VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,181)

page 12 of 60
  • CVE-2026-84115HigSep 1, 2026
    risk 0.54cvss 8.3epss 0.00

    A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is…

  • CVE-2026-32916CriMar 31, 2026
    risk 0.54cvss 9.4epss 0.01

    OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated requests to plugin-owned routes can invoke…

  • CVE-2026-81805HigSep 10, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.

  • CVE-2026-73350HigAug 18, 2026
    risk 0.53cvss 8.2epss 0.00

    Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.

  • CVE-2026-61979HigAug 13, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.

  • CVE-2026-27543HigAug 13, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.

  • CVE-2026-15467HigAug 10, 2026
    risk 0.53cvss 8.1epss 0.01

    A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote…

  • CVE-2026-33390HigJul 9, 2026
    risk 0.53cvss 8.1epss 0.00

    An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device…

  • CVE-2026-39587HigJun 15, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.

  • CVE-2026-9397HigMay 24, 2026
    risk 0.53cvss 8.1epss 0.01

    A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown functionality of the component OTA Update Installation Handler. This manipulation causes improper authorization. The attack is possible to be carried out…

  • CVE-2026-32488HigMar 25, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Registration: from n/a through <= 4.4.9.

  • CVE-2026-25334HigMar 25, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issue affects Salon Booking System Pro: from n/a through < 10.30.12.

  • CVE-2026-24373HigMar 25, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege Escalation.This issue affects RegistrationMagic: from n/a through <= 6.0.7.1.

  • CVE-2026-22267HigFeb 19, 2026
    risk 0.53cvss 8.1epss 0.00

    Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2025-67953HigJan 22, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect Privilege Assignment vulnerability in Booking Activities Team Booking Activities booking-activities allows Privilege Escalation.This issue affects Booking Activities: from n/a through <= 1.16.44.

  • CVE-2025-4922HigJun 11, 2025
    risk 0.53cvss 8.1epss 0.01

    Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14.

  • CVE-2025-23974HigJun 9, 2025
    risk 0.53cvss 8.1epss 0.00

    Incorrect Privilege Assignment vulnerability in ifkooo One-Login one-login allows Privilege Escalation.This issue affects One-Login: from n/a through <= 1.4.

  • CVE-2025-48911HigJun 6, 2025
    risk 0.53cvss 8.2epss 0.00

    Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-50550HigOct 29, 2024
    risk 0.53cvss 8.1epss 0.01

    Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through <= 6.5.1.

  • CVE-2024-27273HigMay 7, 2024
    risk 0.53cvss 8.1epss 0.00

    IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. IBM X-Force ID: 284903.