VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,190)

page 1 of 60
  • CVE-2026-48172CriKEVMay 21, 2026
    risk 0.77cvss 9.8epss 0.01

    LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash.…

  • CVE-2024-28000CriAug 21, 2024
    risk 0.72cvss 9.8epss 0.68

    Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.

  • CVE-2025-27007CriMay 1, 2025
    risk 0.71cvss 9.8epss 0.54

    Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82.

  • CVE-2025-34112CriJul 15, 2025
    risk 0.68cvss —epss 0.03

    An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances. A SQL injection vulnerability in the '/api/common/1.0/login' endpoint can be exploited to create a new user account in the…

  • CVE-2025-47539CriMay 23, 2025
    risk 0.66cvss 9.8epss 0.28

    Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26.

  • CVE-2026-23800CriJan 16, 2026
    risk 0.65cvss 10.0epss 0.01

    Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 before 2.6.0.

  • CVE-2026-23550CriJan 14, 2026
    risk 0.65cvss 9.8epss 0.22

    Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1.

  • CVE-2024-9479CriNov 20, 2024
    risk 0.65cvss —epss 0.00

    Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.

  • CVE-2024-9478CriNov 20, 2024
    risk 0.65cvss —epss 0.00

    Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.

  • CVE-2026-78330CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a successful authentication and obtaining a…

  • CVE-2026-84814CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.00

    Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.

  • CVE-2026-81294CriSep 2, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.

  • CVE-2026-32566CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

  • CVE-2026-78267CriAug 24, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.

  • CVE-2026-66648CriAug 24, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.

  • CVE-2026-32558CriAug 24, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.

  • CVE-2026-28165CriAug 24, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Digits <= 9.2 versions.

  • CVE-2026-66682CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

  • CVE-2025-15689CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.

  • CVE-2026-73390CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.