VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,068)

page 10 of 54
  • CVE-2019-14819HigJan 7, 2020
    risk 0.57cvss 8.8epss 0.01

    A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges…

  • CVE-2025-52726HigJun 27, 2025
    risk 0.56cvss 8.6epss 0.00

    Incorrect Privilege Assignment vulnerability in pebas CouponXxL Custom Post Types couponxxl-cpt allows Privilege Escalation.This issue affects CouponXxL Custom Post Types: from n/a through <= 3.0.

  • CVE-2024-25632HigOct 1, 2024
    risk 0.56cvss 8.6epss 0.00

    eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A user may be an administrator in one team and a regular user in…

  • CVE-2024-27453HigMay 3, 2024
    risk 0.56cvss 8.6epss 0.01

    In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI).

  • CVE-2023-50437HigFeb 29, 2024
    risk 0.56cvss 8.6epss 0.01

    An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageCluster2.

  • CVE-2025-65807HigDec 10, 2025
    risk 0.55cvss 8.4epss 0.00

    An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command.

  • CVE-2025-10577HigOct 15, 2025
    risk 0.55cvss epss 0.00

    Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. HP is releasing updated audio packages to mitigate the potential vulnerabilities

  • CVE-2025-10576HigOct 15, 2025
    risk 0.55cvss epss 0.00

    Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. HP is releasing updated audio packages to mitigate the potential vulnerabilities.

  • CVE-2024-36534HigJul 24, 2024
    risk 0.55cvss 8.4epss 0.00

    Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

  • CVE-2023-30691HigAug 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.

  • CVE-2023-30680HigAug 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.

  • CVE-2023-28956HigJun 22, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls.

  • CVE-2026-32916CriMar 31, 2026
    risk 0.54cvss 9.4epss 0.00

    OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated requests to plugin-owned routes can invoke…

  • CVE-2026-15467HigAug 10, 2026
    risk 0.53cvss 8.1epss 0.00

    A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote…

  • CVE-2026-33390HigJul 9, 2026
    risk 0.53cvss 8.1epss 0.00

    An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device…

  • CVE-2026-39587HigJun 15, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.

  • CVE-2026-9397HigMay 24, 2026
    risk 0.53cvss 8.1epss 0.00

    A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown functionality of the component OTA Update Installation Handler. This manipulation causes improper authorization. The attack is possible to be carried out…

  • CVE-2026-32488HigMar 25, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Registration: from n/a through <= 4.4.9.

  • CVE-2026-25334HigMar 25, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issue affects Salon Booking System Pro: from n/a through < 10.30.12.

  • CVE-2026-24373HigMar 25, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege Escalation.This issue affects RegistrationMagic: from n/a through <= 6.0.7.1.