CVE-2026-50335
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
CVSS
7.8
Alto
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Publicado: 14 jul 2026 · Última mod.: 22 jul 2026 · CWE-284
0.3%EPSS · 30 días0.3%
2026-07-152026-07-22
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-64796——
——0Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.3hCVE-2026-64794——
——0User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details.3hCVE-2026-64793——
——0Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the required access.3hCVE-2026-64791——
——0Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could install, update or remove extensions.3hCVE-2026-63685——
——0Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform database replacements, potentially causing major data corruption or site compromise.3hCVE-2026-63684——
——0Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks could expose, create or modify extension configuration and items.3h