The product does not properly manage a user within its environment.
Volume of CVEs assigned to CWE-286 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59943CRITICAL phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of email addresses during user registration. This allows multipl | Oct 3, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-35638HIGH OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated sessions to retain self-declared privileged scopes without dev | Apr 9, 2026 | 8.8 | 31 | NO | NO |
CVE-2025-64725CRITICAL Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a workar | Dec 15, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-26689CRITICAL An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request. | Sep 25, 2024 | 9.8 | 29 | NO | NO |
CVE-2022-32260CRITICAL A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application creates temporary user credentials for UMC (User Management | Jun 14, 2022 | 9.8 | 29 | NO | NO |
CVE-2025-7972CRITICAL A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This by | Aug 14, 2025 | 9.1 | 27 | NO | NO |
CVE-2024-48853CRITICAL An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. This issue affects ASPECT-Enterpris | May 22, 2025 | 9.0 | 27 | NO | NO |
CVE-2021-21553HIGH Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allow the CompAdmin user to elevate privilege | Aug 3, 2021 | 8.8 | 26 | NO | NO |
CVE-2022-45857HIGH An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a passw | Jan 5, 2023 | 7.5 | 25 | NO | NO |
CVE-2024-52359HIGH IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform unauthorized actions that should be reserved to administrator used due to imprope | Nov 19, 2024 | 8.8 | 23 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.