CWE-266
Incorrect Privilege Assignment
Description
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
CVEs mapped to this weakness (1,181)
page 12 of 60| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-84115 | Hig | 0.54 | 8.3 | 0.00 | Sep 1, 2026 | A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is… | ||
| CVE-2026-32916 | Cri | 0.54 | 9.4 | 0.01 | Mar 31, 2026 | OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated requests to plugin-owned routes can invoke… | ||
| CVE-2026-81805 | Hig | 0.53 | 8.1 | 0.00 | Sep 10, 2026 | Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions. | ||
| CVE-2026-73350 | Hig | 0.53 | 8.2 | 0.00 | Aug 18, 2026 | Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions. | ||
| CVE-2026-61979 | Hig | 0.53 | 8.1 | 0.00 | Aug 13, 2026 | Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions. | ||
| CVE-2026-27543 | Hig | 0.53 | 8.1 | 0.00 | Aug 13, 2026 | Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions. | ||
| CVE-2026-15467 | Hig | 0.53 | 8.1 | 0.01 | Aug 10, 2026 | A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote… | ||
| CVE-2026-33390 | Hig | 0.53 | 8.1 | 0.00 | Jul 9, 2026 | An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device… | ||
| CVE-2026-39587 | Hig | 0.53 | 8.1 | 0.00 | Jun 15, 2026 | Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions. | ||
| CVE-2026-9397 | Hig | 0.53 | 8.1 | 0.01 | May 24, 2026 | A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown functionality of the component OTA Update Installation Handler. This manipulation causes improper authorization. The attack is possible to be carried out… | ||
| CVE-2026-32488 | Hig | 0.53 | 8.1 | 0.00 | Mar 25, 2026 | Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Registration: from n/a through <= 4.4.9. | ||
| CVE-2026-25334 | Hig | 0.53 | 8.1 | 0.00 | Mar 25, 2026 | Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issue affects Salon Booking System Pro: from n/a through < 10.30.12. | ||
| CVE-2026-24373 | Hig | 0.53 | 8.1 | 0.00 | Mar 25, 2026 | Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege Escalation.This issue affects RegistrationMagic: from n/a through <= 6.0.7.1. | ||
| CVE-2026-22267 | Hig | 0.53 | 8.1 | 0.00 | Feb 19, 2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | ||
| CVE-2025-67953 | Hig | 0.53 | 8.1 | 0.00 | Jan 22, 2026 | Incorrect Privilege Assignment vulnerability in Booking Activities Team Booking Activities booking-activities allows Privilege Escalation.This issue affects Booking Activities: from n/a through <= 1.16.44. | ||
| CVE-2025-4922 | Hig | 0.53 | 8.1 | 0.01 | Jun 11, 2025 | Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14. | ||
| CVE-2025-23974 | Hig | 0.53 | 8.1 | 0.00 | Jun 9, 2025 | Incorrect Privilege Assignment vulnerability in ifkooo One-Login one-login allows Privilege Escalation.This issue affects One-Login: from n/a through <= 1.4. | ||
| CVE-2025-48911 | Hig | 0.53 | 8.2 | 0.00 | Jun 6, 2025 | Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-50550 | Hig | 0.53 | 8.1 | 0.01 | Oct 29, 2024 | Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through <= 6.5.1. | ||
| CVE-2024-27273 | Hig | 0.53 | 8.1 | 0.00 | May 7, 2024 | IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. IBM X-Force ID: 284903. |
- risk 0.54cvss 8.3epss 0.00
A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is…
- risk 0.54cvss 9.4epss 0.01
OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated requests to plugin-owned routes can invoke…
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
- risk 0.53cvss 8.2epss 0.00
Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.
- risk 0.53cvss 8.1epss 0.01
A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote…
- risk 0.53cvss 8.1epss 0.00
An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device…
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.
- risk 0.53cvss 8.1epss 0.01
A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown functionality of the component OTA Update Installation Handler. This manipulation causes improper authorization. The attack is possible to be carried out…
- risk 0.53cvss 8.1epss 0.00
Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Registration: from n/a through <= 4.4.9.
- risk 0.53cvss 8.1epss 0.00
Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issue affects Salon Booking System Pro: from n/a through < 10.30.12.
- risk 0.53cvss 8.1epss 0.00
Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege Escalation.This issue affects RegistrationMagic: from n/a through <= 6.0.7.1.
- risk 0.53cvss 8.1epss 0.00
Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
- risk 0.53cvss 8.1epss 0.00
Incorrect Privilege Assignment vulnerability in Booking Activities Team Booking Activities booking-activities allows Privilege Escalation.This issue affects Booking Activities: from n/a through <= 1.16.44.
- risk 0.53cvss 8.1epss 0.01
Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14.
- risk 0.53cvss 8.1epss 0.00
Incorrect Privilege Assignment vulnerability in ifkooo One-Login one-login allows Privilege Escalation.This issue affects One-Login: from n/a through <= 1.4.
- risk 0.53cvss 8.2epss 0.00
Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.53cvss 8.1epss 0.01
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through <= 6.5.1.
- risk 0.53cvss 8.1epss 0.00
IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. IBM X-Force ID: 284903.