CWE-266— Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
1,225 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-266page 8 of 25
- CVE-2025-65807HIGHCVSS 8.4EG 8.42025-12-10
An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command.
- CVE-2025-2098HIGHCVSS 8.4EG 8.42025-03-26
Fast CAD Reader application on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. Incorrect permi…
- CVE-2025-1413HIGHCVSS 8.4EG 8.42025-02-28
DaVinci Resolve on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. Incorrect permissions allow…
- CVE-2024-36534HIGHCVSS 8.4EG 8.42024-07-24
Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
- CVE-2023-30691HIGHCVSS 8.4EG 8.42023-08-10
Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.
- CVE-2023-30680HIGHCVSS 8.4EG 8.42023-08-10
Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.
- CVE-2023-28956HIGHCVSS 8.4EG 8.42023-06-22
IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls.
- CVE-2024-23288HIGHCVSS 7.8EG 8.42024-03-08
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to elevate privileges.
- CVE-2026-84115HIGHCVSS 8.3EG 8.32026-09-01
A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in impr…
- CVE-2026-53814HIGHCVSS 8.3EG 8.32026-06-11
OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. Attackers with a valid hook token can exploi…
- CVE-2026-96341HIGHCVSS 8.2EG 8.22026-10-10
Incorrect Privilege Assignment vulnerability in WPMU DEV Forminator forminator allows Privilege Escalation.This issue affects Forminator: from n/a through 1.57.3.
- CVE-2026-102674HIGHCVSS 8.2EG 8.22026-09-29
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a sandboxed top-level document did not inherit that document's…
- CVE-2026-73350HIGHCVSS 8.2EG 8.22026-08-18
Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.
- CVE-2026-57768HIGHCVSS 8.2EG 8.22026-07-13
Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3.
- CVE-2025-48911HIGHCVSS 8.2EG 8.22025-06-06
Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-104405HIGHCVSS 8.1EG 8.12026-10-06
Unauthenticated Privilege Escalation in GiveWP <= 4.17.0 versions.
- CVE-2026-95594HIGHCVSS 8.1EG 8.12026-10-06
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions.
- CVE-2026-81805HIGHCVSS 8.1EG 8.12026-09-10
Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
- CVE-2026-61979HIGHCVSS 8.1EG 8.12026-08-13
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
- CVE-2026-27543HIGHCVSS 8.1EG 8.12026-08-13
Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.
- CVE-2026-15467HIGHCVSS 8.1EG 8.12026-08-10
A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user…
- CVE-2026-33390HIGHCVSS 8.1EG 8.12026-07-09
An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through th…
- CVE-2026-39587HIGHCVSS 8.1EG 8.12026-06-15
Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.
- CVE-2026-9397HIGHCVSS 8.1EG 8.12026-05-24
A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown functionality of the component OTA Update Installation Handler. This manipulation causes improper authorization. The at…
- CVE-2026-33997HIGHCVSS 8.1EG 8.12026-03-31
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege…
- CVE-2026-32488HIGHCVSS 8.1EG 8.12026-03-25
Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Registration: from n/a through <= 4.4.9.
- CVE-2026-25334HIGHCVSS 8.1EG 8.12026-03-25
Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issue affects Salon Booking System Pro: from n/a through < 10.30.12.
- CVE-2026-24373HIGHCVSS 8.1EG 8.12026-03-25
Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege Escalation.This issue affects RegistrationMagic: from n/a through <= 6.0.7.1.
- CVE-2026-2109HIGHCVSS 8.1EG 8.12026-02-07
A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/undo/ of the component Delete Category Handler. Such manipulation of the argument ID leads to improper authorization. T…
- CVE-2025-67953HIGHCVSS 8.1EG 8.12026-01-22
Incorrect Privilege Assignment vulnerability in Booking Activities Team Booking Activities booking-activities allows Privilege Escalation.This issue affects Booking Activities: from n/a through <= 1.16.44.
- CVE-2026-1112HIGHCVSS 8.1EG 8.12026-01-18
A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeAddressController.java of the component Trade Address Deleti…
- CVE-2025-15085HIGHCVSS 8.1EG 8.12025-12-25
A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java of the component Balanc…
- CVE-2025-59945HIGHCVSS 8.1EG 8.12025-09-27
SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can assign the is_project_admin permission to their own user. This allows users to r…
- CVE-2025-7947HIGHCVSS 8.1EG 8.12025-07-22
A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component Account Handler. The manipulation of the argument ID leads to improper authorization. It i…
- CVE-2025-4922HIGHCVSS 8.1EG 8.12025-06-11
Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad E…
- CVE-2025-23974HIGHCVSS 8.1EG 8.12025-06-09
Incorrect Privilege Assignment vulnerability in ifkooo One-Login one-login allows Privilege Escalation.This issue affects One-Login: from n/a through <= 1.4.
- CVE-2025-0628HIGHCVSS 8.1EG 8.12025-03-20
An improper authorization vulnerability exists in the main-latest version of BerriAI/litellm. When a user with the role 'internal_user_viewer' logs into the application, they are provided with an overly privileged API key. This key can be …
- CVE-2024-50550HIGHCVSS 8.1EG 8.12024-10-29
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through <= 6.5.1.
- CVE-2024-27273HIGHCVSS 8.1EG 8.12024-05-07
IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. IBM X-Forc…
- CVE-2023-47140HIGHCVSS 8.1EG 8.12024-01-08
IBM CICS Transaction Gateway 9.3 could allow a user to transfer or view files due to improper access controls.
- CVE-2021-42135HIGHCVSS 8.1EG 8.12021-10-11
HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user …
- CVE-2018-1088HIGHCVSS 8.1EG 8.12018-04-18
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
- CVE-2021-1594HIGHCVSS 7.5EG 8.12021-10-06
A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a command injection attack and elevate privileges to root. This vulnerability is due to insufficient input v…
- CVE-2026-73461HIGHCVSS 8.0EG 8.02026-09-16
On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong AAA method list. This…
- CVE-2026-47237HIGHCVSS 8.0EG 8.02026-07-21
Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnera…
- CVE-2025-41255HIGHCVSS 8.0EG 8.02025-06-25
Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions. Thi…
- CVE-2025-49580HIGHCVSS 8.0EG 8.02025-06-13
XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or programming rights when they contain a link and the target of the link is renamed or moved. This might lead to execution …
- CVE-2023-38296HIGHCVSS 8.0EG 8.02024-04-22
Various software builds for the following TCL 30Z and TCL A3X devices leak the ICCID to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps…
- CVE-2019-11893HIGHCVSS 8.0EG 8.02019-05-29
A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a restricted app obtaining default app permissions. In order to exp…
- CVE-2019-11891HIGHCVSS 8.0EG 8.02019-05-29
A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in elevated privileges of the adversary's choosing. In order to exploit th…
Map vulnerabilities like CWE-266 to your infrastructure
EchelonGraph correlates every CVE — across CWE-266 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →