows a user can modify. An attacker with admin credentials can exploit this to gain super_admin privileges, effectively taking full control of the system.

  • CVE-2026-10152MEDIUM 6.3

    A flaw in TaleLin's lin-cms-spring-boot framework (version 0.2.1 and earlier) allows authenticated users to bypass access controls on the book endpoint. An attacker with valid login credentials can manipulate requests to perform actions they should not be permitted to execute, such as viewing, modifying, or deleting book records without proper authorization checks. Proof-of-concept code is publicly available, increasing the risk of active exploitation.

  • CVE-2026-10217MEDIUM 6.3

    A privilege management flaw exists in nextlevelbuilder GoClaw versions up to 3.11.3 that allows authenticated users to escalate their access or perform unauthorized actions. The vulnerability affects the RoleAdmin Gateway component, specifically in how it handles configuration saves. An attacker with valid credentials can exploit this remotely to gain elevated permissions or manipulate role-based access controls, potentially affecting data confidentiality, integrity, and availability.

  • CVE-2026-10269MEDIUM 6.3

    A vulnerability in decolua 9router allows an authenticated user to bypass authorization controls by manipulating the Host HTTP header. The flaw exists in the authentication logic of the dashboard guard component and can be exploited remotely by someone with valid login credentials. Affected versions up to 0.4.0 should be updated immediately to 0.4.1.

  • CVE-2026-10277MEDIUM 6.3

    A security flaw exists in the MCP Google Workspace integration's Gmail tool that allows authenticated users to bypass access controls and manipulate file storage operations. An attacker with valid login credentials can remotely exploit this vulnerability to gain unauthorized access to data or perform unintended modifications. The vulnerability affects the component up to commit 831790e7d5c2663325733d9f5579cc339a267c4c, and a patch has been released.

  • CVE-2026-10693MEDIUM 6.3

    SourceCodester Online Boat Reservation System version 1.0 contains a flaw in its administrative endpoints that fails to properly verify user permissions. An authenticated attacker can exploit this improper authorization to access or modify administrative functions they shouldn't have access to. The vulnerability requires an existing user account but can be exploited over the network without user interaction. The flaw affects multiple administrative endpoints, and exploit details have been publicly disclosed.

  • CVE-2026-10876MEDIUM 6.3

    SourceCodester Ship Ferry Ticket Reservation System version 1.0 contains an authorization bypass vulnerability affecting its admin panel. An authenticated user can manipulate the 'page' parameter in requests to /admin/ to access functions they should not be permitted to use. This vulnerability requires valid login credentials to exploit, but once authenticated, an attacker can view, modify, or delete unauthorized data. The vulnerability has been publicly disclosed with working exploits available, increasing active risk.

  • CVE-2026-11336MEDIUM 6.3

    A flaw in the College Management System allows authenticated users to bypass authorization controls and gain unauthorized access to sensitive administrative functions. An attacker with valid login credentials can manipulate a parameter called UserAuthData in the admin dashboard to perform actions they shouldn't be allowed to perform, potentially viewing, modifying, or deleting data. Because this vulnerability requires prior authentication and the exploit details are now public, it poses a meaningful security risk to organizations running this software.

  • CVE-2026-11438MEDIUM 6.3

    A security flaw in OneDev versions up to 15.0.5 allows authenticated users to manipulate project forking parameters in a way that bypasses authorization controls. An attacker with valid credentials can supply a crafted project ID in the forking mechanism to gain unauthorized access or modify projects they should not have permission to touch. This is a remote vulnerability requiring only standard user login—no special network access or user interaction needed beyond the attack itself.

  • CVE-2026-11439MEDIUM 6.3

    A vulnerability in OneDev up to version 15.0.5 allows authenticated users to manipulate parent project assignments in a way that bypasses authorization checks. An attacker with valid credentials can exploit the project.parentId parameter in the /projects/ endpoint to gain unauthorized access or make unauthorized changes to project hierarchies. This is a remote, network-accessible flaw that requires an existing user account to exploit.

  • CVE-2026-11440MEDIUM 6.3

    A vulnerability in OneDev versions up to 15.0.5 allows authenticated users to bypass authorization controls when modifying project default branch settings through the REST API. An attacker with login credentials can manipulate the `project.defaultBranch` parameter to gain unauthorized access or make changes they shouldn't be permitted to make. The vulnerability requires valid authentication to exploit but poses a moderate risk due to the potential for privilege escalation or unauthorized repository configuration changes.

  • CVE-2026-11441MEDIUM 6.3

    A flaw exists in theonedev onedev versions up to 15.0.5 that allows authenticated users to bypass authorization checks when accessing pull request issues. An attacker with valid credentials can manipulate how the system validates whether they have permission to view or modify specific issues, potentially gaining unauthorized access to sensitive project data. The vulnerability is straightforward to exploit once an attacker has credentials, and it requires only network access to the affected instance.

  • CVE-2026-11476MEDIUM 6.3

    Kushan2k's student-management-system contains a flaw in its admin profile update endpoint that allows authenticated users to escalate their privileges by manipulating the 'isadmin' parameter. An attacker with legitimate credentials can modify this parameter to grant themselves administrative access without proper authorization checks. The vulnerability has already been disclosed publicly, and remote exploitation requires only network access and valid login credentials.

  • CVE-2026-11519MEDIUM 6.3

    SourceCodester Inventory System version 1.0 contains a privilege escalation vulnerability in its user account creation mechanism. An authenticated attacker can manipulate the ROLE parameter during account creation to bypass authorization controls and gain elevated privileges. The vulnerability requires valid login credentials but can be exploited remotely without user interaction. Public exploits are available, increasing the likelihood of active exploitation.

  • CVE-2026-11521MEDIUM 6.3

    A security vulnerability exists in the Transaction Endpoint of the Mohammed-eid35 bank-management-system-springboot project that allows authenticated users to perform actions they shouldn't be authorized for. The flaw lies in the TransactionController component and enables an attacker with valid login credentials to manipulate transaction data beyond their permitted scope. Because this is a publicly disclosed vulnerability affecting a banking system component, prompt remediation is important even though exploitation requires existing user access.

  • CVE-2026-11532MEDIUM 6.3

    A security flaw has been discovered in imvks786's student management system that weakens access controls on student records. An authenticated user with basic access can manipulate requests to the Student Record Handler component (/add.php) to gain unauthorized permissions or modify data they shouldn't be able to touch. The vulnerability requires login credentials but can be exploited remotely. Public disclosure of exploitation techniques has already occurred, increasing near-term risk.

  • CVE-2026-11619MEDIUM 6.3

    A flaw exists in Dolibarr ERP CRM versions up to 23.0.2 within the Legacy Filemanager component. An authenticated attacker can exploit improper authorization controls in a configuration file to gain unauthorized access to functionality they should not have. The vulnerability allows remote exploitation and does not require user interaction. Public exploit code is available, increasing practical attack risk. The issue is resolved by upgrading to version 23.0.3 or later.

  • CVE-2026-43000MEDIUM 6.0

    An authenticated attacker with basic member-level permissions on an OpenStack Keystone project can escalate their privileges to administrator by chaining two Keystone features—application credentials and trusts—in an unintended way. The attack exploits a validation gap: when an impersonated token is created, Keystone checks the victim's stored admin role assignment in the database rather than validating against the actual permissions on the requesting token. This allows the attacker to create a trust that delegates the victim's admin privileges to themselves. The resulting admin access persists independently and can be maintained through additional credential chains, while all actions appear in audit logs under the victim's identity.

  • CVE-2026-10218MEDIUM 5.4

    A security flaw exists in nextlevelbuilder GoClaw versions up to 3.11.3 that allows authenticated users to perform actions they shouldn't be authorized to perform. The vulnerability resides in the authentication logic of the application and can be exploited remotely by someone with valid login credentials. Because the flaw has been publicly disclosed, there's elevated risk that attackers may attempt to exploit it.

  • CVE-2026-10284MEDIUM 5.4

    A security flaw in DevaslanPHP project-management versions up to 2.0.0-beta1 allows authenticated users to bypass authorization controls when editing or deleting comments in ticket management workflows. An attacker with login credentials can manipulate comment-related functions to perform actions they shouldn't be authorized to perform, such as deleting or modifying comments belonging to other users. The issue resides in the Livewire handler component and can be exploited remotely without requiring additional user interaction.

  • CVE-2026-10285MEDIUM 5.4

    DevaslanPHP project-management versions up to 2.0.0-beta1 contain an authorization flaw in the ticket handler component. An authenticated user can manipulate ticket records in ways they should not be permitted to perform, potentially modifying or deleting ticket data without proper access controls. The vulnerability requires an existing login but can be exploited remotely over the network.

  • CVE-2026-11466MEDIUM 5.4

    Zilliz's deep-searcher library contains an access control vulnerability in its collection routing logic. An authenticated attacker can manipulate function arguments to bypass intended restrictions, gaining unauthorized read access to data or causing service disruption. The issue affects versions up to 0.0.2, and exploit code is now publicly available, raising the risk of opportunistic attacks.

  • CVE-2026-11533MEDIUM 5.4

    A vulnerability in the imvks786 student_management_system allows an authenticated user to bypass authorization controls on the student deletion function. By manipulating a parameter called 'del' in the /see.php endpoint, an attacker with login credentials can perform unauthorized deletions of student records. The vulnerability requires valid authentication but does not need special privileges, meaning any logged-in user—including those with limited access—could exploit it. Public disclosure has occurred, increasing the likelihood of active exploitation.

  • CVE-2026-12770MEDIUM 5.4

    A security flaw was found in BerriAI's litellm, an open-source library for managing large language model API calls, affecting versions up to 1.63.1. The vulnerability resides in the admin key management system and allows authenticated users to perform actions they shouldn't be authorized to perform. An attacker who already has some level of access to the system could exploit this to modify or disrupt operations. The flaw has been publicly disclosed and patches are available.

  • CVE-2026-53847MEDIUM 5.4

    OpenClaw versions prior to 2026.5.6 contain a privilege escalation flaw affecting users with operator.write permissions. These users can bypass intended access controls to modify global configuration settings normally restricted to administrator-level accounts. The vulnerability stems from insufficient validation of permission scope boundaries, allowing write operations to affect system-wide settings beyond what the operator.write role should permit.

  • CVE-2026-10255MEDIUM 5.3

    A remote access control weakness exists in SourceCodester Pharmacy Sales and Inventory System version 1.0. An unauthenticated attacker can exploit the sell_statement function in the application's form controller to bypass authorization checks and gain unauthorized read access to sensitive pharmacy data. The vulnerability requires no special interaction from users and can be triggered over the network. Because exploit code has already been publicly disclosed, active exploitation risk is elevated.

  • CVE-2026-11497MEDIUM 5.3

    A vulnerability exists in D-Link DCS-5615 network camera firmware version 1.01.00 affecting the Boa web server configuration. An unauthenticated remote attacker can manipulate the web server settings to escalate privileges or modify system functionality without proper authorization. The vulnerability requires no special interaction from the user and can be exploited over the network. While the technical impact is bounded to integrity violations, the ability to alter web server configuration on a networked device introduces operational risk, particularly in environments where the camera serves as a network endpoint with security implications.

  • CVE-2026-11620MEDIUM 5.3

    TOTOLINK has released a vulnerability in the EX200 router (version 4.0.3c.7646) that allows an attacker to manipulate vsftpd configuration files remotely without authentication, potentially bypassing security restrictions. The flaw resides in how the device handles file permissions or access controls for the FTP service configuration, enabling an unauthenticated attacker over the network to make unauthorized changes that could weaken the router's security posture.

  • CVE-2026-12201MEDIUM 5.3

    IObit Malware Fighter versions up to 13.2.0 contain a flaw in its DLL Handler component that allows a local attacker with standard user privileges to gain elevated permissions or access sensitive system information. The vulnerability requires an attacker to be already logged into the system; it cannot be exploited remotely. An exploit has been publicly disclosed, increasing the risk of opportunistic attacks in environments where this software is deployed.

  • CVE-2026-12771MEDIUM 5.0

    BerriAI's litellm, a language model proxy library, contains an authorization flaw in its M2M (machine-to-machine) JWT authentication handler. An authenticated attacker can manipulate requests to bypass proper authorization checks, potentially gaining unauthorized access to protected functionality. This requires existing credentials and significant technical knowledge to exploit, though proof-of-concept code is publicly available.

  • CVE-2026-44173MEDIUM 5.0

    MariaDB server versions within specific ranges contain a privilege-escalation flaw that allows authenticated users to write files to the server's filesystem without possessing the FILE privilege. The vulnerability exists when SELECT statements direct output to files (using INTO OUTFILE or INTO DUMPFILE) and the FROM clause references only subqueries, bypassing the privilege check. An attacker with database login credentials but no explicit FILE permission can exploit this to write arbitrary content to disk, potentially compromising system integrity or enabling further attacks.

  • CVE-2026-10070MEDIUM 4.7

    A flaw in macrozheng mall versions up to 1.0.3 allows an authenticated administrator with high privileges to bypass authorization controls on the super admin password update endpoint. An attacker with admin credentials could manipulate requests to the /admin/update/ path and gain unauthorized access to sensitive administrative functions. The vulnerability requires valid admin-level authentication and cannot be exploited anonymously from the network.

  • CVE-2026-12164MEDIUM 4.4

    Fortra File Integrity Monitoring (FIM), the integrity monitoring solution formerly known as Tripwire Enterprise, contains a permission assignment flaw in its user import functionality. When administrators use the tetool import command to add users while FIM is actively running—especially if the import simultaneously creates or modifies roles and their associated permissions—the system may grant those imported users incorrect or overly permissive access rights. This means a user intended to have limited monitoring privileges could end up with elevated capabilities, creating an unintended privilege escalation within the FIM system itself.

  • CVE-2026-10215MEDIUM 4.3

    A flaw in Dolibarr ERP CRM's Leave Request REST API fails to properly check whether users have permission to access specific leave request objects. An authenticated attacker can remotely exploit this to view leave data they should not be able to see. The vulnerability affects versions up to 23.0.1, and Dolibarr has released version 23.0.2 as a fix. Because the exploit has been publicly disclosed, this poses an active risk despite its moderate CVSS score.

  • CVE-2026-10282MEDIUM 4.3

    Bottelet DaybydayCRM versions up to 2.2.1 contain an authorization flaw in the Documents controller that allows authenticated users to access files they shouldn't be able to view. An attacker with valid login credentials can exploit this remotely to read sensitive documents beyond their intended access scope. The vulnerability is rated MEDIUM severity and requires patching.

  • CVE-2026-10294MEDIUM 4.3

    PackageKit, a system library for package management on Linux, contains an authorization bypass vulnerability in versions up to 1.3.5. An authenticated attacker can manipulate the frontend-socket parameter in the API to gain unauthorized access to sensitive information. The vulnerability requires an existing user account to exploit but does not require user interaction. While the attack surface is somewhat limited by authentication requirements, the unauthorized information disclosure poses a real security concern for systems relying on PackageKit.

  • CVE-2026-11492MEDIUM 4.3

    A vulnerability in the D-Link DIR-823G router (firmware version 1.0.2B05) allows an authenticated attacker to modify the vsftpd configuration file in a way that violates least privilege protections. The flaw can be exploited remotely by someone with valid login credentials. While the barrier to entry requires authentication, the impact is a privilege escalation that could allow an attacker to exceed their intended access level on the device.

  • CVE-2026-11494MEDIUM 4.3

    A privilege escalation vulnerability has been discovered in TOTOLIK AC1200 T8 running firmware version 4.1.5cu.8611. The flaw resides in the vsftpd (Very Secure FTP Daemon) configuration file and allows an authenticated attacker to modify settings in a way that violates the principle of least privilege. While the vulnerability requires valid login credentials to exploit, successful attacks could lead to unauthorized configuration changes that broaden attacker capabilities on the device. Public disclosure of this issue means exploitation techniques are available in the wild.

  • CVE-2026-11554MEDIUM 4.3

    A privilege escalation weakness has been identified in TOTOLINK CP450 version 4.1.0cu.747 affecting the vsftpd FTP service configuration. An authenticated attacker can modify the /etc/vsftpd.conf file in a way that violates the principle of least privilege, potentially allowing them to expand their access or capabilities on the device. The vulnerability requires valid login credentials to exploit, but once leveraged, could enable unauthorized actions. Public details about this issue are already available, increasing the likelihood of active exploitation.

  • CVE-2026-12212MEDIUM 4.3

    A flaw in hcengineering's Huly Platform versions up to 0.7.0 allows authenticated users to access sensitive mailbox secrets they should not be able to read. The vulnerability resides in the RPC interface used to manage account operations and stems from weak access controls on a specific function. An attacker with valid credentials can exploit this remotely to view confidential data. Public disclosure has already occurred, and the vendor has not responded to early notification attempts.

  • CVE-2026-12213MEDIUM 4.3

    A flaw in hcengineering's Huly Platform allows authenticated users to view information about other user accounts they should not have access to. The vulnerability exists in the user information retrieval function and stems from insufficient permission checks. While the issue requires an attacker to already have login credentials, the simplicity of exploitation and public availability of details increase risk. The vendor has not responded to early disclosure attempts.

  • CVE-2026-12799MEDIUM 4.3

    BerriAI's litellm library contains an authorization flaw in its user management interface. An authenticated attacker can view unauthorized user information by exploiting an incomplete fix to a prior vulnerability. The issue affects versions up to 1.82.2 and requires valid credentials to exploit, limiting the immediate attack surface but posing a meaningful risk to multi-tenant deployments where user isolation is critical.

  • CVE-2026-53862MEDIUM 4.2

    OpenClaw versions before 2026.5.12 allow attackers to replay bootstrap tokens used during device pairing setup. An attacker who intercepts or obtains a pending bootstrap token can reuse it to request broader permissions than the token's original scope allowed, effectively escalating their access during the pairing process. This vulnerability requires the attacker to have network access and for a user to interact with the malicious request, but it can lead to unauthorized authority being granted to a paired device.

  • CVE-2026-11555LOW 3.7

    A privilege escalation vulnerability exists in D-Link's DGS-1100-08PD switch running firmware version 1.00.006. The issue resides in how the web interface processes the /etc/boa.conf configuration file, potentially allowing an attacker to modify system settings in ways that bypass normal access restrictions. While a public exploit exists, successful exploitation requires significant technical skill and specific conditions to align. The impact is limited to integrity violations—an attacker cannot read sensitive data or crash the device, only make unauthorized configuration changes.

  • CVE-2026-12823LOW 3.3

    A permissions misconfiguration vulnerability has been discovered in Browserbase Skills (versions up to 20260526) affecting the Autobrowse Trace Artifact Handler component. The flaw results in incorrect default access controls that could allow a local user to read sensitive information. This is a low-severity issue requiring local system access to exploit, and while proof-of-concept code has been publicly released, the practical risk remains limited due to its local-only attack vector and information-disclosure nature.