CWE-266— Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
1,225 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-266page 10 of 25
- CVE-2024-20389HIGHCVSS 7.8EG 7.82024-05-16
A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This v…
- CVE-2024-31771HIGHCVSS 7.8EG 7.82024-05-14
Insecure Permission vulnerability in TotalAV v.6.0.740 allows a local attacker to escalate privileges via a crafted file
- CVE-2024-20320HIGHCVSS 7.8EG 7.82024-03-13
A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Convergence System (NCS) 540 Series and 5700 Series Routers could allow an authenticated, local attacker to elevate privileg…
- CVE-2023-40109HIGHCVSS 7.8EG 7.82024-02-15
In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti…
- CVE-2023-21269HIGHCVSS 7.8EG 7.82023-08-14
In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL bypass. This could lead to local escalation of privilege with no additional execution privileges need…
- CVE-2023-20957HIGHCVSS 7.8EG 7.82023-03-24
In onAttach of SettingsPreferenceFragment.java, there is a possible bypass of Factory Reset Protections due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interac…
- CVE-2020-10728HIGHCVSS 7.8EG 7.82022-08-16
A flaw was found in automationbroker/apb container in versions up to and including 2.0.4-1. This container grants all users sudoer permissions allowing an unauthorized user with access to the running container the ability to escalate their…
- CVE-2022-20681HIGHCVSS 7.8EG 7.82022-04-15
A vulnerability in the CLI of Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches and Cisco Catalyst 9000 Family Wireless Controllers could allow an authenticated, local attacker to elevate privileges to level 15 on an affected d…
- CVE-2021-20264HIGHCVSS 7.8EG 7.82021-10-06
An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw allows an attacker with access to the container to modify the /etc/passwd and escalate their privileges. The highest th…
- CVE-2021-1572HIGHCVSS 7.8EG 7.82021-08-04
A vulnerability in ConfD could allow an authenticated, local attacker to execute arbitrary commands at the level of the account under which ConfD is running, which is commonly root. To exploit this vulnerability, an attacker must have a va…
- CVE-2020-10695HIGHCVSS 7.8EG 7.82021-05-26
An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An attacker with access to the container can use this flaw to modify the /etc/passwd and escalate their privileges.
- CVE-2019-19354HIGHCVSS 7.8EG 7.82021-03-24
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate th…
- CVE-2019-19350HIGHCVSS 7.8EG 7.82021-03-24
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 and 3.11. An attacker with access to the container could use this flaw to modify /etc/passwd…
- CVE-2019-19349HIGHCVSS 7.8EG 7.82021-03-24
An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/p…
- CVE-2020-6652HIGHCVSS 7.8EG 7.82020-05-07
Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests. This can result in non-admin users …
- CVE-2019-3843HIGHCVSS 7.8EG 7.82019-04-26
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to…
- CVE-2016-7066HIGHCVSS 7.8EG 7.82018-09-11
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.
- CVE-2017-12711HIGHCVSS 7.8EG 7.82017-08-30
An Incorrect Privilege Assignment issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A built-in user account has been granted a sensitive privilege that may allow a user to elevate to administrative privileges.
- CVE-2019-19345HIGHCVSS 7.0EG 7.82020-03-20
A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mediawiki-apb. An attacker with access to the…
- CVE-2021-40124HIGHCVSS 6.7EG 7.82021-11-04
A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to escalate privileges on an affected device. This vulnerability is due to incor…
- CVE-2026-15140HIGHCVSS 7.7EG 7.72026-09-09
A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped per…
- CVE-2026-66661HIGHCVSS 7.7EG 7.72026-08-13
Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.
- CVE-2026-20852HIGHCVSS 7.7EG 7.72026-01-13
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
- CVE-2026-20804HIGHCVSS 7.7EG 7.72026-01-13
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
- CVE-2025-58323HIGHCVSS 7.7EG 7.72025-08-29
NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by executing arbitrary files due to improper privilege checks.
- CVE-2024-4555HIGHCVSS 7.7EG 7.72024-08-28
Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affects NetIQ Access Manager before 5.0.4.1 and before 5.1
- CVE-2020-7334HIGHCVSS 7.7EG 7.72020-10-15
Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2 allows local administrators to change or update the configuration settings via a carefully constructed MSI configured …
- CVE-2026-18621HIGHCVSS 7.6EG 7.62026-08-10
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with el…
- CVE-2026-39546HIGHCVSS 7.6EG 7.62026-06-17
Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions.
- CVE-2025-3744HIGHCVSS 7.6EG 7.62025-05-13
Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.
- CVE-2025-31420HIGHCVSS 7.6EG 7.62025-04-04
Incorrect Privilege Assignment vulnerability in Tomdever wpForo Forum wpforo allows Privilege Escalation.This issue affects wpForo Forum: from n/a through <= 2.4.2.
- CVE-2023-25591HIGHCVSS 7.6EG 7.62023-03-22
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve informat…
- CVE-2022-1746HIGHCVSS 7.6EG 7.62022-06-24
The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Systems ImageCast X can expose cryptographic secrets used to protect election information. An attacker could leverage this v…
- CVE-2026-94178HIGHCVSS 7.5EG 7.52026-09-30
Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.
- CVE-2026-91930HIGHCVSS 7.5EG 7.52026-09-15
Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, creat…
- CVE-2026-85400HIGHCVSS 7.5EG 7.52026-09-08
Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is norma…
- CVE-2026-81297HIGHCVSS 7.5EG 7.52026-08-31
Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
- CVE-2026-15271HIGHCVSS 7.5EG 7.52026-07-09
A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by this issue is some unknown functionality of the file /etc/boa/boa.conf of the component Web …
- CVE-2026-15270HIGHCVSS 7.5EG 7.52026-07-09
A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. Executing a manipulation can lead to least privil…
- CVE-2026-12771HIGHCVSS 7.5EG 7.52026-06-21
A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulation leads to improper authorization. The a…
- CVE-2026-49083HIGHCVSS 7.5EG 7.52026-06-15
Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.
- CVE-2026-47169HIGHCVSS 7.5EG 7.52026-06-11
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a user with Manage Server / ManageGuild, but without Manage Roles or Administrator, can configure the bot’s AutoRole featu…
- CVE-2026-11555HIGHCVSS 7.5EG 7.52026-06-08
A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. The attack may be l…
- CVE-2025-68420HIGHCVSS 7.5EG 7.52026-05-14
Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to which a user logs in. It is possible for a local attacker who controls the client process to dump it's memory, extrac…
- CVE-2026-40869HIGHCVSS 7.5EG 7.52026-04-21
Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users…
- CVE-2026-4193HIGHCVSS 7.5EG 7.52026-03-16
A security vulnerability has been detected in D-Link DIR-823G 1.0.2B05. The affected element is the function GetDDNSSettings/GetDeviceDomainName/GetDeviceSettings/GetDMZSettings/GetFirewallSettings/GetGuestNetworkSettings/GetLanWanConflict…
- CVE-2025-43914HIGHCVSS 7.5EG 7.52025-10-07
Dell PowerProtect Data Domain BoostFS for Linux Ubuntu systems of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 t…
- CVE-2025-47422HIGHCVSS 7.5EG 7.52025-07-08
Advanced Installer before 22.6 has an uncontrolled search path element local privilege escalation vulnerability. When running as SYSTEM in certain configurations, Advanced Installer looks in standard-user writable locations for non-existen…
- CVE-2025-5511HIGHCVSS 7.5EG 7.52025-06-03
A vulnerability, which was classified as critical, has been found in quequnlong shiyi-blog up to 1.2.1. This issue affects some unknown processing of the file /dev api/app/album/photos/. The manipulation leads to improper authorization. Th…
- CVE-2025-47291HIGHCVSS 7.5EG 7.52025-05-21
containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under the Kubernetes' cgro…
Map vulnerabilities like CWE-266 to your infrastructure
EchelonGraph correlates every CVE — across CWE-266 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →