CWE-266— Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
1,220 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-266page 1 of 25
- CVE-2026-48172CRITICALCVSS 9.8EG 9.8⚠ KEV2026-05-21
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr…
- CVE-2026-39773CRITICALCVSS 10.0EG 10.02026-10-06
Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions.
- CVE-2026-105284CRITICALCVSS 10.0EG 10.02026-10-05
A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorizatio…
- CVE-2026-23800CRITICALCVSS 10.0EG 10.02026-01-16
Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 before 2.6.0.
- CVE-2024-58338CRITICALCVSS 10.0EG 10.02025-12-30
Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject shell commands and g…
- CVE-2025-41115CRITICALCVSS 10.0EG 10.02025-11-21
SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated user lifecycle management. In Grafana versions 12.x where SCIM pro…
- CVE-2025-34112CRITICALCVSS 10.0EG 10.02025-07-15
An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances. A SQL injection vulnerability in the '/api/common/1.0/login' endpoint can be exploited t…
- CVE-2024-9479CRITICALCVSS 10.0EG 10.02024-11-20
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.
- CVE-2024-9478CRITICALCVSS 10.0EG 10.02024-11-20
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.
- CVE-2026-23550CRITICALCVSS 9.8EG 10.02026-01-14
Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1.
- CVE-2024-23794CRITICALCVSS 5.2EG 10.02024-07-15
An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an agent with read-only permissions to gain full access to a ticket. This issue arises in very r…
- CVE-2026-42368CRITICALCVSS 9.9EG 9.92026-05-04
A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this v…
- CVE-2026-32922CRITICALCVSS 9.9EG 9.92026-03-29
OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller's c…
- CVE-2025-62645CRITICALCVSS 9.9EG 9.92025-10-17
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform via the createToken GraphQL mutation.
- CVE-2025-10725CRITICALCVSS 9.9EG 9.92025-09-30
A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example as a data scientist using a standard Jupyter notebook, can escalate their privileges to a full cluster adminis…
- CVE-2025-54049CRITICALCVSS 9.9EG 9.92025-08-20
Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalation.This issue affects Custom API for WP: from n/a through <= 4.2.2.
- CVE-2025-8795CRITICALCVSS 9.9EG 9.92025-08-10
A vulnerability, which was classified as critical, was found in LitmusChaos Litmus up to 3.19.0. This affects an unknown part of the file /auth/login. The manipulation of the argument projectID leads to improper access controls. It is poss…
- CVE-2025-26512CRITICALCVSS 9.9EG 9.92025-03-24
SnapCenter versions prior to 6.0.1P1 and 6.1P1 are susceptible to a vulnerability which may allow an authenticated SnapCenter Server user to become an admin user on a remote system where a SnapCenter plug-in has been installed.
- CVE-2019-10940CRITICALCVSS 9.9EG 9.92020-01-16
A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1). Incorrect session validation could allow an attacker with a valid session, with low privileges, to perform firmware updates and other administrative …
- CVE-2026-22907CRITICALCVSS 9.1EG 9.92026-01-15
An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.
- CVE-2026-39761CRITICALCVSS 9.8EG 9.82026-10-06
Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions.
- CVE-2026-39753CRITICALCVSS 9.8EG 9.82026-10-06
Unauthenticated Privilege Escalation in Taskbot <= 6.6 versions.
- CVE-2026-103752CRITICALCVSS 9.8EG 9.82026-10-01
Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.
- CVE-2026-96350CRITICALCVSS 9.8EG 9.82026-09-30
Subscriber Privilege Escalation in Estatik <= 4.3.5 versions.
- CVE-2026-78330CRITICALCVSS 9.8EG 9.82026-09-14
Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a succes…
- CVE-2026-84814CRITICALCVSS 9.8EG 9.82026-09-03
Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
- CVE-2026-81294CRITICALCVSS 9.8EG 9.82026-09-02
Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
- CVE-2026-32566CRITICALCVSS 9.8EG 9.82026-08-27
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
- CVE-2026-78267CRITICALCVSS 9.8EG 9.82026-08-24
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
- CVE-2026-66648CRITICALCVSS 9.8EG 9.82026-08-24
Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
- CVE-2026-32558CRITICALCVSS 9.8EG 9.82026-08-24
Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
- CVE-2026-28165CRITICALCVSS 9.8EG 9.82026-08-24
Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
- CVE-2026-66682CRITICALCVSS 9.8EG 9.82026-08-20
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
- CVE-2025-15689CRITICALCVSS 9.8EG 9.82026-08-20
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
- CVE-2026-73390CRITICALCVSS 9.8EG 9.82026-08-19
Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
- CVE-2026-73347CRITICALCVSS 9.8EG 9.82026-08-19
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
- CVE-2026-72839CRITICALCVSS 9.8EG 9.82026-08-13
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full creat…
- CVE-2026-66424CRITICALCVSS 9.8EG 9.82026-08-13
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
- CVE-2026-66662CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
- CVE-2026-65507CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
- CVE-2026-61951CRITICALCVSS 9.8EG 9.82026-07-23
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
- CVE-2026-59540CRITICALCVSS 9.8EG 9.82026-07-23
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
- CVE-2026-57813CRITICALCVSS 9.8EG 9.82026-07-13
Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3.
- CVE-2026-57692CRITICALCVSS 9.8EG 9.82026-07-01
Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2.
- CVE-2026-56028CRITICALCVSS 9.8EG 9.82026-06-26
Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4.9 versions.
- CVE-2026-56030CRITICALCVSS 9.8EG 9.82026-06-26
Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.
- CVE-2026-56033CRITICALCVSS 9.8EG 9.82026-06-26
Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.
- CVE-2026-54807CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.
- CVE-2026-49058CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.
- CVE-2026-27395CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.
Map vulnerabilities like CWE-266 to your infrastructure
EchelonGraph correlates every CVE — across CWE-266 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →