CWE-266
Incorrect Privilege Assignment
Description
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
CVEs mapped to this weakness (1,190)
page 1 of 60| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-48172 | Cri | 0.77 | 9.8 | 0.01 | KEV | May 21, 2026 | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash.… | |
| CVE-2024-28000 | Cri | 0.72 | 9.8 | 0.68 | Aug 21, 2024 | Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1. | ||
| CVE-2025-27007 | Cri | 0.71 | 9.8 | 0.54 | May 1, 2025 | Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82. | ||
| CVE-2025-34112 | Cri | 0.68 | — | 0.03 | Jul 15, 2025 | An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances. A SQL injection vulnerability in the '/api/common/1.0/login' endpoint can be exploited to create a new user account in the… | ||
| CVE-2025-47539 | Cri | 0.66 | 9.8 | 0.28 | May 23, 2025 | Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26. | ||
| CVE-2026-23800 | Cri | 0.65 | 10.0 | 0.01 | Jan 16, 2026 | Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 before 2.6.0. | ||
| CVE-2026-23550 | Cri | 0.65 | 9.8 | 0.22 | Jan 14, 2026 | Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1. | ||
| CVE-2024-9479 | Cri | 0.65 | — | 0.00 | Nov 20, 2024 | Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2. | ||
| CVE-2024-9478 | Cri | 0.65 | — | 0.00 | Nov 20, 2024 | Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2. | ||
| CVE-2026-78330 | Cri | 0.64 | 9.8 | 0.01 | Sep 14, 2026 | Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a successful authentication and obtaining a… | ||
| CVE-2026-84814 | Cri | 0.64 | 9.8 | 0.00 | Sep 3, 2026 | Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions. | ||
| CVE-2026-81294 | Cri | 0.64 | 9.8 | 0.00 | Sep 2, 2026 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. | ||
| CVE-2026-32566 | Cri | 0.64 | 9.8 | 0.00 | Aug 27, 2026 | Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | ||
| CVE-2026-78267 | Cri | 0.64 | 9.8 | 0.00 | Aug 24, 2026 | Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. | ||
| CVE-2026-66648 | Cri | 0.64 | 9.8 | 0.00 | Aug 24, 2026 | Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions. | ||
| CVE-2026-32558 | Cri | 0.64 | 9.8 | 0.00 | Aug 24, 2026 | Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions. | ||
| CVE-2026-28165 | Cri | 0.64 | 9.8 | 0.00 | Aug 24, 2026 | Unauthenticated Privilege Escalation in Digits <= 9.2 versions. | ||
| CVE-2026-66682 | Cri | 0.64 | 9.8 | 0.00 | Aug 20, 2026 | Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. | ||
| CVE-2025-15689 | Cri | 0.64 | 9.8 | 0.00 | Aug 20, 2026 | Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. | ||
| CVE-2026-73390 | Cri | 0.64 | 9.8 | 0.00 | Aug 19, 2026 | Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. |
- risk 0.77cvss 9.8epss 0.01
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash.…
- risk 0.72cvss 9.8epss 0.68
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.
- risk 0.71cvss 9.8epss 0.54
Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82.
- risk 0.68cvss —epss 0.03
An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances. A SQL injection vulnerability in the '/api/common/1.0/login' endpoint can be exploited to create a new user account in the…
- risk 0.66cvss 9.8epss 0.28
Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26.
- risk 0.65cvss 10.0epss 0.01
Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 before 2.6.0.
- risk 0.65cvss 9.8epss 0.22
Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1.
- risk 0.65cvss —epss 0.00
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.
- risk 0.65cvss —epss 0.00
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.
- risk 0.64cvss 9.8epss 0.01
Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a successful authentication and obtaining a…
- risk 0.64cvss 9.8epss 0.00
Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.