CWE-266
Incorrect Privilege Assignment
Description
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
CVEs mapped to this weakness (1,068)
page 1 of 54| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-48172 | Cri | 0.77 | 9.8 | 0.19 | KEV | May 21, 2026 | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash.… | |
| CVE-2024-28000 | Cri | 0.72 | 9.8 | 0.68 | Aug 21, 2024 | Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1. | ||
| CVE-2025-27007 | Cri | 0.71 | 9.8 | 0.51 | May 1, 2025 | Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82. | ||
| CVE-2025-34112 | Cri | 0.68 | — | 0.02 | Jul 15, 2025 | An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances. A SQL injection vulnerability in the '/api/common/1.0/login' endpoint can be exploited to create a new user account in the… | ||
| CVE-2025-47539 | Cri | 0.66 | 9.8 | 0.33 | May 23, 2025 | Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26. | ||
| CVE-2026-23800 | Cri | 0.65 | 10.0 | 0.00 | Jan 16, 2026 | Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 before 2.6.0. | ||
| CVE-2026-23550 | Cri | 0.65 | 9.8 | 0.21 | Jan 14, 2026 | Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1. | ||
| CVE-2024-9479 | Cri | 0.65 | — | 0.00 | Nov 20, 2024 | Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2. | ||
| CVE-2024-9478 | Cri | 0.65 | — | 0.00 | Nov 20, 2024 | Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2. | ||
| CVE-2026-66662 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||
| CVE-2026-65507 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions. | ||
| CVE-2026-54807 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions. | ||
| CVE-2026-49058 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions. | ||
| CVE-2026-27395 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions. | ||
| CVE-2025-69179 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions. | ||
| CVE-2026-39583 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2026 | Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions. | ||
| CVE-2026-34901 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2026 | Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions. | ||
| CVE-2026-49060 | Cri | 0.64 | 9.8 | 0.01 | Jun 11, 2026 | Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4. | ||
| CVE-2025-53209 | Cri | 0.64 | 9.8 | 0.00 | Jun 2, 2026 | Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0. | ||
| CVE-2026-48879 | Cri | 0.64 | 9.8 | 0.00 | Jun 1, 2026 | Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17. |
- risk 0.77cvss 9.8epss 0.19
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash.…
- risk 0.72cvss 9.8epss 0.68
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.
- risk 0.71cvss 9.8epss 0.51
Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82.
- risk 0.68cvss —epss 0.02
An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances. A SQL injection vulnerability in the '/api/common/1.0/login' endpoint can be exploited to create a new user account in the…
- risk 0.66cvss 9.8epss 0.33
Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26.
- risk 0.65cvss 10.0epss 0.00
Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 before 2.6.0.
- risk 0.65cvss 9.8epss 0.21
Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1.
- risk 0.65cvss —epss 0.00
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.
- risk 0.65cvss —epss 0.00
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.
- risk 0.64cvss 9.8epss 0.01
Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4.
- risk 0.64cvss 9.8epss 0.00
Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0.
- risk 0.64cvss 9.8epss 0.00
Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.