By weakness (CWE)

CWE-284: related vulnerabilities

CVEs classified under CWE-284. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

304 published vulnerabilities · page 1 of 4

  • CVE-2025-66391HIGH 8.8

    A vulnerability in Citrix Cloud allows users with read-only account permissions to initiate sensitive operations they should not be able to perform. Specifically, an attacker with read-only access can trigger password reset workflows and receive one-time passwords sent to attacker-controlled email addresses, effectively taking over user accounts. This represents a significant privilege escalation flaw where access controls fail to properly restrict who can initiate administrative workflows.

  • CVE-2025-71380HIGH 8.8

    n8n's Execute Command node permits authenticated users to run arbitrary operating system commands on the server hosting n8n. If an attacker gains user credentials or an insider abuse their access, they can invoke this node to execute malicious commands—potentially stealing data, disrupting services, or taking over the entire system. The vulnerability requires valid authentication but imposes no additional technical barriers once inside.

  • CVE-2026-11179HIGH 8.8

    Google Chrome versions before 149.0.7827.53 contain a flaw in the Object Request Broker (ORB) feature that allows attackers to bypass site isolation—a critical Chrome security boundary that prevents websites from accessing each other's data. An attacker can exploit this by hosting a malicious HTML page that, when visited by a user, breaks through site isolation and gains unauthorized access to sensitive information from other open tabs or windows. The vulnerability requires user interaction (visiting the crafted page) but demands no special privileges, making it a practical concern for any Chrome user.

  • CVE-2026-13897HIGH 8.8

    A flaw in how Google Chrome enforces security policies for Chromecast functionality allows attackers to trick users into visiting malicious web pages that escalate their browser privileges. The attacker gains access equivalent to the user's account, posing a direct risk to data and system integrity. This affects Chrome versions before 150.0.7871.47.

  • CVE-2026-35311HIGH 8.8

    Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.2.0.0 contain a vulnerability in the Core component that allows a low-privileged user with network access to take over the entire application server. The flaw is relatively easy to exploit and requires only HTTP access—no special conditions or user interaction needed. Once compromised, an attacker gains complete control over the WebLogic instance, including the ability to read, modify, or delete data and disrupt service availability.

  • CVE-2026-35315HIGH 8.8

    A critical vulnerability in Oracle WebCenter Content allows authenticated users with low-level network access to gain complete control over the content server. An attacker who already has valid credentials or can access the system via HTTP can exploit this flaw to read, modify, or delete data, and potentially disrupt service. The vulnerability affects two widely-deployed versions of the product: 12.2.1.4.0 and 14.1.2.0.0.

  • CVE-2026-35317HIGH 8.8

    Oracle WebCenter Content, a widely deployed content management system within Oracle Fusion Middleware, contains an improper access control vulnerability that allows an authenticated user with low privileges to gain complete control over the system. The attacker needs only standard network access and valid login credentials—no special interaction or user clicks required. Once exploited, the attacker can read sensitive data, modify or delete content, and disrupt service availability.

  • CVE-2026-35318HIGH 8.8

    Oracle WebCenter Sites, a content management platform, contains a privilege escalation vulnerability that allows low-privileged attackers with network access to gain full administrative control. An attacker with basic user credentials can exploit this flaw via HTTP to completely compromise the system, potentially accessing, modifying, or deleting sensitive content and disrupting service availability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0.

  • CVE-2026-35322HIGH 8.8

    A privilege escalation vulnerability exists in Oracle WebCenter Content that allows an authenticated user with basic network access to gain complete administrative control of the system. The vulnerability resides in the Content Server component and affects two recent versions of the product. An attacker who already has low-level user credentials can exploit this flaw without user interaction to compromise confidentiality, integrity, and availability of the entire WebCenter Content instance.

  • CVE-2026-35324HIGH 8.8

    A flaw in Oracle WebCenter Content allows authenticated users with basic network access to gain complete control over the system. An attacker who already has low-level login credentials can exploit this vulnerability to read sensitive data, modify content, and disrupt service availability. The vulnerability affects two specific versions of the software and is straightforward to exploit—no special techniques or user interaction required.

  • CVE-2026-35325HIGH 8.8

    Oracle WebCenter Content, a document and content management system used within Oracle Fusion Middleware, contains a privilege escalation vulnerability affecting versions 12.2.1.4.0 and 14.1.2.0.0. A logged-in user with basic access permissions can exploit this flaw over the network to gain unauthorized control of the entire Content Server instance, compromising data confidentiality, integrity, and availability. The vulnerability requires no user interaction and can be triggered through standard HTTP requests.

  • CVE-2026-46827HIGH 8.8

    CVE-2026-46827 is a high-severity vulnerability in Oracle E-Business Suite's Payroll module that allows a low-privileged network attacker to gain full control over the payroll system. An authenticated user with minimal permissions can exploit this flaw remotely via HTTP to read sensitive data, modify payroll records, or disrupt service availability. This represents a complete compromise of the affected payroll component.

  • CVE-2026-46864HIGH 8.8

    A flaw in Oracle Enterprise Manager Base Platform's Agent Next Gen component allows attackers with low-level network access to take over the entire management platform. An authenticated user with SSH access can exploit this issue to gain full control, compromising confidentiality, integrity, and availability of your Enterprise Manager environment. Versions 13.5 and 24.1 are affected. This is a high-severity issue that requires prompt attention.

  • CVE-2026-46886HIGH 8.8

    A high-severity vulnerability in Oracle Siebel CRM's Marketing application allows attackers with basic user credentials to gain complete control over the system without requiring user interaction. The flaw affects all currently supported versions (17.0 through 26.5) and is accessible over standard HTTP network connections. Successful exploitation results in full compromise—attackers can read sensitive data, modify records, and disrupt marketing operations.

  • CVE-2026-46916HIGH 8.8

    A high-severity flaw in Oracle's Process Manufacturing Product Development component (part of E-Business Suite) allows authenticated users with low-level network access to gain full control over the affected system. An attacker who has obtained basic credentials can exploit this over the network to read sensitive data, modify critical information, and disrupt operations without requiring user interaction. Versions 12.2.3 through 12.2.15 are vulnerable.

  • CVE-2026-46921HIGH 8.8

    A high-severity vulnerability exists in Oracle Siebel CRM Cloud Manager that allows a low-privileged attacker with network access to take over the entire application. The flaw affects Siebel CRM versions 17.0 through 26.5 and requires only standard HTTP access—no user interaction or elevated privileges needed beyond basic network authentication. Attackers exploiting this could gain full control over confidentiality, integrity, and availability of the system.

  • CVE-2026-46926HIGH 8.8

    Oracle Siebel CRM Cloud Applications contains a privilege escalation flaw in the Siebel Cloud Manager component that allows a low-privileged local user to gain complete control over the CRM system. An attacker already logged into the infrastructure where Siebel runs can exploit this vulnerability without further user interaction to compromise confidentiality, integrity, and availability of the application and potentially adjacent systems.

  • CVE-2026-46929HIGH 8.8

    CVE-2026-46929 is a high-severity vulnerability in Oracle's Cost Management component within Oracle E-Business Suite (versions 12.2.3 through 12.2.15). An attacker with a low-level user account and network access can exploit this flaw via HTTP to gain complete control over the Cost Management system. The vulnerability requires no user interaction, making it straightforward to exploit. Successful exploitation allows attackers to read sensitive data, modify cost planning information, and disrupt system availability.

  • CVE-2026-46931HIGH 8.8

    A flaw in Oracle Enterprise Asset Management (part of Oracle E-Business Suite) allows someone with low-level access to the system to gain complete control over it through the network. The attacker needs basic user credentials to exploit this, and no additional interaction is required. Once successful, they can read, modify, or destroy data, or take the system offline. This affects versions 12.2.6 through 12.2.15.

  • CVE-2026-46940HIGH 8.8

    CVE-2026-46940 is a critical vulnerability in Oracle Cost Management, a component of Oracle E-Business Suite. An attacker with a low-level user account and network access can exploit this flaw to take over the entire Cost Management system. The vulnerability is network-accessible, does not require user interaction, and can compromise confidentiality, integrity, and availability of the affected system. Organizations running Oracle E-Business Suite versions 12.2.3 through 12.2.15 should treat this as an urgent security matter.

  • CVE-2026-46942HIGH 8.8

    A vulnerability in Oracle's Process Manufacturing Process Planning component allows attackers with low-level network access to take over the system. The flaw affects versions 12.2.3 through 12.2.15 of the Oracle E-Business Suite module and requires an attacker to have valid user credentials, but no special privileges or user interaction. Once exploited, an attacker gains complete control over the affected application, compromising all data confidentiality, system integrity, and availability.

  • CVE-2026-46947HIGH 8.8

    Oracle Advanced Outbound Telephony, a component within Oracle E-Business Suite versions 12.2.3 through 12.2.15, contains a network-accessible vulnerability that allows authenticated users with low-level privileges to gain unauthorized control over the system. An attacker with valid credentials can exploit this flaw remotely via HTTP without user interaction, leading to complete system compromise—affecting confidentiality, integrity, and availability of the telephony system.

  • CVE-2026-46950HIGH 8.8

    Oracle Advanced Outbound Telephony, a component within Oracle E-Business Suite, contains a vulnerability that allows an authenticated attacker with basic user privileges to remotely compromise the system over HTTP. The flaw is straightforward to exploit and grants attackers complete control—the ability to read sensitive data, modify configurations, and disrupt service availability. Organizations running affected versions (12.2.3 through 12.2.15) should treat this as a priority remediation target.

  • CVE-2026-46965HIGH 8.8

    A critical vulnerability in Oracle Universal Work Queue—a component of Oracle E-Business Suite—allows a low-privileged user with network access to take complete control of the Work Provider Site Level Administration functions. The attacker needs only basic network connectivity and low-level credentials; no special interaction or advanced attack techniques are required. Once exploited, an attacker can read, modify, and delete data, as well as disrupt system availability.

  • CVE-2026-46967HIGH 8.8

    A flaw in Oracle's Public Sector Financials (International) module, part of E-Business Suite, allows an authenticated attacker with basic network access to gain complete control over the application. The vulnerability exists in how the system handles user permissions and can be exploited without requiring user interaction. Attackers could read sensitive data, modify records, or disrupt service availability.

  • CVE-2026-48948HIGH 8.8

    A Joomla vulnerability allows authenticated users to bypass access controls and download contact card (vcard) exports for contacts they should not be able to access. An attacker with a user account can exploit this to retrieve sensitive contact information that has been restricted by administrators, potentially exposing personal data, organizational structures, or confidential contact details.

  • CVE-2026-48958HIGH 8.8

    A vulnerability in Joomla's webservices functionality allows authenticated users to bypass access controls and create custom fields they shouldn't have permission to modify. An attacker with valid user credentials can exploit this to inject unauthorized fields into the system, potentially altering application behavior or exfiltrating sensitive information. The flaw stems from improper validation of user permissions before allowing field creation through the API.

  • CVE-2026-50884HIGH 8.8

    A privilege escalation vulnerability exists in statping-ng version 0.93.0 where a logged-in user can gain unauthorized Administrator-level access due to improper access control checks. An attacker with basic user credentials can exploit this flaw to bypass intended permission restrictions and access sensitive application components that should be restricted to administrators only.

  • CVE-2026-5228HIGH 8.8

    WriteUp Mobile App versions 1.3.0 through 04062026 contain an access control flaw that allows authenticated users to perform actions they should not have permission to execute. An attacker with legitimate credentials can bypass the application's authorization checks to access or modify restricted functionality. This is a post-authentication vulnerability—the attacker must have a valid account, but once logged in, the broken permission system fails to prevent unauthorized operations.

  • CVE-2026-55114HIGH 8.8

    CVE-2026-55114 is a privilege escalation flaw in Ubiquiti's UniFi Network Application that allows an authenticated attacker with low-level permissions to gain higher privileges within the application. An attacker already present on the network can exploit weak access controls to expand their capabilities and potentially compromise network infrastructure management.

  • CVE-2026-9085HIGH 8.8

    CVE-2026-9085 is a permission and access control flaw in Pardus-Parental-Control (version 0.5.1 and earlier) that allows a local attacker to perform DNS spoofing attacks. Because the software incorrectly assigns permissions to security-critical resources, an attacker with basic local user access can manipulate DNS resolution on the affected system, redirecting network traffic to malicious destinations. This is particularly concerning in environments where Pardus-Parental-Control is deployed to manage network access or security policies.

  • CVE-2026-9614HIGH 8.8

    Ivanti Neurons for ITSM contains an access control flaw that lets a logged-in user escalate their privileges to admin level. This affects both cloud and on-premises deployments. An attacker who already has valid credentials can exploit this to gain full administrative control without needing to bypass additional authentication steps.

  • CVE-2026-35271HIGH 8.7

    CVE-2026-35271 is a network-accessible vulnerability in Oracle PeopleSoft Enterprise PT PeopleTools (versions 8.61 and 8.62) that allows an unauthenticated attacker to read, modify, or delete sensitive data without authentication. The vulnerability resides in the WebLogic component and is considered difficult to exploit, but successful attacks can compromise both PeopleSoft data and potentially impact other connected systems. The flaw carries a CVSS score of 8.7 (High severity) due to its potential for unauthorized access to critical information.

  • CVE-2026-46808HIGH 8.7

    Oracle WebCenter Content version 14.1.2.0.0 contains a privilege-escalation vulnerability accessible over the network that allows attackers with low-level credentials to manipulate or steal sensitive data. The attack requires tricking another user into performing an action (such as clicking a link or opening a file), but once successful, an attacker can read, modify, or delete critical information stored in WebCenter Content or connected systems. The flaw affects authorization controls rather than availability, meaning systems remain operational but security is compromised.

  • CVE-2026-46776HIGH 8.6

    Oracle Unified Directory, a directory service component in Oracle Fusion Middleware, contains a network-accessible vulnerability that allows attackers without credentials to read, modify, or delete sensitive directory data. An attacker on the network can exploit this flaw via the LDAP protocol to gain unauthorized access to critical configuration and user information, with limited ability to disrupt service. The vulnerability affects two specific versions: 12.2.1.4.0 and 14.1.2.1.0.

  • CVE-2026-47907HIGH 8.6

    Adobe Dreamweaver Desktop versions 21.7 and earlier contain a flaw that allows an attacker to run malicious code on a victim's computer. The vulnerability exists because Dreamweaver does not properly restrict access to certain functions. An attacker must trick a user into opening a specially crafted file—Dreamweaver itself will not automatically trigger the issue. Once exploited, the attacker gains the ability to execute code with the same permissions as the user running Dreamweaver, potentially compromising sensitive projects, credentials stored locally, or the broader system.

  • CVE-2026-54407HIGH 8.6

    UniFi Protect Application contains an authentication bypass vulnerability that allows an attacker with network access to circumvent login controls on certain API endpoints. An unauthenticated attacker on the network can reach these endpoints and perform unauthorized actions without valid credentials, potentially affecting the confidentiality, integrity, and availability of protected systems.

  • CVE-2026-54408HIGH 8.6

    CVE-2026-54408 is a network-based authentication bypass flaw in UniFi Protect that allows an attacker with network access to stream video data without providing valid credentials. The vulnerability stems from improper access control logic and carries a CVSS score of 8.6 (HIGH severity). While an attacker cannot modify system configuration or cause denial of service at scale, the ability to intercept sensitive surveillance footage represents a significant confidentiality breach for organizations relying on UniFi Protect for physical security monitoring.

  • CVE-2026-7862HIGH 8.6

    A flaw in the Eupago Gateway For WooCommerce plugin (versions before 4.7.2) allows anyone on the internet to process refunds on any order without logging in. Attackers can exploit this to steal money by redirecting refunds to accounts they control. The vulnerability stems from missing access controls on the refund handler.

  • CVE-2026-46820HIGH 8.5

    A vulnerability in Oracle Financials Common Modules allows attackers with basic user credentials to gain unauthorized access to sensitive financial data. An attacker with low-level access and network connectivity can trigger a flaw that lets them read critical data, modify records, or access information across multiple Oracle E-Business Suite systems. This is particularly dangerous because it requires no additional tricks or user interaction—just ordinary network access. The vulnerability affects Oracle Financials versions 12.2.3 through 12.2.15 and poses a material risk to organizations storing financial records in Oracle systems.

  • CVE-2026-46870HIGH 8.5

    CVE-2026-46870 is a privilege escalation and system compromise vulnerability in Oracle MySQL Shell for VS Code (version 2026.2.0+9.6.1). An attacker with low-level network access and basic system credentials can exploit this issue through multiple network protocols to gain full control over the MySQL Shell application. The vulnerability is difficult to exploit but has severe impact: successful attacks lead to complete compromise of confidentiality, integrity, and availability. Critically, compromising MySQL Shell can enable attacks on other systems it connects to or manages, expanding the blast radius beyond the tool itself.

  • CVE-2026-46915HIGH 8.5

    Oracle's Complex Maintenance, Repair and Overhaul (CMRO) component within E-Business Suite contains a privilege escalation vulnerability that allows attackers with low-level network access to compromise the system. An attacker would need valid credentials or low privileges to initiate an attack via HTTP, but exploitation is complex and not trivial. If successful, the attacker could gain complete control over CMRO and potentially affect other connected Oracle systems due to the scope change.

  • CVE-2026-49824HIGH 8.5

    Fission, an open-source serverless framework for Kubernetes, contains a namespace validation gap in its Function admission webhook. The webhook correctly validates that Secrets and ConfigMaps referenced by a function must belong to the same namespace as the function itself—a security boundary enforcement mechanism. However, it failed to apply the same check to environment specifications, allowing authenticated users to reference environments from other namespaces. This cross-namespace access could enable privilege escalation or unauthorized data exposure in multi-tenant Kubernetes clusters. The issue affects all versions prior to 1.24.0.

  • CVE-2026-54765HIGH 8.5

    Traefik versions 3.7.0 through 3.7.5 contain a filter application bug in the Kubernetes Gateway API provider that can cause requests intended for one HTTPRoute to be processed using a different route's security filters. An attacker with the ability to create HTTPRoutes in a Kubernetes cluster can exploit this to apply their own filter rules (such as injected headers) to legitimate traffic, potentially escalating privileges or accessing data they shouldn't see. The vulnerability requires existing cluster access but can cross namespace boundaries if ReferenceGrants permit it.

  • CVE-2026-46788HIGH 8.4

    A vulnerability in Oracle WebCenter Content version 14.1.2.0.0 allows an attacker with administrative privileges to compromise the system through specially crafted HTTP requests. The vulnerability requires an administrator to interact with malicious content, but once exploited, can lead to complete control of the WebCenter Content instance. Because WebCenter Content often integrates with other enterprise systems, a successful attack may cascade to affect additional products in your Oracle Fusion Middleware environment.

  • CVE-2026-35262HIGH 8.3

    A vulnerability in Oracle Data Integrator (part of Oracle Fusion Middleware) allows authenticated users on a network to read, modify, or delete sensitive data within the application, and potentially disrupt service. The flaw requires valid credentials but no special privileges—any legitimate user account can trigger it. An attacker with low-level access could escalate impact to critical data loss or unauthorized viewing of all accessible information.

  • CVE-2026-46925HIGH 8.3

    A vulnerability exists in Oracle Siebel CRM Cloud Applications (versions 17.0 through 26.5) that allows an unauthenticated attacker with physical access to the network segment where the application runs to take over the system entirely. While the flaw is in Siebel itself, successful exploitation can impact other connected systems. The attack is difficult to execute in practice, but if successful, gives an attacker complete control over confidentiality, integrity, and availability of the application.

  • CVE-2026-54010HIGH 8.3

    Open WebUI, a self-hosted AI platform, contains a privilege escalation vulnerability that allows authenticated users to access files they should not have permission to read or delete. An attacker can attach file references to their own chat messages without validation, then share that chat to gain unauthorized access to those files. This affects versions prior to 0.9.6 and has been patched in the latest release.

  • CVE-2026-55118HIGH 8.3

    CVE-2026-55118 is a privilege escalation vulnerability in Ubiquiti's UniFi Network Application. An attacker who already has network access and low-level privileges can exploit an access control flaw to gain elevated permissions within the application. The vulnerability requires the attacker to already be authenticated or have network-level presence, limiting the scope somewhat, but the impact of successful exploitation is severe—attackers could modify network settings, access sensitive data, or disrupt network operations.

  • CVE-2026-46865HIGH 8.2

    Oracle Enterprise Manager Base Platform contains a privilege escalation vulnerability in its Extensibility Framework that allows a high-privileged local user to gain complete control over the platform. The flaw affects versions 13.5 and 24.1, and successful exploitation can lead to full system compromise. Because Enterprise Manager often serves as a central management hub, an attack could cascade to compromise other managed infrastructure and systems.

  • CVE-2026-58525HIGH 8.2

    Microsoft Edge (Chromium-based) contains a flaw that allows attackers to bypass a security feature through network-based attack vectors. An attacker can exploit this weakness to gain unauthorized access to protected functionality, potentially compromising user confidentiality. The vulnerability requires user interaction to trigger, but once activated, impacts extend beyond the individual browser instance.

  • CVE-2025-45422HIGH 8.1

    A Proximus b-box v8c.725A router contains a flaw that allows authenticated users to modify port forwarding rules beyond their intended scope. An attacker with valid credentials—such as a compromised admin account or an insider—can reconfigure port forwarding to redirect network traffic, enabling unauthorized access to services or lateral movement within a network. This is not a remotely-exploitable flaw from the internet; you must already have user-level access to the device.

  • CVE-2026-13864HIGH 8.1

    A flaw in Google Chrome's WebHID (Web Hardware Interface Device) policy enforcement allows attackers to escalate their privileges if they can trick a user into installing a malicious browser extension. While the attack requires social engineering—convincing someone to install the extension—the underlying technical weakness is significant because it bypasses Chrome's normally strict security boundaries around hardware access. Once installed, the extension gains the ability to interact with USB and other hardware devices in ways that shouldn't be possible, effectively elevating its capabilities beyond what the user intended to grant.

  • CVE-2026-22555HIGH 8.1

    Gitea, a self-hosted Git service, contains an authorization bypass flaw affecting versions before 1.26.0. Authenticated users can fork a repository into an organization they do not have explicit permission to create repositories within, circumventing a critical access control check. This bypass allows attackers to expose organization secrets that would normally be protected. The vulnerability requires an existing user account but poses significant risk to organizations relying on Gitea for internal code hosting and secret management.

  • CVE-2026-28699HIGH 8.1

    Gitea, a self-hosted Git service, has a critical flaw in how it enforces API permissions for OAuth2 applications. When someone logs in using HTTP Basic authentication (username and password), the system fails to respect the restricted access scopes that should apply to OAuth2 tokens. This means an attacker with a compromised user account or valid credentials could use HTTP Basic auth to perform actions that an OAuth2 application was explicitly forbidden from doing, such as modifying repositories or accessing sensitive information.

  • CVE-2026-35277HIGH 8.1

    Oracle REST Data Services contains a flaw that allows authenticated users with basic network access to read and modify sensitive data they shouldn't be able to access. An attacker with a low-privilege account can exploit this remotely without user interaction, potentially accessing, changing, or deleting critical information across the service. This is a significant risk because it bypasses normal data access controls.

  • CVE-2026-36720HIGH 8.1

    Bookcars version 8.3 contains a privilege escalation vulnerability that allows logged-in users to upgrade their account to administrator status by manipulating their user type settings. An attacker who has obtained valid credentials—whether through compromise, social engineering, or as a legitimate user—can exploit weak permission controls to gain full administrative access to the system without requiring additional authentication or authorization checks.

  • CVE-2026-42863HIGH 8.1

    FlowiseAI versions prior to 3.1.2 contain a mass assignment vulnerability in their chatflow update feature. An authenticated user can modify internal system properties—such as workspace assignment, deployment status, and visibility settings—that should only be controlled by administrators. This allows attackers to reassign workflows to other workspaces, change deployment states without authorization, and alter public/private visibility of chatflows. The vulnerability requires valid login credentials but no additional special access.

  • CVE-2026-44249HIGH 8.1

    Netty is a widely-used Java networking framework that powers many protocol servers and clients. A flaw in how it filters IPv6 traffic has been discovered: the masking logic in the IPv6 subnet filtering rules is broken, allowing attackers to craft IP addresses that appear to bypass intended network access controls. If your application relies on Netty to restrict traffic to specific IPv6 subnets, an attacker could send requests from addresses that should have been blocked, potentially gaining unauthorized access to protected services.

  • CVE-2026-45178HIGH 8.1

    Idira Secrets Manager Self-Hosted versions 13.8.0 and earlier contain a flaw that allows authenticated users with basic node-level credentials to access internal cluster communication channels they shouldn't be able to reach. An attacker with valid login credentials could exploit these unsecured endpoints to steal secrets stored in the system or disrupt its availability. The vulnerability requires prior authentication, so it represents an insider or compromised-credential risk rather than an unauthenticated attack vector.

  • CVE-2026-45707HIGH 8.1

    n8n-MCP is a server component that bridges AI assistants to n8n automation workflows. In multi-tenant deployments (where one operator hosts multiple customer accounts), versions before 2.51.2 had a critical credential-handling flaw: when requests lacked the headers specifying which tenant's n8n instance to target, the system fell back to the operator's own administrative credentials instead of rejecting the request or requiring proper tenant identification. An authenticated user in one tenant could exploit this to execute operations against the operator's primary n8n instance, potentially compromising the entire service.

  • CVE-2026-46828HIGH 8.1

    A vulnerability in Oracle Payroll (part of Oracle E-Business Suite) allows a low-privileged user with network access to read sensitive payroll data and make unauthorized changes to it. An attacker who already has valid credentials to the system—or gains them through other means—can exploit this flaw via HTTP requests to view or alter critical employee and compensation information. This is not a vulnerability requiring special technical skill or complex exploitation chains, making it a realistic risk for organizations running affected versions.

  • CVE-2026-46849HIGH 8.1

    A security flaw in Oracle PeopleSoft Enterprise CS Student Financials version 9.2.38 allows someone with basic user credentials and network access to read, modify, or delete financial records they shouldn't be able to touch. The vulnerability requires an attacker to have valid login credentials but does not require any user interaction—once authenticated, the attacker can exploit it directly. This puts sensitive student financial data at significant risk.

  • CVE-2026-46891HIGH 8.1

    A vulnerability in Oracle JD Edwards EnterpriseOne Accounts Payable version 9.2 allows a low-privileged, authenticated user with network access to read, create, modify, or delete critical financial data without authorization. The attacker needs valid login credentials and can exploit the flaw via standard HTTP connections. The vulnerability primarily affects data confidentiality and integrity, making it a significant risk for organizations relying on JD Edwards for accounts payable operations.

  • CVE-2026-46898HIGH 8.1

    Oracle Enterprise Command Center Framework versions 15 and 16 contain a vulnerability that allows an unauthenticated attacker to gain unauthorized access to sensitive data or modify critical information through a network-based attack over HTTPS. The attack requires tricking a user into taking an action, but the attacker themselves does not need valid credentials. Once successful, an attacker can read, create, delete, or modify data depending on what the compromised user can access within the framework.

  • CVE-2026-46920HIGH 8.1

    A vulnerability in Oracle's Siebel CRM Cloud Manager allows an unauthenticated attacker with network access to take over a Siebel CRM Cloud Applications deployment. The attack requires some specific conditions to be met (high attack complexity) but does not require user interaction or valid credentials. If successfully exploited, an attacker gains full control over confidentiality, integrity, and availability of the affected CRM system. Versions 17.0 through 26.5 are vulnerable.

  • CVE-2026-46927HIGH 8.1

    Oracle Receivables, a core component of Oracle E-Business Suite, contains a network-accessible vulnerability in versions 12.2.3 through 12.2.15 that allows an unauthenticated attacker to remotely compromise the system. The vulnerability is exposed via SOAP web services and, if successfully exploited, grants an attacker full control over the Receivables application—potentially enabling them to read, modify, or destroy critical financial data. The attack requires specific conditions to be met (high attack complexity), but the absence of authentication requirements and the severity of potential impact make this a significant security concern for organizations running affected versions.

  • CVE-2026-46939HIGH 8.1

    A vulnerability exists in Oracle's Configure to Order product, a component of Oracle E-Business Suite used for managing complex product configurations and orders. An attacker with basic user credentials and network access can exploit this flaw to read sensitive data, create unauthorized records, modify existing data, or delete information—all without requiring user interaction or special technical conditions. The vulnerability affects versions 12.2.3 through 12.2.15 and carries a CVSS score of 8.1, reflecting significant risk to data confidentiality and integrity.

  • CVE-2026-48610HIGH 8.1

    A vulnerability in UniFi OS devices allows attackers on the network to make unauthorized changes to affected devices due to improper access controls. Under specific network configurations, an attacker doesn't need valid credentials to modify device settings—a significant risk for organizations relying on UniFi infrastructure for network management and security.

  • CVE-2026-50875HIGH 8.1

    Deck9 Input v2.0.1 contains a flaw in how it controls access to webhook management endpoints. An attacker with valid credentials to one tenant account can craft requests to modify or delete webhooks belonging to a different tenant. This cross-tenant privilege escalation allows unauthorized tampering with webhook configurations—potentially redirecting data flows, disabling integrations, or causing service disruption—without requiring administrative access or special exploitation techniques.

  • CVE-2026-50881HIGH 8.1

    Bonsai v6.0 contains a privilege escalation vulnerability that allows authenticated users with Editor-level permissions to gain full Administrator access. Once escalated, attackers can make unauthorized changes to accounts, passwords, and system configurations. The vulnerability requires an attacker to already have valid Editor credentials, but no additional user interaction is needed to exploit it.

  • CVE-2026-50891HIGH 8.1

    Filestash v0.4.0 contains an access control vulnerability in its admin configuration API endpoint that allows authenticated users to escalate their privileges beyond their intended permission level. An attacker with valid login credentials can craft a specially formed request to /admin/api/config to gain elevated privileges, potentially accessing or modifying sensitive system settings reserved for administrators.

  • CVE-2026-55119HIGH 8.1

    A vulnerability in Ubiquiti's UniFi Talk Application allows an attacker with basic network access and low-level user privileges to gain higher privileges within the application. An attacker would need to be authenticated to the network and application first, but once in, they can escalate their access level without additional user interaction. This type of privilege escalation is particularly concerning in enterprise environments where applications manage critical communications infrastructure.

  • CVE-2026-58282HIGH 8.1

    Microsoft Edge (Chromium-based) contains an access control flaw that allows attackers to spoof content over the network. An attacker does not need credentials or special privilege to exploit this vulnerability, though successful attacks require specific technical conditions to be met. The primary risk is that an attacker could impersonate trusted websites or services, potentially deceiving users into trusting malicious content.

  • CVE-2026-58286HIGH 8.1

    Microsoft Edge (Chromium-based) contains an access control flaw that allows attackers to spoof content or identity over the network without requiring user interaction or special privileges. The attacker must overcome some technical barriers to exploit it, but once successful, the impact on system integrity is significant. This is a HIGH severity issue affecting confidentiality, integrity, and availability across network boundaries.

  • CVE-2026-8147HIGH 8.1

    MLflow, a popular machine learning tracking and versioning platform, has a critical authorization bypass vulnerability in its trace API endpoints. When authentication is enabled, authenticated users can access, modify, or delete machine learning experiment traces they shouldn't be able to see—essentially breaking the permission boundaries that organizations set up to isolate experiments. An attacker with any valid login can read sensitive training data, destroy audit records, or tamper with experiment metadata across the entire platform. The flaw stems from missing authorization checks in the trace API handler, allowing requests to skip permission validation entirely.

  • CVE-2026-45654HIGH 7.9

    Windows Secure Boot, a critical firmware-level security mechanism, contains an access control flaw that allows a high-privileged local attacker to circumvent its protections. Secure Boot is designed to ensure that only trusted code runs during system startup; this vulnerability permits an authorized user with administrative or equivalent rights to bypass those protections, potentially allowing unsigned or malicious code to execute at boot time. The issue affects recent Windows 11 versions and Windows Server 2025.

  • CVE-2026-46848HIGH 7.9

    Oracle WebLogic Server contains a privilege escalation vulnerability in its Console component that allows a low-privileged, authenticated attacker with local access to the server to compromise the system and gain unauthorized access to sensitive data. The attack requires trick a different user into taking an action, but once successful, can lead to disclosure or modification of critical information accessible through WebLogic. The vulnerability affects WebLogic Server versions 14.1.2.0.0 and 15.1.1.0.0.

  • CVE-2026-48578HIGH 7.9

    CVE-2026-48578 is a privilege escalation flaw in Windows Secure Boot affecting Windows 10 and 11 across multiple versions, as well as Windows Server 2012 through 2025. An attacker who already has administrative credentials on a system can exploit improper access controls to gain elevated privileges, potentially affecting system integrity and confidentiality. The vulnerability requires the attacker to be locally present and authenticated, but does not require user interaction to exploit. This is not currently listed in CISA's Known Exploited Vulnerabilities catalog.

  • CVE-2025-22426HIGH 7.8

    CVE-2025-22426 is a privilege escalation vulnerability in Android's ComputerEngine component that allows a local attacker with basic user-level access to bypass security boundaries and access resources (URIs) belonging to other users on the same device. The flaw stems from a logic error in multiple functions within ComputerEngine.java that fails to properly enforce cross-user access controls. An attacker needs only local access to the device and their own user account—no special permissions or user interaction required—making this a straightforward path to elevated privileges.

  • CVE-2026-12778HIGH 7.8

    A privilege escalation flaw exists in AOMEI Partition Assistant version 10.10.1 and earlier, affecting the ampa10.sys kernel driver. An authenticated local attacker can exploit improper access controls in the driver to gain elevated system privileges, potentially compromising the entire system. The vulnerability has been publicly disclosed, and exploit code may be in circulation. The vendor has not responded to early disclosure attempts.

  • CVE-2026-12779HIGH 7.8

    AOMEI Dynamic Disk Manager versions up to 10.10.1 contain a privilege escalation vulnerability in the ddmdrv.sys kernel driver that allows a locally authenticated attacker to bypass access controls and gain elevated privileges on the system. An attacker with user-level access can manipulate the kernel driver to achieve high-impact unauthorized actions. The vendor has not responded to early disclosure efforts, and exploit code is publicly available.

  • CVE-2026-12780HIGH 7.8

    AOMEI Backupper, a widely-used backup and disaster recovery application, contains a kernel driver vulnerability that allows local attackers with user-level privileges to bypass access controls and gain elevated capabilities on affected systems. The flaw resides in the amwrtdrv.sys driver and requires an attacker to already have local access to the machine. Public exploit code exists, and the vendor has not responded to early disclosure attempts.

  • CVE-2026-12781HIGH 7.8

    EaseUS Partition Master versions up to 14.5 contain a kernel driver vulnerability that allows authenticated local users to bypass security controls and gain elevated privileges. An attacker with legitimate access to a system running the affected software can exploit an improper access control flaw in the epmntdrv.sys driver to read, modify, or disrupt system functionality. The vendor has confirmed the issue only existed in older versions and has been resolved in current releases.

  • CVE-2026-12782HIGH 7.8

    EaseUS Partition Master versions up to 14.5 contain a kernel driver vulnerability that allows local users with standard privileges to gain elevated system access and control over disk partitioning functions. The flaw stems from improper access controls in the EUEDKEPM.sys driver. Because exploit code is publicly available, this vulnerability poses an active risk to organizations running older versions of the software. The vendor has confirmed the issue is resolved in current releases.

  • CVE-2026-12784HIGH 7.8

    IM-Magic Partition Resizer versions up to 7.9.0 contain a security flaw in its kernel driver (MDA_NTDRV.sys) that fails to properly enforce access controls. An attacker with local system access could exploit this weakness to gain elevated privileges or interfere with system integrity. Public exploit code now exists, elevating the practical risk. The vendor has not responded to early disclosure attempts, leaving affected users without an official patch.

  • CVE-2026-12786HIGH 7.8

    Ezbsystems UltraISO Premium Edition versions up to 9.76 contain a vulnerability in a kernel driver (bootpt64.sys) that fails to enforce proper access controls. An attacker with local system access can exploit this weakness to gain elevated privileges and potentially read, modify, or delete sensitive data on the affected system. The vulnerability has been publicly disclosed, and while the vendor was notified early, they have not provided a response or patch.

  • CVE-2026-13800HIGH 7.8

    Google Chrome on Windows has a flaw in its automatic updater that allows a local attacker to gain elevated system privileges by tricking a user into opening a malicious file. The vulnerability requires the attacker already has local system access and user interaction (such as opening a file), but once triggered, it can lead to complete system compromise. This is a high-severity issue affecting Chrome versions prior to 150.0.7871.47.

  • CVE-2026-40715HIGH 7.8

    Dell ThinOS 10 versions before 2602_10.0765 contain an access control flaw that allows a user with basic system access to gain elevated administrative privileges. An attacker already on the system as a regular user could leverage this vulnerability to take full control, making it a critical privilege escalation risk for any organization relying on ThinOS-based thin clients or endpoints.

  • CVE-2026-41092HIGH 7.8

    A flaw in Microsoft Kinect's access control allows someone who already has local user access to a Windows machine to elevate their privileges to a higher level of system access. This is a local-only attack that requires an attacker to have an existing account on the target system; it cannot be exploited remotely. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server platforms.

  • CVE-2026-42829HIGH 7.8

    CVE-2026-42829 is a local privilege escalation vulnerability affecting Windows 11 across multiple update versions. An authenticated user with standard privileges can bypass Windows Administrator Protection—a security boundary designed to restrict administrative actions—through improper access control handling. Exploitation requires local system access and valid credentials, but does not require user interaction. The vulnerability grants an attacker full system-level permissions including read, modify, and delete capabilities.

  • CVE-2026-45658HIGH 7.8

    A flaw in Windows BitLocker's access controls allows someone with local system access to circumvent the encryption security feature. An authorized user—such as an administrator or service account—can exploit this weakness to bypass BitLocker protections without requiring additional authentication or user interaction. This is a local-only attack and does not grant network-based access, but it significantly weakens the confidentiality and integrity guarantees that BitLocker is meant to provide.

  • CVE-2026-46461HIGH 7.8

    Dell Server Hardware Manager versions before 3.2.2 contain an access control flaw that allows a low-privileged user with local system access to escalate their privileges to a higher level. An attacker with a basic user account on the affected server could gain elevated permissions, potentially compromising the confidentiality, integrity, and availability of server operations and data.

  • CVE-2026-46733HIGH 7.8

    Dell Display and Peripheral Manager (DDPM) for Windows versions before 2.3 has an access control flaw that allows a user with basic local system access to run arbitrary code. An attacker would need to already have a foothold on the machine—either through a standard user account or through physical access—but once present, they could escalate their privileges and take full control of the system. This is a post-compromise risk rather than a worm-like threat.

  • CVE-2026-46888HIGH 7.8

    A privilege escalation vulnerability exists in Oracle Siebel CRM Deployment affecting versions 17.0 through 26.5. A low-privileged user with local access to the infrastructure running Siebel CRM Deployment can exploit this flaw in the Database Upgrade component to gain full control of the system. The vulnerability requires only basic system access and no user interaction to exploit, making it a meaningful risk for organizations that haven't properly restricted local access to their Siebel infrastructure.

  • CVE-2026-49161HIGH 7.8

    Microsoft PC Manager contains an access control weakness that allows a logged-in attacker to circumvent a built-in security control on the local system. The flaw does not require user interaction and grants an attacker with standard user privileges the ability to read sensitive data, modify system settings, or disable protective features.

  • CVE-2026-45296HIGH 7.7

    OpenReplay, a self-hosted session replay platform, contains a multi-tenant authorization bypass that allows attackers with valid API credentials for one tenant to access another tenant's sensitive session data. The vulnerability exists because the API does not verify that an API key and requested project belong to the same tenant—it only confirms the API key is valid and the project exists. Since project IDs are exposed in browser-side code, an attacker can discover victim project identifiers and exploit this flaw to enumerate user sessions and extract sensitive event details across tenant boundaries. This is a critical tenant isolation failure that affects confidentiality.

  • CVE-2026-46821HIGH 7.7

    CVE-2026-46821 is a high-severity flaw in Oracle Financials Common Modules that allows a low-privileged attacker with network access to view sensitive financial data without authorization. The vulnerability exists in Oracle E-Business Suite versions 12.2.3 through 12.2.15 and can be exploited via standard HTTP requests. What makes this particularly concerning is that while the defect lives in the Common Modules component, successful exploitation can grant attackers access to confidential information across multiple interconnected Oracle applications, expanding the blast radius beyond a single product.

  • CVE-2026-49822HIGH 7.7

    A vulnerability in Fission, an open-source serverless framework for Kubernetes, allows low-privilege developers to spy on activity in other namespaces. Specifically, a developer with limited access who can create a KubernetesWatchTrigger (KWT) in their own namespace can exploit this to establish unauthorized monitoring of unrelated namespaces. This violates namespace isolation, a core security boundary in Kubernetes. The issue has been patched in version 1.24.0.

  • CVE-2026-49823HIGH 7.7

    Fission, an open-source serverless framework for Kubernetes, contains a namespace isolation bypass in versions prior to 1.24.0. When defining Fission Functions, administrators can reference Secrets, ConfigMaps, and Packages. The admission webhook—a Kubernetes security control—validated namespace boundaries for Secrets and ConfigMaps but failed to validate the namespace referenced in PackageRef. This gap allows an authenticated user in one namespace to access packages from other namespaces, violating expected isolation. Version 1.24.0 patches this validation gap.