CWE-266— Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
1,223 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-266page 7 of 25
- CVE-2025-23528HIGHCVSS 8.8EG 8.82025-01-16
Incorrect Privilege Assignment vulnerability in Mosterd3d DD Roles dd-roles allows Privilege Escalation.This issue affects DD Roles: from n/a through <= 4.1.
- CVE-2025-22736HIGHCVSS 8.8EG 8.82025-01-15
Incorrect Privilege Assignment vulnerability in Saad Iqbal User Management user-management allows Privilege Escalation.This issue affects User Management: from n/a through <= 1.2.
- CVE-2024-13251HIGHCVSS 8.8EG 8.82025-01-09
Incorrect Privilege Assignment vulnerability in Drupal Registration role allows Privilege Escalation.This issue affects Registration role: from 0.0.0 before 2.0.1.
- CVE-2024-56280HIGHCVSS 8.8EG 8.82025-01-07
Incorrect Privilege Assignment vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Privilege Escalation.This issue affects WPGuppy: from n/a through <= 1.1.0.
- CVE-2024-49644HIGHCVSS 8.8EG 8.82025-01-07
Incorrect Privilege Assignment vulnerability in AllAccessible Accessibility by AllAccessible allaccessible allows Privilege Escalation.This issue affects Accessibility by AllAccessible: from n/a through <= 1.3.4.
- CVE-2024-54365HIGHCVSS 8.8EG 8.82024-12-16
Incorrect Privilege Assignment vulnerability in Knowhalim KH Easy User Settings kh-easy-user-settings allows Privilege Escalation.This issue affects KH Easy User Settings: from n/a through <= 1.0.0.
- CVE-2024-50506HIGHCVSS 8.8EG 8.82024-10-30
Incorrect Privilege Assignment vulnerability in azexo Marketing Automation by AZEXO marketing-automation-by-azexo allows Privilege Escalation.This issue affects Marketing Automation by AZEXO: from n/a through <= 1.27.80.
- CVE-2024-50504HIGHCVSS 8.8EG 8.82024-10-30
Incorrect Privilege Assignment vulnerability in webxmedia Bulk Change Role bulk-role-change allows Privilege Escalation.This issue affects Bulk Change Role: from n/a through <= 1.1.
- CVE-2024-50481HIGHCVSS 8.8EG 8.82024-10-29
Incorrect Privilege Assignment vulnerability in stackthemes Bstone Demo Importer bstone-demo-importer allows Privilege Escalation.This issue affects Bstone Demo Importer: from n/a through <= 1.0.1.
- CVE-2024-49608HIGHCVSS 8.8EG 8.82024-10-20
Incorrect Privilege Assignment vulnerability in gerryworks GERRYWORKS Post by Mail gerryworks-post-by-mail allows Privilege Escalation.This issue affects GERRYWORKS Post by Mail: from n/a through <= 1.0.
- CVE-2024-49219HIGHCVSS 8.8EG 8.82024-10-17
Incorrect Privilege Assignment vulnerability in themexpo RS-Members rs-members allows Privilege Escalation.This issue affects RS-Members: from n/a through <= 1.0.3.
- CVE-2024-22303HIGHCVSS 8.8EG 8.82024-09-17
Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 3.2.4.
- CVE-2024-21743HIGHCVSS 8.8EG 8.82024-09-17
Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5.
- CVE-2024-8253HIGHCVSS 8.8EG 8.82024-09-11
The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the plugin not properly restricting what user meta values can be updated and ensuring a form is …
- CVE-2024-39576HIGHCVSS 8.8EG 8.82024-08-22
Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevatio…
- CVE-2024-40433HIGHCVSS 8.8EG 8.82024-07-26
Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.
- CVE-2024-32959HIGHCVSS 8.8EG 8.82024-05-17
Incorrect Privilege Assignment vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.2.
- CVE-2024-32507HIGHCVSS 8.8EG 8.82024-05-17
Incorrect Privilege Assignment vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.7.16.
- CVE-2024-22145HIGHCVSS 8.8EG 8.82024-05-17
Incorrect Privilege Assignment vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.
- CVE-2023-38298HIGHCVSS 8.8EG 8.82024-04-22
Various software builds for the following TCL devices (30Z, A3X, 20XE, 10L) leak the device IMEI to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted thir…
- CVE-2023-49647HIGHCVSS 8.8EG 8.82024-01-12
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2023-6009HIGHCVSS 8.8EG 8.82023-11-22
The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to insufficient restriction on the 'userpro_update_user_profile' function. This makes it possible for authenticated attacker…
- CVE-2023-4153HIGHCVSS 8.8EG 8.82023-09-13
The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.5.3 due to a missing capability check on the 'w3dev_save_ban_user_settings_callback' function. This makes it possible for authenti…
- CVE-2020-10129HIGHCVSS 8.8EG 8.82023-09-06
SearchBlox before Version 9.2.1 is vulnerable to Privileged Escalation-Lower user is able to access Admin functionality.
- CVE-2022-20759HIGHCVSS 8.8EG 8.82022-05-03
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attac…
- CVE-2021-1303HIGHCVSS 8.8EG 8.82021-01-20
A vulnerability in the user management roles of Cisco DNA Center could allow an authenticated, remote attacker to execute unauthorized commands on an affected device. The vulnerability is due to improper enforcement of actions for assigned…
- CVE-2020-7018HIGHCVSS 8.8EG 8.82020-08-18
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These credentials could …
- CVE-2020-7014HIGHCVSS 8.8EG 8.82020-06-03
The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker w…
- CVE-2020-7009HIGHCVSS 8.8EG 8.82020-03-31
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result i…
- CVE-2019-14819HIGHCVSS 8.8EG 8.82020-01-07
A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivil…
- CVE-2022-4441HIGHCVSS 7.6EG 8.82023-01-31
Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.9.0 before 0…
- CVE-2023-1874HIGHCVSS 7.5EG 8.82023-04-12
The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. This is due to a lack of authorization checks on the multiple_roles_update function. This makes it possible for authenti…
- CVE-2025-53425HIGHCVSS 7.2EG 8.82025-10-22
Incorrect Privilege Assignment vulnerability in Dokan, Inc. Dokan dokan-lite allows Privilege Escalation.This issue affects Dokan: from n/a through <= 4.1.3.
- CVE-2022-4281HIGHCVSS 6.3EG 8.82022-12-05
A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /face-recognition-php/facepay-master/camera.php. The manipulation of the argument userId leads…
- CVE-2022-3944HIGHCVSS 6.3EG 8.82022-11-11
A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the function uploadImages of the file application/controllers/basedata/inventory.php of the component Commodity Management. Th…
- CVE-2022-3770HIGHCVSS 6.3EG 8.82022-10-31
A vulnerability classified as critical was found in Yunjing CMS. This vulnerability affects unknown code of the file /index/user/upload_img.html. The manipulation of the argument file leads to unrestricted upload. The attack can be initiat…
- CVE-2022-3496HIGHCVSS 6.3EG 8.82022-10-14
A vulnerability was found in SourceCodester Human Resource Management System 1.0 and classified as critical. This issue affects some unknown processing of the file employeeadd.php of the component Admin Panel. The manipulation leads to imp…
- CVE-2022-4041HIGHCVSS 5.9EG 8.82023-01-31
Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.8.0 before 0…
- CVE-2022-2637HIGHCVSS 5.4EG 8.82022-10-06
Incorrect Privilege Assignment vulnerability in Hitachi Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation.This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.8.0 b…
- CVE-2024-56513HIGHCVSS 8.7EG 8.72025-01-03
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, the PULL mode clusters registered with the `karmadactl register` command …
- CVE-2023-2816HIGHCVSS 8.7EG 8.72023-06-02
Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has per…
- CVE-2025-52726HIGHCVSS 8.6EG 8.62025-06-27
Incorrect Privilege Assignment vulnerability in pebas CouponXxL Custom Post Types couponxxl-cpt allows Privilege Escalation.This issue affects CouponXxL Custom Post Types: from n/a through <= 3.0.
- CVE-2024-25632HIGHCVSS 8.6EG 8.62024-10-01
eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A user may be an administr…
- CVE-2024-27453HIGHCVSS 8.6EG 8.62024-05-03
In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI).
- CVE-2023-50437HIGHCVSS 8.6EG 8.62024-02-29
An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageCluster2.
- CVE-2025-10577HIGHCVSS 8.5EG 8.52025-10-15
Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. HP is releasing updated audio packages to mitigate the pote…
- CVE-2025-10576HIGHCVSS 8.5EG 8.52025-10-15
Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. HP is releasing updated audio packages to mitigate the pote…
- CVE-2023-53973HIGHCVSS 8.4EG 8.42025-12-22
Zillya Total Security 3.0.2367.0 contains a privilege escalation vulnerability that allows low-privileged users to copy files to unauthorized system locations using the quarantine module. Attackers can leverage symbolic link techniques to …
- CVE-2025-65807HIGHCVSS 8.4EG 8.42025-12-10
An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command.
- CVE-2025-2098HIGHCVSS 8.4EG 8.42025-03-26
Fast CAD Reader application on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. Incorrect permi…
Map vulnerabilities like CWE-266 to your infrastructure
EchelonGraph correlates every CVE — across CWE-266 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →