CVE-2026-66661
Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.
CVSS
7.7
High
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Published: Aug 13, 2026 · Last modified: Aug 14, 2026 · CWE-266
0.3%EPSS · 30 days0.3%
2026-08-142026-09-09
Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-15140——
——0A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended, potentially resulting in elevated privileges within the Kubernetes cluster.1dCVE-2026-868045.3 MED31.4%
——9A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the function CPAResource of the file apps/manager-server/internal/http/controller/proxy/handler.go of the component HTTP Handler. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. Upgrading to version 1.11.11 is able to resolve this issue. The identifier of the patch is 842eec791377ddcbea5cd639bc065eaa4801d656. It is suggested to upgrade the affected component.2dCVE-2026-77654—0.9%
——0Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection.
A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file.
This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.2dCVE-2026-85400—37.0%
——11Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a consequence, this allowed them, for example, to gain system maintainer privileges or cause a denial of service. Exploiting this vulnerability requires an administrator-level backend user account. This issue affects TYPO3 CMS versions 14.2.0-14.3.6.2dCVE-2026-817926.5 MED9.5%
——3Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions.2dCVE-2026-865164.7 MED14.0%
——4A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is possible to initiate the attack remotely. The patch is named 6ab3147282d867c1993f995272750db091c2290b. Applying a patch is the recommended action to fix this issue.2d