CWE-266— Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
1,220 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-266page 4 of 25
- CVE-2025-10644CRITICALCVSS 9.4EG 9.42025-09-17
Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on Wondershare Repairit. Authentication is not required to exploit this…
- CVE-2026-103470CRITICALCVSS 9.3EG 9.32026-09-30
In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.
- CVE-2026-64639CRITICALCVSS 9.3EG 9.32026-08-12
Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.
- CVE-2026-50562CRITICALCVSS 9.3EG 9.32026-07-15
FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/workflows/preview-docs-build.yml and .github/workflows/previe…
- CVE-2026-86153CRITICALCVSS 9.1EG 9.12026-09-06
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the atta…
- CVE-2026-10059CRITICALCVSS 9.1EG 9.12026-08-05
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently…
- CVE-2025-10263CRITICALCVSS 9.1EG 9.12026-06-09
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow…
- CVE-2026-22908CRITICALCVSS 9.1EG 9.12026-01-15
Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.
- CVE-2025-13888CRITICALCVSS 9.1EG 9.12025-12-15
A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker c…
- CVE-2025-13787CRITICALCVSS 9.1EG 9.12025-11-30
A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper priv…
- CVE-2025-45006CRITICALCVSS 9.1EG 9.12025-07-01
Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec constraints, enabling potential physical memory access attacks.
- CVE-2025-23391CRITICALCVSS 9.1EG 9.12025-04-11
A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password of Administrators and take over their accounts. This issue affects rancher: from 2.8.0 before 2.8.14, from 2.9.0 before…
- CVE-2026-32519CRITICALCVSS 9.0EG 9.02026-03-25
Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through <= 1.2.2.
- CVE-2024-25660CRITICALCVSS 9.0EG 9.02024-10-01
The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.
- CVE-2026-105070HIGHCVSS 8.8EG 8.82026-10-06
Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions.
- CVE-2026-105058HIGHCVSS 8.8EG 8.82026-10-06
Subscriber Privilege Escalation in WP User Profiles <= 2.7.3 versions.
- CVE-2026-39775HIGHCVSS 8.8EG 8.82026-10-06
Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme <= 2.2 versions.
- CVE-2026-39774HIGHCVSS 8.8EG 8.82026-10-06
Unauthenticated Privilege Escalation in Tourfic Pro <= 1.17.3 versions.
- CVE-2026-103068HIGHCVSS 8.8EG 8.82026-10-01
Subscriber Privilege Escalation in ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 versions.
- CVE-2026-101860HIGHCVSS 8.8EG 8.82026-09-29
A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipula…
- CVE-2026-100619HIGHCVSS 8.8EG 8.82026-09-26
Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy, but that restriction can be bypassed indirectly. A principal holding an app-scoped upload/write/all API key (upload+ …
- CVE-2026-86583HIGHCVSS 8.8EG 8.82026-09-23
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the expo…
- CVE-2026-94425HIGHCVSS 8.8EG 8.82026-09-21
A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation results in improper privilege mana…
- CVE-2026-94036HIGHCVSS 8.8EG 8.82026-09-20
A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results i…
- CVE-2026-90493HIGHCVSS 8.8EG 8.82026-09-13
A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access …
- CVE-2026-62106HIGHCVSS 8.8EG 8.82026-09-11
Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.
- CVE-2026-62102HIGHCVSS 8.8EG 8.82026-09-11
Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.
- CVE-2026-86482HIGHCVSS 8.8EG 8.82026-09-07
In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation
- CVE-2026-81769HIGHCVSS 8.8EG 8.82026-09-02
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.
- CVE-2026-82807HIGHCVSS 8.8EG 8.82026-08-31
A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown processing in the library URDSCSI.sys of the component Kernel Driver. This manipulation causes improper privilege management. The attack ne…
- CVE-2026-82628HIGHCVSS 8.8EG 8.82026-08-31
A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a manipulation of the argument PhysicalAddress/AlignNu…
- CVE-2026-32561HIGHCVSS 8.8EG 8.82026-08-24
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
- CVE-2026-28191HIGHCVSS 8.8EG 8.82026-08-18
Incorrect Privilege Assignment vulnerability in ThemeOne The Grid allows Privilege Escalation. This issue affects The Grid: from n/a through 2.8.0.
- CVE-2026-72840HIGHCVSS 8.8EG 8.82026-08-13
OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL gr…
- CVE-2026-28161HIGHCVSS 8.8EG 8.82026-08-13
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
- CVE-2026-18950HIGHCVSS 8.8EG 8.82026-08-10
A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitra…
- CVE-2026-28111HIGHCVSS 8.8EG 8.82026-08-06
Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
- CVE-2026-17626HIGHCVSS 8.8EG 8.82026-08-05
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mappi…
- CVE-2026-59541HIGHCVSS 8.8EG 8.82026-07-23
Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
- CVE-2026-21824HIGHCVSS 8.8EG 8.82026-07-20
HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
- CVE-2026-57410HIGHCVSS 8.8EG 8.82026-07-13
Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.This issue affects MailerPress: from n/a through <= 2.0.2.
- CVE-2026-57386HIGHCVSS 8.8EG 8.82026-07-13
Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1.
- CVE-2026-59093HIGHCVSS 8.8EG 8.82026-07-02
Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted by the assigned role. The assignRoleToUser and assignRoleToGroup handlers (POST /authz/users/{id}/assign and /authz/gr…
- CVE-2026-5136HIGHCVSS 8.8EG 8.82026-07-01
A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary rol…
- CVE-2026-56247HIGHCVSS 8.8EG 8.82026-07-01
Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compatibility, including to pending invitees. Attackers can pre-seed malformed high-privilege bindings that survive invite a…
- CVE-2026-56008HIGHCVSS 8.8EG 8.82026-06-26
Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.
- CVE-2026-56010HIGHCVSS 8.8EG 8.82026-06-26
Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
- CVE-2026-12770HIGHCVSS 8.8EG 8.82026-06-21
A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endpoints/key_management_endpoints.py of the component Admin Key Handler. This manipulation ca…
- CVE-2026-54805HIGHCVSS 8.8EG 8.82026-06-17
Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.
- CVE-2025-69138HIGHCVSS 8.8EG 8.82026-06-17
Subscriber Privilege Escalation in Genemy <= 1.6.6 versions.
Map vulnerabilities like CWE-266 to your infrastructure
EchelonGraph correlates every CVE — across CWE-266 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →