Security Risk Category

Privilege Escalation Security Risks — Page 3

Published vulnerability pages connected to Privilege Escalation. Each page keeps one canonical URL and focused remediation guidance.

113 published Privilege Escalation risks

Privilege Escalation risks

Showing 73–108 of 113 published risks.

criticalEPSS 0.009

CVE-2026-50748 in UniFi Access Application

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.

CVE-2026-50748network-securityremote-code-executioninput-validationprivilege-escalation

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-54400 in UniFi Access Application

A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.

CVE-2026-54400network-securityauthorization-bypassprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-54401 in UniFi OS Server

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances.

CVE-2026-54401network-securityssrfprivilege-escalation

Updated Jul 14, 2026

criticalEPSS 0.009

CVE-2026-54402 in UniFi OS Server

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.

CVE-2026-54402network-securityremote-code-executioninput-validationprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-54404 in UniFi OS

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances.

CVE-2026-54404network-securitysql-injectionprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-54406 in UniFi Network Application

A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device.

CVE-2026-54406network-securitypath-traversalfile-writeprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-55112 in UniFi OS with UniFi Protect

A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.

CVE-2026-55112network-securityauthorization-bypassprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-55114 in UniFi Network Application

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.

CVE-2026-55114network-securityauthorization-bypassprivilege-escalation

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-55115 in UniFi Protect Application

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.

CVE-2026-55115network-securityssrfprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-55118 in UniFi Network Application

A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.

CVE-2026-55118network-securityauthorization-bypassprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-55119 in UniFi Talk Application

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.

CVE-2026-55119network-securityauthorization-bypassprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-56841 in UniFi Protect Application

A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device.

CVE-2026-56841network-securitysql-injectionprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-8079 in Progress Flowmon

In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration.

CVE-2026-8079network-securityauthorization-bypassprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-59093 Weaviate Vulnerability

Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted by the assigned role. The assignRoleToUser and assignRoleToGroup handlers (POST /authz/users/{id}/assign and /authz/groups/{id}/assign) authorize only that the caller may assign roles to the target user or group, not the permissions contained in the assigned roles, unlike role creation which enforces that a user can only create roles with permissions less than or equal to its own. A user holding only the delegated assign_and_revoke_users or assign_and_revoke_groups permission can assign the built-in admin role, or any high-privilege custom role, to itself or others, escalating to full administrative control of the database.

CVE-2026-59093web-applicationauthorization-bypassprivilege-escalation

Updated Jul 14, 2026

high

CVE-2026-13079 mobile vpn with ssl vulnerability

A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed. This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2.

CVE-2026-13079windowsnetwork-securityprivilege-escalation

Updated Jul 14, 2026

mediumEPSS 0.001

CVE-2026-44268 data domain operating system vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect permission Assignment for critical resource vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.

CVE-2026-44268network-securityprivilege-escalation

Updated Jul 14, 2026

criticalEPSS 0.004

CVE-2026-40138 privileged remote access vulnerability

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled

CVE-2026-40138authentication-bypassauthorization-bypassprivilege-escalation

Updated Jul 13, 2026

criticalEPSS 0.007

CVE-2026-40139 privileged remote access vulnerability

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.

CVE-2026-40139authentication-bypassauthorization-bypassprivilege-escalation

Updated Jul 13, 2026

mediumEPSS 0.004

CVE-2026-15270 dir-823g firmware vulnerability

A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. Executing a manipulation can lead to least privilege violation. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks.

CVE-2026-15270privilege-escalation

Updated Jul 13, 2026

highEPSS 0.003

WP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter

The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key validation in the `update()` handler for the `/wp-json/wpgb/v2/metadata` REST endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to Administrator by updating their own `wp_capabilities` user meta with a crafted nested array payload.

CVE-2026-13756wordpressauthorization-bypassprivilege-escalation

Updated Jul 13, 2026

highEPSS 0.003

Genolve – AI image AI video generation <= 5.0.5 - Authenticated (Contributor+) Incorrect Authorization to Privilege Escalation via theopt

The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to update arbitrary WordPress options, including enabling user registration and setting the default role to administrator, resulting in privilege escalation.

CVE-2026-1359wordpressauthorization-bypassprivilege-escalation

Updated Jul 13, 2026

highEPSS 0.004

Simple JWT Login <= 3.6.6 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' Parameter

The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerability exists because `AuthenticateService::generatePayload()` only overwrites JWT payload keys whose names appear in the admin-configured `jwt_payload` list — leaving any attacker-supplied identity claims such as `email`, `id`, or `username` intact and signed into the JWT with the site's HS256 secret. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their privileges to that of an Administrator by injecting a target administrator's email address into the `payload` parameter at the `/wp-json/simple-jwt-login/v1/auth` endpoint, then redeeming the resulting JWT at the `/autologin` endpoint to obtain a fully authenticated session as that administrator.

CVE-2026-14262wordpressauthentication-bypassprivilege-escalation

Updated Jul 13, 2026

highEPSS 0.003

SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook

The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details like email during customer profile synchronization from webhook events. This makes it possible for unauthenticated attackers to change linked user's email addresses, including administrators if the administrator account is linked to a SureCart customer record, and leverage that to reset the user's password and gain access to their account if the customer ID is known.

CVE-2026-7655wordpressprivilege-escalation

Updated Jul 13, 2026

highEPSS 0.003

CVE-2026-55843 Snipe-IT vulnerability

Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and PreserveUnauthorizedPrivilegedPermissionsAction in a way that can overwrite a target user’s permissions with a sparse result, allowing an administrator updating another administrator, or a user with users.edit updating a regular account, to remove the target’s administrative or granular permissions. This issue is fixed in version 8.6.0.

CVE-2026-55843phpweb-applicationauthorization-bypassprivilege-escalation

Updated Jul 12, 2026

highEPSS 0.001

CVE-2026-14868 PcVue vulnerability

The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the existing configuration and ultimately gain privileged access to the PcVue application.

CVE-2026-14868industrial-controlprivilege-escalationcryptography

Updated Jul 12, 2026

criticalEPSS 0.006

CVE-2026-53483 Dell PowerProtect Data Domain vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an improper authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.

CVE-2026-53483network-securityauthentication-bypassprivilege-escalation

Updated Jul 12, 2026

highEPSS 0.012

CVE-2026-53479 Dell PowerProtect Data Domain vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection') vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to protection mechanism bypass. This is a Critical vulnerability as it allows an attacker to invoke arbitrary command execution with root privileges; so Dell recommends customers to upgrade at the earliest opportunity.

CVE-2026-53479network-securityremote-code-executionprivilege-escalation

Updated Jul 12, 2026

highEPSS 0.006

CVE-2026-55077 Coder vulnerability

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the `PUT /api/v2/users/{user}/password` endpoint authorized only `ActionUpdatePersonal` and did not prevent a `user-admin` from resetting an `owner` account's password. It also did not require the current password when an admin reset another user's password. Exploitation requires the privileged `user-admin` role so practical risk is limited to deployments that grant `user-admin` to less trusted operators. The fix in versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2 prevents non-owner users from resetting the password of an account that holds the `owner` role. As a workaround, restrict the `user-admin` role to trusted administrators.

CVE-2026-55077api-securitydevopsauthorization-bypassprivilege-escalation

Updated Jul 12, 2026

highEPSS 0.001

BOSH Windows Stemcell Builder SYSTEM Privilege Escalation Vulnerability

Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.

CVE-2026-47830windowscloud-securityprivilege-escalation

Updated Jul 10, 2026

highEPSS 0.002

Nozomi Networks Guardian and CMC Arc Sensor CLI Privilege Assignment Vulnerability

An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.

CVE-2026-33390industrial-controlprivilege-escalation

Updated Jul 10, 2026

lowEPSS 0.002

Pinniped Supervisor Active Directory Group Authorization Vulnerability

A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in the clusters, only if all the following conditions were true: the Pinniped Supervisor server is running with an ActiveDirectoryIdentityProvider resource configured; the ActiveDirectoryIdentityProvider.spec.groupSearch.attributes.groupName is empty; the attacker gains the ability to edit some part of the distinguished name (DN) of group entries in the Active Directory (AD) server's database for groups to which they belong; the configured group search parameters cause the edited group to be included in the group search results for the user; and the attacker knows the password for an AD user who belongs to the edited AD group. Affected versions: Pinniped (go.pinniped.dev) v0.11.0 through v0.46.0 inclusive; fixed in v0.47.0.

CVE-2026-59269cloud-securityauthorization-bypassprivilege-escalation

Updated Jul 10, 2026

high

Siemens SICORE Admin Account Authorization Bypass Vulnerability

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. This could allow an authenticated attacker to bypass security controls and gain unauthorized elevated privileges.

CVE-2026-54801api-securityindustrial-controlauthorization-bypassprivilege-escalation

Updated Jul 10, 2026

low

django-job-portal Employee Profile Access Control Vulnerability

A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affected by this vulnerability is the function EditEmployeeProfileAPIView of the file accounts/api/views.py of the component Employee Dashboard Endpoint. This manipulation of the argument role causes improper access controls. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.

CVE-2026-15188pythonapi-securityweb-applicationauthorization-bypass

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.055

Linux Kernel Improper Authentication Vulnerability

Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.

CVE-2022-0492linuxauthentication-bypassauthorization-bypassprivilege-escalation

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.017

Android Framework Integer Overflow Vulnerability

Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.

CVE-2025-48595input-validationprivilege-escalation

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.189

LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.

CVE-2026-48172privilege-escalation

Updated Jul 9, 2026