CWE-266— Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
1,220 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-266page 2 of 25
- CVE-2025-69179CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions.
- CVE-2026-39583CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.
- CVE-2026-34901CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.
- CVE-2026-49060CRITICALCVSS 9.8EG 9.82026-06-11
Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4.
- CVE-2025-53209CRITICALCVSS 9.8EG 9.82026-06-02
Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0.
- CVE-2026-42680CRITICALCVSS 9.8EG 9.82026-06-01
Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 29.0.1.
- CVE-2026-48879CRITICALCVSS 9.8EG 9.82026-06-01
Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.
- CVE-2026-42758CRITICALCVSS 9.8EG 9.82026-05-27
Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through < 4.08.253.
- CVE-2026-42731CRITICALCVSS 9.8EG 9.82026-05-27
Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through <= 5.4.9.
- CVE-2026-22337CRITICALCVSS 9.8EG 9.82026-04-27
Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Social Login: from n/a before 2.1.4.
- CVE-2026-33519CRITICALCVSS 9.8EG 9.82026-04-21
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
- CVE-2026-33518CRITICALCVSS 9.8EG 9.82026-04-21
An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.
- CVE-2026-5569CRITICALCVSS 9.8EG 9.82026-04-05
A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the component Endpoint. The manipulation results in improper access controls. The attack may be perfor…
- CVE-2026-5526CRITICALCVSS 9.8EG 9.82026-04-04
A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation results in improper access controls. The attac…
- CVE-2026-32916CRITICALCVSS 9.8EG 9.82026-03-31
OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated req…
- CVE-2026-32520CRITICALCVSS 9.8EG 9.82026-03-25
Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalation.This issue affects RewardsWP: from n/a through <= 1.0.4.
- CVE-2026-27051CRITICALCVSS 9.8EG 9.82026-03-25
Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0.
- CVE-2026-24971CRITICALCVSS 9.8EG 9.82026-03-25
Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n/a through <= 2.8.
- CVE-2026-24968CRITICALCVSS 9.8EG 9.82026-03-25
Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a through <= 7.1.0.30.
- CVE-2026-27542CRITICALCVSS 9.8EG 9.82026-03-19
Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Privilege Escalation.This issue affects Woocommerce Wholesale Lead Capture: from n/a throug…
- CVE-2026-4194CRITICALCVSS 9.8EG 9.82026-03-16
A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-…
- CVE-2026-4180CRITICALCVSS 9.8EG 9.82026-03-16
A vulnerability was identified in D-Link DIR-816 1.10CNB05. The impacted element is an unknown function of the file redirect.asp of the component goahead. The manipulation of the argument token_id leads to improper access controls. The att…
- CVE-2026-3762CRITICALCVSS 9.8EG 9.82026-03-08
A vulnerability has been found in SourceCodester Client Database Management System 1.0/3.1. Impacted is an unknown function of the file /superadmin_delete_manager.php of the component Endpoint. The manipulation of the argument manager_id l…
- CVE-2026-27983CRITICALCVSS 9.8EG 9.82026-03-05
Incorrect Privilege Assignment vulnerability in designthemes LMS Elementor Pro lms-elementor-pro allows Privilege Escalation.This issue affects LMS Elementor Pro: from n/a through <= 1.0.4.
- CVE-2026-2983CRITICALCVSS 9.8EG 9.82026-02-23
A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin/core/import_users.php of the component Bulk Import. This manipulation of the argument Fil…
- CVE-2026-1963CRITICALCVSS 9.8EG 9.82026-02-05
A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage. The manipulation results in improper access controls. The attack may be launched remotel…
- CVE-2026-1962CRITICALCVSS 9.8EG 9.82026-02-05
A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the component Attachment Migration. The manipulation leads to improper access controls. The attack…
- CVE-2025-68869CRITICALCVSS 9.8EG 9.82026-01-22
Incorrect Privilege Assignment vulnerability in LazyCoders LLC LazyTasks lazytasks-project-task-management allows Privilege Escalation.This issue affects LazyTasks: from n/a through <= 1.2.37.
- CVE-2019-25249CRITICALCVSS 9.8EG 9.82025-12-24
devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, …
- CVE-2025-64188CRITICALCVSS 9.8EG 9.82025-12-18
Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through <= 8.6.9.
- CVE-2025-13806CRITICALCVSS 9.8EG 9.82025-12-01
A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthModu…
- CVE-2025-6325CRITICALCVSS 9.8EG 9.82025-11-06
Incorrect Privilege Assignment vulnerability in KingAddons.com King Addons for Elementor king-addons allows Privilege Escalation.This issue affects King Addons for Elementor: from n/a through <= 51.1.36.
- CVE-2025-60243CRITICALCVSS 9.8EG 9.82025-11-06
Incorrect Privilege Assignment vulnerability in Holest Engineering Selling Commander for WooCommerce selling-commander-connector allows Privilege Escalation.This issue affects Selling Commander for WooCommerce: from n/a through <= 1.2.46.
- CVE-2025-60195CRITICALCVSS 9.8EG 9.82025-11-06
Incorrect Privilege Assignment vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Privilege Escalation.This issue affects Atarim: from n/a through <= 4.2.1.
- CVE-2025-60220CRITICALCVSS 9.8EG 9.82025-10-22
Incorrect Privilege Assignment vulnerability in pebas CouponXxL couponxxl allows Privilege Escalation.This issue affects CouponXxL: from n/a through <= 3.0.0.
- CVE-2025-49401CRITICALCVSS 9.8EG 9.82025-09-05
Incorrect Privilege Assignment vulnerability in axiomthemes smart SEO smartSEO allows Privilege Escalation.This issue affects smart SEO: from n/a through <= 4.0.
- CVE-2024-32444CRITICALCVSS 9.8EG 9.82025-09-03
Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue affects RealHomes: from n/a through <= 4.3.6.
- CVE-2025-49388CRITICALCVSS 9.8EG 9.82025-08-28
Incorrect Privilege Assignment vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Privilege Escalation.This issue affects Miraculous Core Plugin: from n/a through <= 2.0.7.
- CVE-2025-53580CRITICALCVSS 9.8EG 9.82025-08-20
Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9.
- CVE-2025-49422CRITICALCVSS 9.8EG 9.82025-08-20
Incorrect Privilege Assignment vulnerability in themepassion Support Ticket support-ticket allows Privilege Escalation.This issue affects Support Ticket: from n/a through <= 1.9.
- CVE-2025-8261CRITICALCVSS 9.8EG 9.82025-07-28
A weakness has been identified in Vaelsys VaelsysV4 4.1.0. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the component User Creation Handler. Executing a manipulation can lead to improper authorization. The …
- CVE-2025-44655CRITICALCVSS 9.8EG 9.82025-07-21
In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot poin…
- CVE-2025-52836CRITICALCVSS 9.8EG 9.82025-07-16
Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Privilege Escalation.This issue affects The E-Commerce ERP: from n/a through <= 2.1.1.3.
- CVE-2025-49867CRITICALCVSS 9.8EG 9.82025-07-04
Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue affects RealHomes: from n/a through <= 4.4.0.
- CVE-2025-23970CRITICALCVSS 9.8EG 9.82025-07-04
Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking sf-booking allows Privilege Escalation.This issue affects Service Finder Booking: from n/a through <= 6.1.
- CVE-2025-48129CRITICALCVSS 9.8EG 9.82025-06-09
Incorrect Privilege Assignment vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-wp-e-commerce-light allows Privilege Escalation.This issue…
- CVE-2025-5409CRITICALCVSS 9.8EG 9.82025-06-01
A vulnerability was found in Mist Community Edition up to 4.7.1. It has been classified as critical. This affects the function create_token of the file src/mist/api/auth/views.py of the component API Token Handler. The manipulation leads t…
- CVE-2025-5390CRITICALCVSS 9.8EG 9.82025-05-31
A vulnerability, which was classified as critical, was found in JeeWMS up to 20250504. This affects the function filedeal of the file /systemController/filedeal.do of the component File Handler. The manipulation leads to improper access co…
- CVE-2025-5389CRITICALCVSS 9.8EG 9.82025-05-31
A vulnerability, which was classified as critical, has been found in JeeWMS up to 20250504. Affected by this issue is the function dogenerateOne2Many of the file /generateController.do?dogenerateOne2Many of the component File Handler. The …
- CVE-2025-5387CRITICALCVSS 9.8EG 9.82025-05-31
A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of the file /generateController.do?dogenerate of the component File Handler. The manipulation leads to improper access cont…
Map vulnerabilities like CWE-266 to your infrastructure
EchelonGraph correlates every CVE — across CWE-266 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →