Improper Privilege Management

CWE-269 · 4 records · 0 with a public proof-of-concept

Records the NVD classes as Improper Privilege Management (CWE-269), highest CVSS first.

  1. HIGH 8.8CVE-2026-18322

    The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` ov

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 5.4CVE-2026-16071

    A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missin

    build of keycloak

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-64634

    A vulnerability allowing local privilege escalation to the Reporter service context.

    AI risk analysis on Exploit-DB.ai →

  4. UNSCOREDCVE-2026-18759

    The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by AES encryption. Because the encryption key file is readable by standard users and protected using DPAPI. Any a

    AI risk analysis on Exploit-DB.ai →