Improper Privilege Management
CWE-269 · 4 records · 0 with a public proof-of-concept
Records the NVD classes as Improper Privilege Management (CWE-269), highest CVSS first.
- HIGH 8.8CVE-2026-18322
The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` ov…
- MEDIUM 5.4CVE-2026-16071
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missin…
build of keycloak
- UNSCOREDCVE-2026-64634
A vulnerability allowing local privilege escalation to the Reporter service context.
- UNSCOREDCVE-2026-18759
The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by AES encryption. Because the encryption key file is readable by standard users and protected using DPAPI. Any a…